How do I see what ResoFlow is connected to?
The Integrations page is a status hub — one row per connection (Stripe, text messages, Google, Zapier, your domain's email) with a live chip and an Open link to where each is set up.
Settings → Data and policies → Integrations is a read-only status hub: everything ResoFlow is connected to, in one place, with a live chip beside each one and an Open button that takes you to the page where it is actually set up. Only Owners and Admins can see it. Nothing is changed from this page except Zapier, which has its editor here.
The connections
- Stripe payouts — where deposits, tickets, gift cards and orders are paid into. The chip reads Connected, Finish setting up (Stripe still wants details before it will take payments) or Not connected. Open goes to Payouts and Stripe.
- Text messages — the sender behind your booking texts and reminders. Connected, Not set up, or Paused — needs attention if the sender couldn't be finished (our team is alerted when that happens). Open goes to Customer notifications.
- Google (Reserve with Google) — whether you've ticked off adding your booking link to your Google Business Profile. Link added or Not added yet. Open goes to Get more bookings.
- Zapier — Not set up, Enabled (switched on but no address saved yet), Enabled (no events), Active, or Locked on plans without it. Configure opens the Zapier editor below.
- Your domain's email — whether customer emails go out from your own address. Sending from your domain, Records pending, Records failed, or Sending from ResoFlow. Open goes to Your domain.
Rows that don't apply to your set-up (for example Stripe on a venue that takes no money) don't appear.
Zapier — send booking events to other tools (Complete plan)
Zapier sends real-time booking data to Zapier, Make, or any webhook-compatible tool — useful for things like logging bookings to a spreadsheet or pinging a team chat. It needs the Complete plan; on other plans the row shows a padlock and See plans.
- Click Configure on the Zapier row.
- Switch on Enable webhooks.
- Paste your endpoint into Webhook URL, then click Test webhook to send a sample payload. Testing uses the URL in the box — remember to Save changes (top bar) to apply it to live bookings.
- Tick the Events to send: Booking created, Booking confirmed, Booking cancelled, Booking seated, Booking cleared, and Booking no-show. If none are selected nothing is sent — the page warns you.
Two of those events depend on how you track visits. Booking seated and Booking cleared are only sent when somebody marks a booking that way. If your venue is set to Just take bookings or Mark customers as arrived (Settings → Bookings → During service → How your team tracks a service), nobody does — so those two never fire, however many bookings you take, and anything you build on top of them will simply never run. The other four are unaffected. It's listed on the setting itself so you know before you build the automation — see Running ResoFlow as a booking diary.
Signing and recent deliveries
Below the events list, the Signing and recent deliveries section lets your receiving tool check that a delivery really came from ResoFlow, and shows you what has actually been sent.
Signing secret. Click Generate signing secret. The secret is shown once — copy it into your tool (Zapier and Make let you store it as a secret; a custom endpoint keeps it in its config). We never show it again: if you lose it, click Rotate signing secret to make a new one (the old one stops working the moment you do, so update your tool straight after). Until you generate one, deliveries are sent unsigned — the row says so.
Every delivery then carries three headers:
- X-ResoFlow-Signature — t=<seconds since 1970>,v1=<signature>
- X-ResoFlow-Event — the event name, for example reservation.created
- X-ResoFlow-Event-Id — the same eventId that is in the body (use it to ignore a repeat)
To verify: join the t value, a full stop and the raw request body; compute an HMAC-SHA256 of that string with your secret; compare it to v1 using a constant-time compare; and reject anything whose t is more than five minutes old. In Node:
const crypto = require("node:crypto"); function verifyResoFlow(rawBody, header, secret) { const parts = Object.fromEntries(header.split(",").map((p) => p.split("="))); const t = Number(parts.t); if (!t Math.abs(Date.now() / 1000 - t) > 300) return false; // replay guard const expected = crypto.createHmac("sha256", secret).update(${t}.${rawBody}).digest("hex"); const a = Buffer.from(parts.v1 "", "hex"), b = Buffer.from(expected, "hex"); return a.length === b.length && crypto.timingSafeEqual(a, b); }
Use the raw body exactly as received — re-serialising the JSON changes the bytes and the check fails.
Recent deliveries. The same section lists your last 25 deliveries — the event, when it was sent, whether it was accepted, the HTTP status your tool returned, how long it took, and how many retries were needed. A delivery that times out, cannot connect, or gets a 5xx is retried twice more (after one second, then two); a 4xx is not retried because sending the same body again would not change the answer. Rows are kept for 30 days. The Test webhook probe appears here too, as the event test, so you can see the signature arrive before a real booking does.
Booking channels — Google, Apple Maps and social media (any plan)
Booking channels aren't technical integrations, so they have their own page: Settings → Public booking → Get more bookings. It's a free checklist covering Google, Apple Maps, Instagram, Facebook, TikTok, WhatsApp, QR codes and your website — each channel with a short walkthrough and a tracked booking link. See How do I get more bookings from Google, Apple Maps and social media?.
Related: How do I get more bookings from Google, Apple Maps and social media? · How do I take bookings from Google? · How do I set up SMS messages? · How do I add the booking button to my own website?