Incoming webhooks API reference
Incoming PACS webhooks let your access-control system tell UnSpot when employees enter or leave the office. UnSpot uses these events for automatic check-in of bookings and attendance analytics. Events are sent to a universal JSON endpoint that works with any PACS.
1. Create a connection
In Manage > Integrations, create a PACS connection of type JSON. You define which fields of your payload contain the data — so you can adapt UnSpot to whatever your PACS sends:
| Setting | Meaning | Default key |
|---|---|---|
| Office attribute | JSON key holding the name of the access point the employee passed; UnSpot uses it to determine the office (see below) | space |
| User attribute | JSON key holding the user identifier | user |
| Status attribute | JSON key holding the direction (in/out) | status |
| Desk attribute | Optional key holding a desk name | — |
| Access token | Optional shared secret; if set, must be sent in the Un-Token header | — |
After saving, UnSpot generates a unique endpoint token — your PACS will POST events to the URL containing it.
Office to access point mapping. The subscription window has an “Office PACS access point mapping” block: UnSpot uses it to work out which office an employee entered. Click “Add office”, pick an office and list under “Access points” the values your PACS sends in the office attribute — for example, the names of turnstiles and doors. Each value is committed with Enter, by leaving the field or with the check mark. The block is optional: the subscription saves without it. In the request example below the office attribute carries “HQ Berlin” — for such an event to be assigned to an office, this value has to be among the access points.
- one office takes up to 100 access points, and an access point name is up to 255 characters;
- leading and trailing spaces and letter case are ignored: access points are stored and shown in lower case;
- an access point is unique across the company: a repeat within the subscription is flagged in the field with “This value is already in use”, and an access point already used in another subscription is rejected by the server on saving — “Failed to save the subscription. Access points must be unique”;
- a row you add needs an office and at least one access point (“Specify at least one access point”); only offices can be picked, and blocked or deleted offices are not listed;
- mappings are deleted together with the subscription. If an office is deleted, its row stays in the subscription: events for its access points arrive without an office, and the subscription can be saved again only after that row is removed.
2. Send events — POST /api/scud/json/{token}
curl -X POST -H "Content-Type: application/json" -H "Un-Token: <access token>" \
https://acme.unspot.com/api/scud/json/3f2a...-connection-token \
-d '{
"space": "HQ Berlin",
"user": "jane.doe@example.com",
"status": "in_office"
}'Bash- User identification: if the user value is an email, the user is matched by email only, and no other method is tried when that misses. When the value does not look like an email, UnSpot tries the pass number, then the full name, then the display name — the display-name step was added on 7 September 2026. An ambiguous match at any step is rejected.
- The display-name match compares the whole string: leading and trailing spaces are trimmed, several spaces in a row count as one, and case is ignored —
" Anna Smith "finds the employee whose display name isAnna Smith. Unlike the full-name match it drops no words and does not try the reverse word order, and a single-word value is looked up as well. The rule is the same for JSON and for Sigur. - Status: the value must resolve to “in office” or “out of office”. The event time is the moment UnSpot receives the request.
- Events are processed asynchronously; each event (including errors) is recorded in the integration log (Reports > Integration history).
3. What UnSpot does with an event
- Marks the user as present in / absent from the office.
- Confirms check-in for the user’s bookings when check-in policies require office presence.
- Feeds office-attendance analytics and reports.
- Determines the office of the visit: the office attribute value is looked up among the access points of this subscription, ignoring case and leading or trailing spaces. If it matches, the office is written to the visit log; it shows in the Office column of the History of Office Visits (PACS) report and is taken into account by the office filter of PACS analytics. If it does not match or the attribute is empty, the event is still processed and the employee status changes, but the office in the log stays empty.
Errors
Integration not found— wrong endpoint token.Access to subscription denied— theUn-Tokenheader does not match the configured access token.Subscription deactivated— the connection is disabled in UnSpot.User not found/Multiple users found by pass number— the user identifier could not be resolved unambiguously.- Missing office/user/status keys — the event is rejected and logged.
For a hands-on example of the JSON variant, see Incoming Webhooks: Connecting PACS via JSON.