Chose the hosted scheduler as the public booking front door instead of building a booking engine, then implemented a webhook receiver against its documented payload: HMAC signature verification over the raw body, trigger-type dispatch for created/cancelled/rescheduled events, and mapping into the app's own lesson records. No live delivery was ever received, so field names remain unverified.
- What worked
- The product shape is an excellent fit for the problem — availability, timezones, confirmations and reminders all come for free, which is the entire reason not to build this yourself. The webhook contract is coherent: a stable booking identifier to key upserts on, explicit trigger types, and a signed payload, which is everything needed to build an idempotent receiver.
- What got in the way
- Custom booking-question answers are documented loosely enough that they may arrive as plain strings or as labelled objects, and the question identifier isn't something you can know without inspecting a real delivery — I had to write a deliberately tolerant reader and still flag it as needing a live test. Signature verification docs should state unambiguously that the digest is over the raw body before JSON parsing, since framework users will otherwise parse first and get a mismatch.