Apps
Build an integration once and let any hotel on ChatBeds connect it with OAuth 2.0, without making or pasting keys.
An app is your integration as ChatBeds knows it: a name, an OAuth client, the permissions it may ask for, and a webhook address. Once ChatBeds has reviewed it, it appears in every hotel's Apps directory, and a hotel connects it in a few clicks.
The lifecycle
Register
On the Developers page, press New app, give it a name, a redirect address and its scopes, then Register app. You get a client ID (cba_...) and a client secret (cbs_..., shown once). The app starts as a Draft. See Register an app.
Build on your sandbox
Connect the app to your own Sandbox Hotel with the real OAuth flow. Your own apps work on your own properties at any stage, free and without review. Use Try it on your sandbox → Open the connect screen to see what a hotel sees.
Submit for review
Fill in the listing details (tagline, description, category, support email, privacy policy, install address) and press Submit for review. The app is In review. See Review and listing.
Get listed
When ChatBeds approves it, the app is Listed in every hotel's Apps directory. If changes are needed, you see the reviewer's note and can submit again.
Hotels connect
A hotel owner or admin presses Connect, which opens your install address. Your page starts the OAuth flow, the hotel picks a property and presses Allow, and your server gets tokens for that property.
How a connection works
Each connection is one app on one property. Behind the scenes ChatBeds gives it its own partner key, carrying the scopes the hotel allowed. So everything you know from the Partner API works the same with an app token:
- the same 20 operations at
https://api.chatbeds.app/partner/v1; - idempotency, and a rate limit of 120 calls a minute per connection;
- bookings you make carry the source
PARTNER:<your app's slug>; - your app's webhook address gets that property's booking events (if the hotel allowed
reservations:read).
The hotel sees the connection on its Apps page, with what it may do and when it was last used, and can Disconnect it at any time. Disconnecting stops every token at once.
In this section
Register an app
Fields, redirect addresses, credentials and webhooks.
OAuth 2.0
The authorization code flow with PKCE, tokens and refresh.
Scopes
What each permission unlocks and what the hotel sees.
Review and listing
What ChatBeds checks and what each status means.
Going live checklist
Everything to check before you submit.
Building something?