Apps and OAuth
Going live checklist
A practical list to work through before you submit your app for review and before real hotels connect it.
Work through this list against your Sandbox Hotel before you press Submit for review.
Listing
- The App name, Tagline and Description say plainly what your app does for a hotel.
- The description says what you do with the hotel's and its guests' data.
- The Category fits.
- The Support email reaches a person.
- The Privacy policy address opens a real policy that covers guest data.
- The Install address is live over
httpsand starts the OAuth flow.
OAuth
- Your production redirect address is registered, and you send it exactly as registered. Remove
http://localhostaddresses you no longer need. - You send a random
stateper sign-in and reject callbacks where it doesn't match. - You use PKCE with
S256. - You handle
error=access_deniedwhen the hotel presses Cancel. - You swap the code within 10 minutes, once.
- You store tokens per
installation_idandproperty_id, encrypted. - You refresh before the access token's hour is up, from one worker at a time, and save both new tokens.
- You treat
invalid_granton refresh and401on API calls as "disconnected", and ask the hotel to connect again. - The client secret lives only on your server. You know how to rotate it with New client secret.
Scopes
- Every scope you ask for is used by a feature in your listing.
- You read the
scopefield of the token response, and your app copes with a403for a missing scope. - If you need booking webhooks, you ask for
reservations:read.
API calls
- You pass
expected_totalwhen you book, and handle409when the price has changed. - You send an
Idempotency-Keyon every write and reuse it on retries. See Idempotency. - You set your own
external_refon bookings, so you can find them with a search. - You stay under 120 calls a minute per connection and honour
Retry-Afteron429. See Rate limits. - You use the hotel's
todayandtimezonefromGET /propertiesfor dates, not your server's. - You log the
detailof every error, and never log full tokens or secrets.
Webhooks
- Your webhook address is
httpsand reachable from the public internet. - You verify the signature on the raw body and refuse anything older than five minutes.
- You answer
2xxwithin 10 seconds and do the work afterwards. - You ignore repeats by
ChatBeds-Delivery. - You don't rely on the order of events, and re-fetch the reservation when in doubt.
End to end
- From your install address, connect the app to your Sandbox Hotel with Allow.
- Search offers, make a booking, modify it and cancel it.
- Make a booking in the ChatBeds dashboard and see the webhook arrive.
- Press Disconnect on the sandbox's Apps page and check that your app notices.
- Connect again and check that your app picks up the new tokens.
When everything is ticked, press Submit for review. See Review and listing.
Building something?
Review and listing
How to submit your app, what ChatBeds reviewers check, what each status means, and how hotels find, connect and disconnect apps.
API reference
The ChatBeds partner API, version 1. Twenty operations that let your app read a hotel's rooms and prices, book stays, and work with the guest's bill.