ChatBedsDevelopers
Apps and OAuth

Going live checklist

A practical list to work through before you submit your app for review and before real hotels connect it.

Work through this list against your Sandbox Hotel before you press Submit for review.

Listing

  • The App name, Tagline and Description say plainly what your app does for a hotel.
  • The description says what you do with the hotel's and its guests' data.
  • The Category fits.
  • The Support email reaches a person.
  • The Privacy policy address opens a real policy that covers guest data.
  • The Install address is live over https and starts the OAuth flow.

OAuth

  • Your production redirect address is registered, and you send it exactly as registered. Remove http://localhost addresses you no longer need.
  • You send a random state per sign-in and reject callbacks where it doesn't match.
  • You use PKCE with S256.
  • You handle error=access_denied when the hotel presses Cancel.
  • You swap the code within 10 minutes, once.
  • You store tokens per installation_id and property_id, encrypted.
  • You refresh before the access token's hour is up, from one worker at a time, and save both new tokens.
  • You treat invalid_grant on refresh and 401 on API calls as "disconnected", and ask the hotel to connect again.
  • The client secret lives only on your server. You know how to rotate it with New client secret.

Scopes

  • Every scope you ask for is used by a feature in your listing.
  • You read the scope field of the token response, and your app copes with a 403 for a missing scope.
  • If you need booking webhooks, you ask for reservations:read.

API calls

  • You pass expected_total when you book, and handle 409 when the price has changed.
  • You send an Idempotency-Key on every write and reuse it on retries. See Idempotency.
  • You set your own external_ref on bookings, so you can find them with a search.
  • You stay under 120 calls a minute per connection and honour Retry-After on 429. See Rate limits.
  • You use the hotel's today and timezone from GET /properties for dates, not your server's.
  • You log the detail of every error, and never log full tokens or secrets.

Webhooks

  • Your webhook address is https and reachable from the public internet.
  • You verify the signature on the raw body and refuse anything older than five minutes.
  • You answer 2xx within 10 seconds and do the work afterwards.
  • You ignore repeats by ChatBeds-Delivery.
  • You don't rely on the order of events, and re-fetch the reservation when in doubt.

End to end

  • From your install address, connect the app to your Sandbox Hotel with Allow.
  • Search offers, make a booking, modify it and cancel it.
  • Make a booking in the ChatBeds dashboard and see the webhook arrive.
  • Press Disconnect on the sandbox's Apps page and check that your app notices.
  • Connect again and check that your app picks up the new tokens.

When everything is ticked, press Submit for review. See Review and listing.

Building something?

On this page