Register an app
Create an app on the Developers page, get its client ID and secret, and set redirect addresses, scopes, a webhook and listing details.
You register apps on the Developers page of the dashboard, app.chatbeds.app/developers. Only an owner or admin of the account can use it. An account can have up to 10 apps.
Create the app
Under Your apps, press New app and fill in:
| Field | What to enter |
|---|---|
| App name | What hotels see, for example Booker. At least 2 characters, up to 80 |
| Redirect addresses, one per line | Where hotels are sent back after they allow your app, for example https://booker.example.com/chatbeds/callback |
| What the app may do (scopes) | The most your app may ask a hotel for. Starts with property:read, rooms:read, availability:read and reservations:read ticked |
Press Register app. ChatBeds answers with the app, its credentials, and a status of DRAFT:
{
"id": "74edce7e-def4-4d62-8967-0a81d9940763",
"name": "Booker",
"slug": "booker",
"tagline": null,
"description": null,
"category": null,
"website_url": null,
"install_url": null,
"support_email": null,
"privacy_url": null,
"scopes": ["property:read", "rooms:read", "availability:read", "reservations:read"],
"scope_labels": {
"property:read": "See the property's details, policies and what it offers",
"rooms:read": "See room types, rooms, rate plans and extras",
"availability:read": "Search availability and prices",
"reservations:read": "See bookings"
},
"status": "DRAFT",
"client_id": "cba_WID1hm0lWAQFdXATrQ47Qpd5",
"client_secret_prefix": "cbs__Lp9qcRZ",
"redirect_uris": ["https://booker.example.com/chatbeds/callback"],
"webhook_url": null,
"webhook_signing": false,
"review_note": null,
"submitted_at": null,
"reviewed_at": null,
"created_at": "2026-10-10T05:09:47+00:00",
"installs": 0,
"client_secret": "cbs_••••"
}The slug is made from the name and becomes your booking source: PARTNER:booker.
Credentials
| Format | Notes | |
|---|---|---|
| Client ID | cba_... | Public. Goes in the authorize URL and in token requests |
| Client secret | cbs_... | Shown once, when the app is made. Keep it on your server |
Copy the secret now
ChatBeds keeps only a hash of the client secret. The page later shows just its first characters (cbs__Lp9qcRZ…).
Rotating the secret
Press New client secret, then Yes, make a new one. The new secret is shown once, and the old one stops working at once. Connections and tokens already issued keep working; only calls to /oauth/token and /oauth/revoke need the new secret. Deploy it straight away.
Redirect addresses
Hotels are sent back to one of these after they press Allow or Cancel.
- Each must be a full
https://address.http://localhostandhttp://127.0.0.1are allowed for testing. - No
#fragment, and at most 500 characters. - Up to 10 per app.
- The
redirect_uriyou send to the authorize page must match one exactly, character for character. Query strings count.
Scopes
The scopes you tick are the most your app may ever ask for. In each authorize request you may ask for all of them or fewer, never others. See Scopes for what each one unlocks.
Adding scopes later
If your app is already Listed and you add scopes, it goes back to In review. Existing connections keep working with what each hotel allowed.
Webhook
Under Webhook, enter a Webhook address (https) and press Save. ChatBeds shows a signing secret (whsec_...) once. Use it to verify signatures.
- The address must be
httpsand reachable from the public internet. Private, local and internal addresses are refused. - Saving the address again makes a new secret, and the old one stops.
- The address and secret apply to every connection of the app, including ones made before you changed them.
- Leave the address empty and save to turn webhooks off.
Only connections where the hotel allowed reservations:read receive booking events. See Webhooks.
Listing details
Under Listing in the Apps directory, fill in what hotels see before they connect. All of these except the website are needed before you can submit for review:
| Field | Notes |
|---|---|
| App name | Shown on the directory card and the connect screen |
| Category | One of: Booking channels, Channel managers, Guest messaging, Payments, Revenue, Operations, Accounting, Reviews, Other |
| Tagline | One short line, up to 140 characters |
| Description | What your app does for a hotel, and what it does with their data. Up to 4,000 characters |
| Website | Optional. https:// |
| Install address | Where the Connect button sends a hotel. Your page then starts the sign-in. https:// |
| Support email | Shown on the connect screen |
| Privacy policy address | Shown on the connect screen. https:// |
Press Save changes. Then see Review and listing.
Try it on your sandbox
Once a redirect address is saved, Try it on your sandbox → Open the connect screen opens the screen a hotel sees. Choose your Sandbox Hotel and press Allow. You are sent to your redirect address with ?code=…&state=test. Swap the code for tokens within 10 minutes, as described in OAuth 2.0.
Building something?