ChatBedsDevelopers
Apps and OAuth

Register an app

Create an app on the Developers page, get its client ID and secret, and set redirect addresses, scopes, a webhook and listing details.

You register apps on the Developers page of the dashboard, app.chatbeds.app/developers. Only an owner or admin of the account can use it. An account can have up to 10 apps.

Create the app

Under Your apps, press New app and fill in:

FieldWhat to enter
App nameWhat hotels see, for example Booker. At least 2 characters, up to 80
Redirect addresses, one per lineWhere hotels are sent back after they allow your app, for example https://booker.example.com/chatbeds/callback
What the app may do (scopes)The most your app may ask a hotel for. Starts with property:read, rooms:read, availability:read and reservations:read ticked

Press Register app. ChatBeds answers with the app, its credentials, and a status of DRAFT:

201 Created
{
  "id": "74edce7e-def4-4d62-8967-0a81d9940763",
  "name": "Booker",
  "slug": "booker",
  "tagline": null,
  "description": null,
  "category": null,
  "website_url": null,
  "install_url": null,
  "support_email": null,
  "privacy_url": null,
  "scopes": ["property:read", "rooms:read", "availability:read", "reservations:read"],
  "scope_labels": {
    "property:read": "See the property's details, policies and what it offers",
    "rooms:read": "See room types, rooms, rate plans and extras",
    "availability:read": "Search availability and prices",
    "reservations:read": "See bookings"
  },
  "status": "DRAFT",
  "client_id": "cba_WID1hm0lWAQFdXATrQ47Qpd5",
  "client_secret_prefix": "cbs__Lp9qcRZ",
  "redirect_uris": ["https://booker.example.com/chatbeds/callback"],
  "webhook_url": null,
  "webhook_signing": false,
  "review_note": null,
  "submitted_at": null,
  "reviewed_at": null,
  "created_at": "2026-10-10T05:09:47+00:00",
  "installs": 0,
  "client_secret": "cbs_••••"
}

The slug is made from the name and becomes your booking source: PARTNER:booker.

Credentials

FormatNotes
Client IDcba_...Public. Goes in the authorize URL and in token requests
Client secretcbs_...Shown once, when the app is made. Keep it on your server

Copy the secret now

ChatBeds keeps only a hash of the client secret. The page later shows just its first characters (cbs__Lp9qcRZ…).

Rotating the secret

Press New client secret, then Yes, make a new one. The new secret is shown once, and the old one stops working at once. Connections and tokens already issued keep working; only calls to /oauth/token and /oauth/revoke need the new secret. Deploy it straight away.

Redirect addresses

Hotels are sent back to one of these after they press Allow or Cancel.

  • Each must be a full https:// address. http://localhost and http://127.0.0.1 are allowed for testing.
  • No #fragment, and at most 500 characters.
  • Up to 10 per app.
  • The redirect_uri you send to the authorize page must match one exactly, character for character. Query strings count.

Scopes

The scopes you tick are the most your app may ever ask for. In each authorize request you may ask for all of them or fewer, never others. See Scopes for what each one unlocks.

Adding scopes later

If your app is already Listed and you add scopes, it goes back to In review. Existing connections keep working with what each hotel allowed.

Webhook

Under Webhook, enter a Webhook address (https) and press Save. ChatBeds shows a signing secret (whsec_...) once. Use it to verify signatures.

  • The address must be https and reachable from the public internet. Private, local and internal addresses are refused.
  • Saving the address again makes a new secret, and the old one stops.
  • The address and secret apply to every connection of the app, including ones made before you changed them.
  • Leave the address empty and save to turn webhooks off.

Only connections where the hotel allowed reservations:read receive booking events. See Webhooks.

Listing details

Under Listing in the Apps directory, fill in what hotels see before they connect. All of these except the website are needed before you can submit for review:

FieldNotes
App nameShown on the directory card and the connect screen
CategoryOne of: Booking channels, Channel managers, Guest messaging, Payments, Revenue, Operations, Accounting, Reviews, Other
TaglineOne short line, up to 140 characters
DescriptionWhat your app does for a hotel, and what it does with their data. Up to 4,000 characters
WebsiteOptional. https://
Install addressWhere the Connect button sends a hotel. Your page then starts the sign-in. https://
Support emailShown on the connect screen
Privacy policy addressShown on the connect screen. https://

Press Save changes. Then see Review and listing.

Try it on your sandbox

Once a redirect address is saved, Try it on your sandbox → Open the connect screen opens the screen a hotel sees. Choose your Sandbox Hotel and press Allow. You are sent to your redirect address with ?code=…&state=test. Swap the code for tokens within 10 minutes, as described in OAuth 2.0.

Building something?

On this page