ChatBedsDevelopers
Apps and OAuth

Scopes

The permissions an app can ask for, what the hotel sees for each, and which operations each one unlocks.

Scopes limit what an app token may do. You choose the most your app may ask for when you register it; each authorize request asks for those or fewer; the hotel sees each one in plain words and allows them together.

API keys made by hand on Settings → Partner API have no scopes: they can do everything at their property.

The scopes

ScopeWhat the hotel seesOperations it unlocks
property:readSee the property's details, policies and what it offersGET /properties, GET /properties/{id}/policies
rooms:readSee room types, rooms, rate plans and extrasGET /properties/{id}/room-types, /rate-plans, /units, /extras
availability:readSearch availability and pricesGET /properties/{id}/offers
reservations:readSee bookingsGET /reservations/{id}, GET /properties/{id}/reservations, and booking webhooks
reservations:writeMake, change and cancel bookingsPOST /properties/{id}/reservations, PATCH /reservations/{id}, POST /reservations/{id}/cancel, POST /reservations/{id}/extras
folios:readSee guests' bills and paymentsGET /reservations/{id}/folio, GET /payments/{id}
folios:writeAdd charges and record payments on billsPOST /reservations/{id}/folio/charges, POST /reservations/{id}/folio/payments
payments:writeCreate card payment links on the hotel's Stripe accountPOST /reservations/{id}/payment-link

GET /me and GET /capabilities need no scope. Every connected app can call them.

Write doesn't include read

Each scope stands alone. An app that books with reservations:write and then reads the booking back needs reservations:read as well. The same goes for folios:write and folios:read.

Webhooks need reservations:read

A connection receives booking webhooks only if the hotel allowed reservations:read. Without it, nothing is sent to your webhook address for that property, even if the address is set.

A missing scope

Calling an operation the hotel didn't allow answers 403. Nothing is done.

403 Forbidden
{
  "detail": "This connection was not allowed 'reservations:write'. Ask the hotel to connect the app again with that scope."
}

To get a scope you don't have:

  1. Make sure it is ticked on your app. If your app is Listed, adding a scope sends it back to review; existing connections keep working meanwhile.
  2. Send the hotel through the consent page again, asking for the new scope. The hotel picks the same property and sees it as already connected; allowing again updates what your app may do there.

The scope field of every token response tells you exactly what the connection may do. Check it rather than assuming.

Ask for the fewest

Hotels see every scope you ask for before they press Allow, and reviewers check that each one is needed.

You're buildingYou probably need
A booking site or channelproperty:read, rooms:read, availability:read, reservations:read, reservations:write
A channel manager or PMS syncrooms:read, availability:read, reservations:read, reservations:write
A guest messaging toolproperty:read, reservations:read
An accounting exportreservations:read, folios:read
A payments toolreservations:read, folios:read, folios:write, payments:write

Ask for a scope when a feature needs it, not in case it might.

Building something?

On this page