If you want another system to call this app’s API directly — without a signed-in browser session — create an API key from the API Keys section at the top of the API reference page (org-admin only).

Creating a key

Give it a name (so you can tell keys apart later, e.g. “Zapier integration”) and click Create key. The full key is shown once, immediately — copy it before leaving the page. It cannot be shown again afterward: only a one-way hash of it is ever stored, so even this app has no way to recover it later. If you lose it, revoke it and create a new one.

Using a key

Send it as a bearer token:

curl -H "Authorization: Bearer <your key>" https://your-app-domain/api/properties/<propertyId>/orders

A valid key works on every endpoint documented on the API page, including admin-only ones (FTP settings, token purchases) — a key is exactly as powerful as the admin who created it. It cannot, however, create or revoke other keys itself, so a leaked key can’t be used to mint itself replacements.

Building an integration with an AI coding agent

If you’re using Claude Code or another AI coding agent to build against this API, point it at robooko/booking-schema-api-skill — an agent skill covering the auth model, full endpoint reference, and integration gotchas (e.g. order import needing a confirmed field mapping first). Install with npx skills add robooko/booking-schema-api-skill.

Revoking a key

Click Revoke next to any key in the list. A revoked key stops working immediately and stays listed (marked revoked) rather than disappearing, so you keep a record of what existed and when it was retired.