If you want another system to call this app’s API directly — without a signed-in browser session — create an API key from the API Keys section at the top of the API reference page (org-admin only).
Creating a key
Give it a name (so you can tell keys apart later, e.g. “Zapier integration”) and click Create key. The full key is shown once, immediately — copy it before leaving the page. It cannot be shown again afterward: only a one-way hash of it is ever stored, so even this app has no way to recover it later. If you lose it, revoke it and create a new one.
Using a key
Send it as a bearer token:
curl -H "Authorization: Bearer <your key>" https://your-app-domain/api/properties/<propertyId>/orders
A valid key works on every endpoint documented on the API page, including admin-only ones (FTP settings, token purchases) — a key is exactly as powerful as the admin who created it. It cannot, however, create or revoke other keys itself, so a leaked key can’t be used to mint itself replacements.
Building an integration with an AI coding agent
If you’re using Claude Code or another AI coding agent to build against
this API, point it at
robooko/booking-schema-api-skill
— an agent skill covering the auth model, full endpoint reference, and
integration gotchas (e.g. order import needing a confirmed field mapping
first). Install with npx skills add robooko/booking-schema-api-skill.
Revoking a key
Click Revoke next to any key in the list. A revoked key stops working immediately and stays listed (marked revoked) rather than disappearing, so you keep a record of what existed and when it was retired.