This Quickstart Guide provides basic information on the API key authentication required to access Cloudbeds API resources. This guide will help you quickly get an API key to start using with your authentication.
If you are a technology partner, you can create a property-level API key to get started with your development quickly. However, you will need to implement API Keys support at partner level according to our API Keys Authentication Guide for Technology Partners before the certification process.
For the OAuth 2.0 authentication method, see Alternative OAuth 2.0 authentication method.
Cloudbeds believes every lodging business is unique. We offer tools for different property sizes and budgets to help you establish and grow your business. Contact our dedicated team for more information about available packages.
Not yet a Cloudbeds customer? Review our Pricing Guide and schedule a demo.
Before you create API credentials
Before creating API credentials, open the API Credentials page in Cloudbeds. What you see on this page depends on whether API access is already included in your Cloudbeds package.
If API access is not included in your package: You will see a Submit API Access Form button instead of the options to create credentials. Submit the form to request API access and a quote from the Customer Growth Team.
The example below shows the API Credentials page when API access still needs to be requested.
Once API access is enabled for your account, return to the API Credentials page and continue with the steps below.
1. Creating API Credentials
Play this video to understand the process of creating API keys
Once API access is enabled, create the integration first. Then generate its API key, select the required permissions and properties, and authorize the connection.
-
Log in to your Cloudbeds account at https://signin.cloudbeds.com/ and navigate to:
Account
-> Apps & Marketplace
- Open the API Credentials tab.
-
Click + New Credentials.
The API Credentials page shows your existing integrations and the + New Credentials button used to start a new one.
You may also edit previously created Client Credentials if you want to convert that entry. In this case, skip to step 6.
-
Complete the new API integration details:
- Enter the Name of your integration or application.
- Select the Integration Type that best matches your application.
- Because API-Key use does not require a functioning Redirect URL, you may enter https://localhost in the Redirect URI field.
- Enable Enable for Entire Organization if you want the integration to be available across multiple properties in the organization.
- Click Save in the lower right corner.
The New API Integration form contains the integration name, type, redirect URI, and organization-wide setting.
-
Cloudbeds creates Client Credentials containing a Client ID and Client Secret. These attributes are not required in the payload of an API-key-enabled request, so you can close the dialog and continue with API key creation.
The confirmation dialog also reminds you that the Client Secret cannot be viewed again after the dialog is closed.
-
Find the integration in the API Credentials table. In the API Key column, click Create.
The newly created integration appears as a row in the API Credentials table before an API key has been generated.
-
Once you click the Create button within the desired row, you will be presented with a list of API Scopes that you may select.
Scope selections should align with the API endpoints you plan to use. See About Cloudbeds API for more information.
-
Select the required scopes by checking each permission, then click Create.
The New API Key dialog groups the available Read, Write, and Delete permissions by API scope.
-
Select which properties you want the application to connect to. Choose Connect all properties to generate keys that work for all properties within the organization, and click Continue.
-
Review the permissions the application is requesting, then click Allow Access.
The authorization page lists the permission scopes that will be shared with the application before access is granted.
-
Cloudbeds generates the API key after authorization.
Copy and store the API key immediately. The complete API key is only displayed when it is created. Once you close the dialog, you will not be able to view that API key again. Store it in a secure credential manager or another secure location.
The API Key Created dialog displays the key together with the reminder that it cannot be viewed again after the dialog is closed.
2. Using your API Key
You can now use the API key to access the Cloudbeds API by including the API key in the request header as x-api-key or as a bearer token.
Here are some examples:
curl --location '<https://hotels.cloudbeds.com/api/v1.2/getHotels'> \--header 'Authorization: Bearer cbat_EE*** ' \
curl --location '<https://hotels.cloudbeds.com/api/v1.2/getHotels'> \--header 'x-api-key: cbat_EE*** ' \
3. Deleting or Replacing an API Key
You can remove or regenerate a key at any time. In the API Credentials table, locate the API Key column and use the available action for the key.
The API Credentials table keeps the saved API key masked after creation.
When a key is removed or regenerated, the old key will no longer be available to access the API.
FAQ
Do API Keys expire?
They won’t expire, as long as they are used at least once every 30 days.
How to add additional permission scopes after an API key is created?
Access the API Credentials tab, find the API Key column for the relevant API credentials, and click the Trash button to delete the API key.
Once deleted, you can create a new API key with the correct permission scopes.
How to add API keys in Postman?
You can include your API key in the Postman Authorization tab as API key or Bearer token.
Are API keys supported for organization/group accounts at the property level?
Organization users who want to enable API access for multiple properties can select Enable for Entire Organization when completing the New API Integration form in step 4 of Creating API Credentials. During authorization, they can then select which properties the application should connect to.
Keep API keys secure. Cloudbeds makes reasonable efforts to ensure that API keys are not exposed in public-facing repositories such as GitHub or GitLab. If an API key is compromised through public exposure, Cloudbeds may disable the key and require you to create a replacement key and update your integration.
- For more information on policies, pricing, and use cases, see Property and Group Account API Access.
Comments
Please sign in to leave a comment.