SAFETY BOUNDARIES ACTIVE
Trust starts with clear boundaries.
Search, booking and booking management share checks for partner identity, permissions and ownership. Each booking change also requires the guest's approval.
PARTNER API
REST v1
Production access for approved partners. Separate sandbox access is arranged during onboarding.
MCP SERVER
Agent integration
Search and booking tools over Streamable HTTP with the same access controls as REST.
BOOKING ACTIONS
Book and manage
Create bookings, cancel under the applicable terms and update traveller contacts with guest approval.
PAYMENTS
Stripe Checkout
Hosted payment for the first instalment and a saved method for subsequent instalments.
01
Identity
Microsoft Entra ID validates short-lived OAuth tokens and application roles.
02
Partner account
APIM subscriptions enable individual approval, rotation and immediate revocation.
03
Least privilege
Booking read, creation, cancellation and contact editing are granted separately for each partner.
04
Guest approval
A signed-in guest reviews and approves the exact action. Approval expires and cannot authorize a different action.
05
Abuse protection
Partner and guest quotas, idempotency and ownership checks limit repeated or unauthorized actions.
06
Separate environments
Sandbox and production use separate access credentials. Production booking permissions require explicit activation.
DATA FLOW
What the partner interface sees
Offer data | Property, room category, amenities, cancellation terms, availability and canonical total price.
Partner data | Organisation, technical contact, Entra client ID, APIM subscription and approved scopes.
Booking data | Authorized integrations send traveller details and read their own reservations and action status. Contact edits are limited to existing travellers' email and phone details.
Payment details | Card numbers are entered on Stripe's hosted page. The partner integration receives the checkout link and booking status.
Availability | The Azure API Management Basic gateway has a 99.95% Microsoft SLA. Backend, payment and accommodation-provider availability are separate; this is not an end-to-end booking SLA.