Incremental HTTPS polling for new, modified, and cancelled reservations. Authentication, cursor sync, and response schema reference.
MixDorm Connectivity V1
A partner API for PMS and channel managers
MixDorm Connectivity V1 is a versioned REST/JSON surface for inventory (ARI) and reservation events. It is not a public self-serve product. Credentials are issued only after human approval.
- No generic
/{channel}/webhookdispatcher. - No body-level shared_secret as the V1 auth model.
- No “all endpoints return HTTP 200” — parse real HTTP status codes.
- No isolated sandbox environment; Pilot/Test Connection is ops-gated.
- No OTA/HTNG XML in V1.
- No public OpenAPI download without issued credentials.
Partner Connectivity
Dedicated API references for certified channel manager integrations.
Two surfaces
Partner Connectivity V1 (JSON)
Implemented — ops-gatedVersioned /api/connectivity/v1. Signed request auth (preferred) or OAuth client credentials. Durable partner connections, catalog mapping, atomic ARI write-through to MixDorm inventory, idempotency, and reservation lifecycle foundations. Feature-flagged; not self-serve.
Existing certified PMS connectors
Live (legacy)Cloudbeds (/clouds), HostelMate (/hostelmate), eZee (/ezee), Mews (/mews) keep their own contracts. New partners should not integrate against those mounts.
OTA 2003B / HTNG XML
Not supported in V1Not implemented. Not available on request. Do not plan an FDM integration on OTA/HTNG.
Who calls whom
Partner → MixDorm
POST /oauth/token or signed headers · GET /auth/health · GET /catalog/rooms · GET /catalog/rate-plans · POST /ari · POST /reservations/ack
MixDorm → Partner
HTTPS callback with reservation.created / .modified / .cancelled envelopes (HMAC MixDorm-Signature). Adapter-specific payload mapping may apply.
Security overview
- Signed requests (X-MixDorm-Key-Id / Timestamp / Signature) or OAuth client credentials.
- Per-connection credentials; hashed client secrets; sealed signing secrets; one-time reveal.
- Fail-closed auth — no warn-through, no HealthCheck bypass.
- Atomic ARI with currency fail-closed (no USD invent).
- Idempotency-Key on mutations; HMAC outbound webhooks with replay window.
Lifecycle
Approved partners receive authenticated OpenAPI and guides from the API after credentials are issued. Base path: /api/connectivity/v1. FrontDesk Master integration guide: /developers/connectivity/frontdesk-master.