Skip to main content
Developers

Developer docs

Staying exposes two integration interfaces: an inbound booking webhook for property management systems, and per-property iCal feeds. There is no general public REST API for reading or writing Staying data today.

If your integration needs something these interfaces do not cover, tell us what you are trying to build.

Last reviewed: October 2026

Inbound booking webhook

POST https://staying.co/api/webhooks/pms/{provider}

provider is one of guesty, hostaway, ownerrez, hospitable or lodgify. The integration (and its signing secret) is created per property in Admin → Properties → Integrations.

Signature verification

Every request must carry an HMAC-SHA256 of the raw request body, keyed with the integration's signing secret, as lowercase hex. A sha256= prefix is accepted. Comparison is constant-time.

  • guesty: x-guesty-signature or x-signature
  • hostaway: x-hostaway-signature or x-signature
  • ownerrez: x-ownerrez-signature or x-signature
  • hospitable: x-hospitable-signature or x-hub-signature-256
  • lodgify: x-lodgify-signature or x-signature
SIGNATURE=$(printf '%s' "$BODY" | openssl dgst -sha256 -hmac "$SECRET" -hex | cut -d' ' -f2)
curl -X POST https://staying.co/api/webhooks/pms/hostaway \
  -H "Content-Type: application/json" \
  -H "x-hostaway-signature: sha256=$SIGNATURE" \
  --data "$BODY"

Payload

The event name is read from type, event or eventType and mapped to created, updated or cancelled (names containing "creat"/"new", "updat"/"modif"/"chang", or "cancel"/"delet"/"remov"). Other events are acknowledged and ignored.

The booking object is read from data (Guesty, Hostaway, Lodgify), booking or data (Hospitable), or payload or data (OwnerRez). Recognised fields:

  • id or externalId (required)
  • checkIn / checkInDate / check_in and checkOut / checkOutDate / check_out (required, ISO dates)
  • guestName, guestEmail, status, nights, totalAmount or total_price, source, notes (optional)
{
  "event": "booking.created",
  "data": {
    "id": "RES-10442",
    "guestName": "Emma Thompson",
    "guestEmail": "emma@example.com",
    "checkIn": "2026-07-14",
    "checkOut": "2026-07-18",
    "status": "confirmed",
    "totalAmount": 1240,
    "source": "Airbnb"
  }
}

Responses

  • 200 { "received": true }: accepted, or an unknown event type that was ignored
  • 400: unknown provider or invalid JSON
  • 401: missing or invalid signature
  • 404: no active integration with a signing secret for this provider
  • 500: processing error; safe to retry

Webhooks are processed idempotently per booking id: a repeated event updates the same stay.

iCal feeds

Each property has a private export feed at https://staying.co/ical/{token}, copied from the channel settings in the admin. It lists upcoming reserved and checked-in stays as busy dates so OTAs can block them. Treat the URL as a secret: anyone with it can read your availability.

To import, paste an OTA's iCal export URL into the channel settings. Imported events become blocked dates and bookings in Staying.

What is not available

  • No REST or GraphQL API for properties, guests, orders or bookings.
  • No outbound webhooks from Staying to your systems.
  • No API keys or OAuth apps for third-party developers.