Developer docs
Staying exposes two integration interfaces: an inbound booking webhook for property management systems, and per-property iCal feeds. There is no general public REST API for reading or writing Staying data today.
If your integration needs something these interfaces do not cover, tell us what you are trying to build.
Last reviewed: October 2026
Inbound booking webhook
POST https://staying.co/api/webhooks/pms/{provider}
provider is one of guesty, hostaway, ownerrez, hospitable or lodgify. The integration (and its signing secret) is created per property in Admin → Properties → Integrations.
Signature verification
Every request must carry an HMAC-SHA256 of the raw request body, keyed with the integration's signing secret, as lowercase hex. A sha256= prefix is accepted. Comparison is constant-time.
guesty:x-guesty-signatureorx-signaturehostaway:x-hostaway-signatureorx-signatureownerrez:x-ownerrez-signatureorx-signaturehospitable:x-hospitable-signatureorx-hub-signature-256lodgify:x-lodgify-signatureorx-signature
SIGNATURE=$(printf '%s' "$BODY" | openssl dgst -sha256 -hmac "$SECRET" -hex | cut -d' ' -f2)
curl -X POST https://staying.co/api/webhooks/pms/hostaway \
-H "Content-Type: application/json" \
-H "x-hostaway-signature: sha256=$SIGNATURE" \
--data "$BODY"Payload
The event name is read from type, event or eventType and mapped to created, updated or cancelled (names containing "creat"/"new", "updat"/"modif"/"chang", or "cancel"/"delet"/"remov"). Other events are acknowledged and ignored.
The booking object is read from data (Guesty, Hostaway, Lodgify), booking or data (Hospitable), or payload or data (OwnerRez). Recognised fields:
idorexternalId(required)checkIn/checkInDate/check_inandcheckOut/checkOutDate/check_out(required, ISO dates)guestName,guestEmail,status,nights,totalAmountortotal_price,source,notes(optional)
{
"event": "booking.created",
"data": {
"id": "RES-10442",
"guestName": "Emma Thompson",
"guestEmail": "emma@example.com",
"checkIn": "2026-07-14",
"checkOut": "2026-07-18",
"status": "confirmed",
"totalAmount": 1240,
"source": "Airbnb"
}
}Responses
200 { "received": true }: accepted, or an unknown event type that was ignored400: unknown provider or invalid JSON401: missing or invalid signature404: no active integration with a signing secret for this provider500: processing error; safe to retry
Webhooks are processed idempotently per booking id: a repeated event updates the same stay.
iCal feeds
Each property has a private export feed at https://staying.co/ical/{token}, copied from the channel settings in the admin. It lists upcoming reserved and checked-in stays as busy dates so OTAs can block them. Treat the URL as a secret: anyone with it can read your availability.
To import, paste an OTA's iCal export URL into the channel settings. Imported events become blocked dates and bookings in Staying.
What is not available
- No REST or GraphQL API for properties, guests, orders or bookings.
- No outbound webhooks from Staying to your systems.
- No API keys or OAuth apps for third-party developers.