Read this first. By the end you will know what the API does, how access works, and which environment to point at.The Standard Interface API lets external systems and partners exchange hospitality data with WinCloud — companies, properties, rooms, rates, inventory, reservations, guests, travel agents and the supporting reference data.It is a JSON over HTTPS API. Every request is authenticated with an OAuth 2.0 bearer token. Plain HTTP is not supported.
How access works#
Three parts are involved, and they are not the same system. Getting this straight now saves the most common first-day mistake — sending your token request to the API, or your API request to the token endpoint.| Part | What it does |
|---|
| Token endpoint | The authorization server. It holds your credentials and permissions and issues access tokens. It does not serve any business data. |
| Standard Interface | The API that holds and serves the data. It accepts those tokens and enforces the permissions inside them. This is what this documentation covers. |
| Your application | The consumer. It exchanges its credentials at the token endpoint for a token, then sends that token to Standard Interface. |
A single call therefore looks like this:1
Request an access token
Your application sends its Client ID and Client Secret to the token endpoint.
2
Receive an access token
The token endpoint returns a short-lived access token.
3
Call Standard Interface
Your application sends that token to Standard Interface in the Authorization header.
4
Get your data
Standard Interface verifies the token and enforces the permissions it carries.
Your credentials are tied to one customer and one product, so you only ever reach that customer's data on the interface you were granted.
Environments#
The token host and the API host are different systems. Do not send API requests to the token base URL, and do not send token requests to the Standard Interface base URL.
These tables are the only place the full URLs are written down. Everywhere else in this documentation they appear as {token_base_url} and {base_url} — substitute the values for your environment.Token Endpoints#
| Environment | {token_base_url} |
|---|
| UAT | https://uatapi-rbsc.rbsapps.com |
| Production | https://rbsc-api.rbsapps.com |
The token endpoint is POST {token_base_url}/api/v1/oauth/token. It is the only endpoint on this host.Standard Interface Endpoints#
| Environment | {base_url} |
|---|
| UAT | https://uat-api.wincloudone.com/stdinterface |
| Production | https://api.wincloudone.com/stdinterface |
All resource paths sit beneath this, starting /api/v1/. For example, the companies endpoint in UAT is https://uat-api.wincloudone.com/stdinterface/api/v1/companies.UAT credentials do not work in production, and production credentials must never be used for testing. Store the two sets separately.
What you can do#
The endpoint reference is organised into these folders, listed under APIs in the sidebar.| Folder | What it covers |
|---|
| Properties | Company and property information, including the companyId you need for almost every other call |
| Guests | Guest-related master data and operations |
| Inventory | Retrieve and update room inventory |
| Reference Data | Countries, currencies, payment gateways and payment methods |
| Rates | Rate plans, master rates, individual rates and rate adjustment templates |
| Reservations | Reservation retrieval, cancellations, no-shows and statuses |
| Rooms | Rooms, room types, tariffs, feature types and extra charges |
| Travel Agents | Active travel agents for a property |
Each folder documents request parameters, sample payloads and response schemas for every endpoint.
Before you start#
You need four things, all supplied by your RBS administrator:Client ID and Client Secret — your OAuth credentials
Token base URL and Standard Interface base URL for your environment
Audience — wincloud for this interface
Permissions — what your application is allowed to read and write
There is no self-service signup. Credentials are issued by an administrator, and UAT and production credentials are separate. Request production credentials before you go live, not on the day.
Where to go next#
Quick Start
Get a token and make your first successful call, in about ten minutes.Authentication
The full OAuth flow, permissions, token lifetime, and every token error explained.General
Conventions that apply to every endpoint — response shape, pagination, errors, retries, rate limits.Changelog
Changes to the API worth knowing about, newest first.
Support#
For access requests, credentials that have stopped working, or anything that needs escalation, contact the WinCloud Support Team.When you raise an issue, include the error_code if there is one, the environment, the full URL you called, and the time of the request.Never include your client secret in a ticket, a screenshot, a chat message or a log extract. If a secret has been shared by accident, ask your administrator to rotate it immediately.
Token lifetimes and rate limits are environment settings and can change without a code release. Confirm the values for your environment before relying on them, and verify anything you intend to use for a compliance or contractual purpose.