For a developer who already has credentials. Follow these five steps and you will have made a successful API call in about ten minutes.If you do not have credentials yet, ask your RBS administrator — there is no self-service signup. New to the API? Read the Introduction first.
Step 1 — Check what you were given#
Your administrator sends you the following. You cannot work any of them out yourself, so ask if one is missing.| Value | Example | What it is |
|---|
Token base URL ({token_base_url}) | https://uat-rbsc-api.rbsapps.com | Where you send token requests |
| Client ID | A UUID | Identifies your application. Safe to log |
| Client Secret | 40 characters | Your password. Keep it in a secret manager |
| Audience | wincloud | Which interface the token is for. Send it on every token request |
| Permissions | reservations:read rates:write | What you are allowed to do |
Standard Interface base URL ({base_url}) | https://uat-api.wincloudone.com/stdinterface | Where you send API requests |
The client secret is shown to your administrator once and cannot be looked up later. If it is lost, the only way forward is to ask your administrator to rotate it.
UAT and production credentials are separate. The steps below use the two base URLs from this table — substitute your own values for {token_base_url} and {base_url}. For the production URLs see Introduction.
Step 2 — Get an access token#
Exchange your Client ID and Secret for a token.{
"access_token": "eyJhbGciOiJSUzI1NiIs...",
"token_type": "Bearer",
"expires_in": 900,
"scope": "reservations:read rates:read inventory:read"
}
expires_in is the token's life in seconds — 900, or 15 minutes. Read this field rather than hardcoding the value.
scope lists the permissions your application actually has.
Always send audience. See the warning below.
If you omit audience, the token request still succeeds — but the token is issued without an aud claim and Standard Interface will reject it at step 3. The failure surfaces later and looks unrelated, so it is worth getting right now. For this interface the value is wincloud.
Step 3 — Make your first call#
Send the token in the Authorization header. Start with the properties endpoint, because it gives you the companyId you need for everything else.{
"success": true,
"message": null,
"errorCode": null,
"statusCode": 200,
"data": {
"items": [
{
"companyId": "1001",
"companyName": "Grand Riverside Hotel",
"shortName": "GRH",
"baseCurrencyId": "INR",
"countryId": "IN"
}
],
"pageNumber": 1,
"pageSize": 10,
"totalCount": 1,
"totalPages": 1,
"hasPrevious": false,
"hasNext": false
},
"timestamp": "2026-08-27T09:14:22.481Z"
}
Every successful response uses this same envelope, so once you can read this one you can read them all. See General for the full breakdown.
Step 4 — Use the companyId#
The companyId returned in step 3 identifies a property (a hotel). Almost every other endpoint needs it, passed as a query parameter.For example, to fetch the room inventory for that property:If your credentials cover more than one property, call /api/v1/companies once at startup and cache the list rather than hardcoding IDs.
Step 5 — Reuse the token#
Do not request a new token for every API call. The token endpoint is rate limited, and requesting a token per call will trip it. This is the single most common cause of a failing integration.
Keep the token in memory and reuse it for its full 15 minutes. Request a replacement about 60 seconds before it expires. There is no refresh token — to renew, call the token endpoint again with the same Client ID and Secret.One token per process, reused for its full life — roughly four token requests an hour.
A fresh token before each call — hundreds of token requests an hour, then RATE_LIMITED.
If an API call returns 401 Unauthorized, get one fresh token and retry that call once. If it fails again, stop retrying and check your audience, permissions and credentials.
Where to go next#
Authentication
Token lifetime, permissions, and every token error explained.General
The response envelope, pagination, error handling, retries, rate limits.Changelog
Changes to the API worth knowing about, newest first.APIs
Every endpoint, with parameters and schemas — in the sidebar below these pages.
If step 2 failed#
The token endpoint returns an error_code naming the exact problem:{
"error_code": "INVALID_CLIENT_CREDENTIALS",
"error_description": "Client authentication failed",
"error_uri": null
}
The five you are most likely to hit:| HTTP | error_code | What to do |
|---|
| 401 | INVALID_CLIENT_CREDENTIALS | Re-copy the client secret and send it as JSON. If it is lost, ask your administrator to rotate it |
| 401 | AUDIENCE_NOT_REGISTERED | Usually a typo in audience. For this interface it is wincloud |
| 400 | UNSUPPORTED_GRANT_TYPE | Send "grant_type": "client_credentials" — it is the only grant supported |
| 422 | INVALID_REQUEST_BODY | A required field is missing, or the body is not valid JSON. Compare against step 2 |
| 429 | RATE_LIMITED | You are requesting tokens too often. Back off, and reuse the token you already hold |
The full list of eleven error codes, with what each one means, is on Authentication.