1. Getting Started
YellowStone
  • Getting Started
    • Introduction
    • Quick Start
    • Authentication
    • General
    • Changelog
  • APIs
    • Booking
      • /api/Booking/PostBooking
    • Fetch
      • /api/Fetch/GetFetchQueueMessage
      • /api/Fetch/UpdateFetchQueueMessage
      • /api/Fetch/health
      • /api/Fetch/healthdb
    • Inventory
      • /api/Inventory/GetInventoryLocations
      • /api/Inventory/GetInventoryItem
    • OnlineBooking
      • /api/OnlineBooking/postreservation
      • /api/OnlineBooking/postinquiry
    • PacesetterItinerary
      • /api/public/PacesetterItinerary/details/{token}
    • RBSCMConnect
      • /api/RBSCMConnect/GetRBSCMConnect
      • /api/RBSCMConnect/UpdateRBSCMConnect
      • /api/RBSCMConnect/GetReservation
    • Reservation
      • /api/Reservation/GetReservations
      • /api/Reservation/GetReservationsForPacesetter
    • Sale
      • /api/Sale/PostSale
    • Schemas
      • Address
      • Addresses
      • AlertRequest
      • ContactInfo
      • ContactInfos
      • DateRange
      • Description
      • Emails
      • GetProperty
      • GetRatePlans
      • GetRatesAvailability
      • GetRoomType
      • GuestRoom
      • HotelDescriptiveContents
      • HotelInfo
      • HotelProperty
      • InquiryCorrespondence
      • InquiryInterest
      • InquiryTag
      • Name
      • Names
      • Occupancy
      • Phone
      • Phones
      • Position
      • PostActivitiesBookedHostsRequest
      • PostActivitiesBookedLocationsRequest
      • PostActivitiesBookedRatesRequest
      • PostActivitiesBookedRequest
      • PostActivitiesBookedResourceRequest
      • PostBookingParametersRequest
      • PostCancellationFeeRequest
      • PostCorrespondenceToBeSentRequest
      • PostGuestsRequest
      • PostInquiryRequest
      • PostPaymentDetailsRequest
      • PostPrimaryGuestDetailsRequest
      • PostRatesRequest
      • PostRequest
      • PostRoomsBookedRequest
      • Prices
      • PropertyResponse
      • RBSCMConnectItem
      • RatePlan
      • RatePlanDescription
      • RatePlanResponse
      • RatePlansContainer
      • Rates
      • RatesAvailabilityResponse
      • ReservationCMRequest
      • ReservationRequest
      • Room
      • RoomDates
      • RoomInfo
      • RoomTypeResponse
      • Rooms
      • SaveExternalPurchaseItemRequest
      • SellableProduct
      • SellableProducts
      • UpdateFetchQueueMessageRequest
  1. Getting Started

Quick Start

For a developer who already has credentials. Follow these five steps and you will have made a successful API call in about ten minutes.
If you do not have credentials yet, ask your RBS administrator — there is no self-service signup. New to the API? Read the Introduction first.

Step 1 — Check what you were given#

Your administrator sends you the following. You cannot work any of them out yourself, so ask if one is missing.
ValueExampleWhat it is
Token base URL ({token_base_url})https://uat-rbsc-api.rbsapps.comWhere you send token requests
Client IDA UUIDIdentifies your application. Safe to log
Client Secret40 charactersYour password. Keep it in a secret manager
AudiencewincloudWhich interface the token is for. Send it on every token request
Permissionsreservations:read rates:writeWhat you are allowed to do
Standard Interface base URL ({base_url})https://uat-api.wincloudone.com/stdinterfaceWhere you send API requests
WARNING
The client secret is shown to your administrator once and cannot be looked up later. If it is lost, the only way forward is to ask your administrator to rotate it.
UAT and production credentials are separate. The steps below use the two base URLs from this table — substitute your own values for {token_base_url} and {base_url}. For the production URLs see Introduction.

Step 2 — Get an access token#

Exchange your Client ID and Secret for a token.
A successful response:
{
  "access_token": "eyJhbGciOiJSUzI1NiIs...",
  "token_type": "Bearer",
  "expires_in": 900,
  "scope": "reservations:read rates:read inventory:read"
}
Three things to note:
expires_in is the token's life in seconds — 900, or 15 minutes. Read this field rather than hardcoding the value.
scope lists the permissions your application actually has.
Always send audience. See the warning below.
DANGER
If you omit audience, the token request still succeeds — but the token is issued without an aud claim and Standard Interface will reject it at step 3. The failure surfaces later and looks unrelated, so it is worth getting right now. For this interface the value is wincloud.
Did this fail? Jump to If step 2 failed.

Step 3 — Make your first call#

Send the token in the Authorization header. Start with the properties endpoint, because it gives you the companyId you need for everything else.
A successful response:
{
  "success": true,
  "message": null,
  "errorCode": null,
  "statusCode": 200,
  "data": {
    "items": [
      {
        "companyId": "1001",
        "companyName": "Grand Riverside Hotel",
        "shortName": "GRH",
        "baseCurrencyId": "INR",
        "countryId": "IN"
      }
    ],
    "pageNumber": 1,
    "pageSize": 10,
    "totalCount": 1,
    "totalPages": 1,
    "hasPrevious": false,
    "hasNext": false
  },
  "timestamp": "2026-08-27T09:14:22.481Z"
}
CHECK
Every successful response uses this same envelope, so once you can read this one you can read them all. See General for the full breakdown.

Step 4 — Use the companyId#

The companyId returned in step 3 identifies a property (a hotel). Almost every other endpoint needs it, passed as a query parameter.
For example, to fetch the room inventory for that property:
If your credentials cover more than one property, call /api/v1/companies once at startup and cache the list rather than hardcoding IDs.

Step 5 — Reuse the token#

DANGER
Do not request a new token for every API call. The token endpoint is rate limited, and requesting a token per call will trip it. This is the single most common cause of a failing integration.
Keep the token in memory and reuse it for its full 15 minutes. Request a replacement about 60 seconds before it expires. There is no refresh token — to renew, call the token endpoint again with the same Client ID and Secret.
One token per process, reused for its full life — roughly four token requests an hour.
A fresh token before each call — hundreds of token requests an hour, then RATE_LIMITED.
If an API call returns 401 Unauthorized, get one fresh token and retry that call once. If it fails again, stop retrying and check your audience, permissions and credentials.

Where to go next#

Authentication
Token lifetime, permissions, and every token error explained.
General
The response envelope, pagination, error handling, retries, rate limits.
Changelog
Changes to the API worth knowing about, newest first.
APIs
Every endpoint, with parameters and schemas — in the sidebar below these pages.

If step 2 failed#

The token endpoint returns an error_code naming the exact problem:
{
  "error_code": "INVALID_CLIENT_CREDENTIALS",
  "error_description": "Client authentication failed",
  "error_uri": null
}
The five you are most likely to hit:
HTTPerror_codeWhat to do
401INVALID_CLIENT_CREDENTIALSRe-copy the client secret and send it as JSON. If it is lost, ask your administrator to rotate it
401AUDIENCE_NOT_REGISTEREDUsually a typo in audience. For this interface it is wincloud
400UNSUPPORTED_GRANT_TYPESend "grant_type": "client_credentials" — it is the only grant supported
422INVALID_REQUEST_BODYA required field is missing, or the body is not valid JSON. Compare against step 2
429RATE_LIMITEDYou are requesting tokens too often. Back off, and reuse the token you already hold
The full list of eleven error codes, with what each one means, is on Authentication.
Modified at 2026-10-07 16:15:40
Previous
Introduction
Next
Authentication
Built with