Authentication

Send your API key in a header. Never in the query string.

Log in to see your API keys
API KeyLabelLast Used

Every call authenticates with an API key issued by the hotel.

X-API-Key: axis_live_…

Authorization: Bearer axis_live_… is accepted as an alternative transport for
the same key.

A key in the query string is never accepted — it would end up in access logs,
browser history and referrer headers.

The key is the account

You never send an account identifier. The key resolves it.

X-Property is different: send it only when your key covers more than one
property. A key scoped to exactly one infers it, and sending a different id
answers 404. See
Scopes and the X-Property header.

When it fails

An unknown, expired, revoked or deactivated key all answer the same
401 APIKEY_INVALID. Distinguishing them would tell an attacker which guesses
are close.

Two failures do get their own code, because they are actionable: APIKEY_MISSING
(a wiring mistake) and TENANT_INACTIVE (an account state the hotel can fix).

A valid key missing a scope answers 403 APIKEY_SCOPE_MISSING, and the message
names the scope — the one place we are deliberately more helpful, because the
caller has already proved who they are.

Full detail in Authentication and API keys.

Credentials
LoadingLoading…
Response
Click Try It! to start a request and see the response here!

Did this page help you?