How to create an API key in your PMS
About 4 minutes · you need administrator access to your PMS environment
Every module from HotelSolutionsMod connects through your PMS’s official API using a scoped credential that you generate yourself. We never ask for your PMS password — the key is the entire handshake, and you can revoke it in seconds.
Step 1 — Sign in as an administrator
Log in to your PMS environment with an account that has administrator rights. If you operate several properties on one group login, switch to the property you want the module to connect to before creating the key — keys are property-scoped.
Step 2 — Open the integrations area
From the main navigation, go to Settings → Integrations (on some editions labelled Settings → API & Integrations). This screen lists every connected service and is where PMS vendor expects third-party connectors to be registered.
Step 3 — Create a new API key
Click Create API key (or “Add integration”). Give it a recognisable label such as “your PMSAddons booking widget” so your future self knows what it belongs to. The label appears in audit logs, so make it specific.
Step 4 — Scope the permissions
This is the important bit. Tick only what the module needs — our activation email for each module lists the exact scope set. As a rule of thumb:
- Read availability / reservations — for widgets, dashboards and parity tools;
- Write reservations — only for booking-widget and sync modules;
- Write rates — only for the rate optimiser, and only if you want auto-apply instead of approval-first.
Least privilege is not just good hygiene: it keeps audit trails readable and means a lost key can do limited damage.
Step 5 — Copy the key once
your PMS shows the full key exactly once. Copy it immediately into a temporary secure note — not an email, not a spreadsheet. If you lose it, delete the key and create a fresh one; there is no recovery view.
Step 6 — Register it in your client area
Paste the key into the activation form in your client area. Our system performs a harmless read-only handshake (it fetches your property name and timezone) before enabling anything. If the handshake fails, the error message tells you whether the key, the scope or the property selection is wrong.
Revoking access later
Back in Settings → Integrations, find the key by its label and delete it. The module loses access immediately and our logs show the disconnect. Configuration data is then removed on the documented 30-day schedule, and you can request certified deletion sooner from support.
Creating the key under the group login but approving it for the wrong property; copying only the visible prefix instead of the full key; ticking “write” scopes “just in case”. If activation fails, re-check those three first — they cover nine out of ten cases.