Skip to main content

HotelX Credentials

API Key​

An API key is a unique alphanumeric code used for authentication when accessing the HotelX API. It must be included in the HTTP Authorization request header to verify and authenticate the user agent with the server.

How to Find and Manage Your API Keys:​

  1. Log in to the Travelgate App.
  2. Click on Manage > API Keys in the menu that appears when you click on your user icon in the top right corner.
  3. To create a new API key, click Create New API Key and complete the required form. Copy the API key immediately, as this is the only time it will be fully displayed.
    • Important: Generated API keys cannot be retrieved later. If lost, a new one must be created. Previously used API keys will remain active.
info

Your API key remains the same across both test and production environments.

Access​

An access is a combination of authentication details and configurations that enable a Buyer to connect with a Seller. It helps differentiate Sellers and manage multiple credentials or configurations from the same Seller (e.g., B2B vs. B2C feeds). You can review access details in My Connections.

info
  • Each Seller may have different access credential requirements depending on their system specifications. Some may require only basic fields, while others require additional data or specific URL endpoints for methods such as Search, Quote, or Book. Supplier authorization may rely on a username and password or a Supplier-generated API key (not to be confused with the Travelgate API Key used to authenticate Travelgate users).
  • All access details must be provided and confirmed by each Seller.

To facilitate testing, these accesses have been pre-activated for your account.

How to Obtain an Access Code from an Actual Seller​

To obtain an access code from a Seller, you must establish a commercial agreement with the desired Partner and request activation via the Auto-Activations Form.

important
  • Avoid making live bookings during the HotelX implementation process until Travelgate has certified your development. If you create test bookings, ensure they are canceled and refundable.
  • To ensure proper billing, all cancellations must be handled via the API. If you encounter any issues, contact Customer Support for assistance.

Client​

A client is an entity purchasing accommodation services through the HotelX API. Client codes remain consistent across all Travelgate implementations and help identify the requesting business and its assigned configurations.

Multiple client codes may be used to distinguish different traffic types, such as B2B and B2C transactions (e.g., client_b2b, client_b2c). Since all accesses are compatible with any client code, selecting the appropriate one is essential. You can review client information in your API Settings.

Context​

A context represents the content codes used by Buyers and Sellers. Each Seller has a unique context, which may differ between test and production environments. Context codes include specific hotel, board, and room codes. This information is available in My Connections.

Buyers can use FastX context (highly recommended), their own Buyer context, or Supplier context. Buyer context codes are generated by the Buyer (not by Travelgate) and are used in mapping file names to align Supplier codes with Buyer-mapped codes. Use Buyer context only when your own code system is a hard requirement. Use Supplier context only for supplier-native scenarios. For more information, see the Mapping Plugin.

Context Decision Matrix​

ModeBest forsettings.context usageMulti-supplier behaviorSearch by Destination pluginCodes returned in booking flow
FastX (Recommended)Standardized content codes, simpler maintenance, aggregation across suppliers. It reduces mapping complexity and improves scalability.Optional. You can set "context": "FASTX" or omit context when sending FastX hotel codes.Designed for multi-supplier requests and aggregation in one query.Not compatible.FastX codes are returned in standard fields. Supplier values are available in supplier fields (for example hotelCodeSupplier, boardCodeSupplier, rooms.supplierCode).
Buyer contextBuyers that must operate with their own hotel/board/room/rate codes, or manage plugin files by Buyer-context naming (for example mapping files)Required (your Buyer context code).Can work across multiple accesses/suppliers when mappings are configured for those connections.Not compatible.Response keeps supplier information and mapped Buyer codes for mapped entities.
Supplier contextSupplier-native flows, supplier troubleshooting, supplier-only featuresRequired (supplier context code).Scoped per request to one supplier context. You can include multiple accesses only if they share that same supplier context.Compatible (required mode).Supplier-context values. In booking flow (Search/Quote/Book), FastX information is not returned when using supplier context.
What is the Difference Between Access and Context?
  • Access contains your authentication credentials for a specific connection.
  • Context is the internal Travelgate code required to request Supplier codes or mapped Buyer codes (uploaded to our SFTP).

For more details, refer to the HotelX Buyers API Documentation and API Settings.

What is the difference in credential management between Legacy and HotelX?​

Besides using different technologies (XML vs GraphQL) and offering different levels of functionality, the main difference between Legacy API (deprecated) and HotelX API lies in how supplier credentials are selected, stored, and used in requests.

In the Legacy API, the Buyer must explicitly send the supplier configuration in every request—username, password, and any additional supplier parameters—directly in the XML payload. The Buyer was fully responsible for managing, storing, and updating these credentials.

In HotelX, supplier credentials are not sent in the API request. Instead, the Buyer sends an access code that references a supplier configuration securely stored in the Travelgate platform. Credentials are managed centrally through My Connections, and authentication is handled using the Travelgate API Key in the request headers.

This approach makes HotelX more secure, easier to maintain, and better suited for complex multi-supplier integrations.

Do I need to create new accesses when migrating from Legacy?​

Not necessarily. If your supplier credentials already appear in My Connections with an associated access code, you do not need to create new accesses—you can reuse the same access codes in HotelX.

What is the difference between a Travelgate API Key and a Supplier API Key?​

These are two distinct concepts that are often confused:

  • The Travelgate API Key authenticates you to Travelgate. It is sent in the request headers, is not supplier-specific, and is never stored inside an access configuration.
  • The Supplier API Key (when required) authenticates your connection to a specific Supplier. It is stored securely inside the access configuration in Travelgate and is never sent directly in your API requests.
tip

For full details on setting up your credentials and running your first requests, check out our HotelX Pull Buyers API Quickstart. 🚀