Skip to content

Hotel Supplier API (1.0) ​

Download OpenAPI specification: Download · Download Postman collection: Download

Tourmind hotel pull API for supplier

Integration Process ​

  1. The supplier develops and tests the API.
  2. The supplier provides the test environment URL, api key, and secret. Tourmind will create some test bookings.
  3. The supplier completes the production environment configuration and provides the production environment URL, api key, and secret.
  4. Tourmind creates a cancellable test booking in the production environment.
  5. Go live

Authentication ​

All endpoints require an Authorization header using HMAC-SHA256 signature scheme.

Signature Generation Steps ​

  1. Get the current Unix timestamp (integer seconds): timestamp
  2. Concatenate the signature input: message = apiKey + apiSecret + timestamp
  3. Compute HMAC-SHA256 of message using apiSecret as the key, then Base64-encode the result to get signature
  4. Assemble the Authorization header: HMAC-SHA256 apikey={apiKey}, timestamp={timestamp}, signature={signature}

Example ​

Authorization: HMAC-SHA256 apikey=myApiKey, timestamp=1715000000, signature=Base64EncodedHmacSha256Result

Postman Script ​

const CryptoJS = require('crypto-js');

const apiKey = pm.environment.get("apiKey");
const apiSecret = pm.environment.get("secret");

if (!apiKey || !apiSecret) {
    console.error("Missing apiKey or secret");
    return;
}

const timestamp = Math.floor(Date.now() / 1000);

const message = apiKey + apiSecret + timestamp.toString();

const signature = CryptoJS.HmacSHA256(message, apiSecret).toString(CryptoJS.enc.Base64);

const authHeader = `HMAC-SHA256 apikey=${apiKey}, timestamp=${timestamp}, signature=${signature}`;

pm.request.headers.upsert({
    key: "Authorization",
    value: authHeader
});

Parameter Reference ​

ParameterDescription
apiKeyThe API key is provided by the supplier
apiSecretThe API Secret is provided by the supplier
timestampUnix timestamp (seconds) at request time; server allows ±300 seconds tolerance
signatureBase64-encoded result of HMAC-SHA256(apiKey + apiSecret + timestamp, apiSecret)

Availability & Booking ​

Search for bookable hotels and rooms that meet specific criteria. Note: When searching for multiple rooms, the same room type and rate plan apply to all rooms, but each room may have a different occupancy count. The returned price is the total amount (including taxes and fees, if applicable) for all rooms.

API Call Schema

NameValue
Request URL/search
Request methodPOST
Request Fields
hotels[]: stringRequired
List of hotel codes to search. Maximum 30 hotels per request.
checkIn: stringRequired
Format: YYYY-MM-DD, e.g. 2025-08-15
checkOut: stringRequired
Format: YYYY-MM-DD. Must be after checkIn, e.g. 2025-08-16
language: string
Language for response content, e.g. en-US, zh-CN. Defaults to English if not provided.
currency: string
Desired price currency as ISO 4217 code, e.g. USD, CNY. Defaults to the supplier's base currency if not provided.
nationality: string
ISO 3166-1 alpha-2 country code, e.g. CN, US. Affects pricing and tax rates for some suppliers.
timeout: integer
Timeout in milliseconds.
requestId: stringRequired
A UUID generated by the caller for tracing and troubleshooting. Returned as-is in the response.
Response Fields
requestId: stringRequired
Matches the requestId sent in the request.
json
{
  "hotels": [
    "12345",
    "67891"
  ],
  "checkIn": "2026-08-15",
  "checkOut": "2026-08-16",
  "occupancies": [
    {
      "roomId": 1,
      "adults": 2,
      "childrenAges": [
        8
      ]
    },
    {
      "roomId": 2,
      "adults": 2,
      "childrenAges": [
        8
      ]
    }
  ],
  "currency": "USD",
  "nationality": "US",
  "timeout": 3000,
  "requestId": "16c74e57-9a86-4e17-843c-3dd66cf84788"
}
json
{
  "requestId": "16c74e57-9a86-4e17-843c-3dd66cf84788",
  "errors": null,
  "data": [
    {
      "hotelCode": "12345",
      "hotelName": "Hotel Name",
      "rooms": [
        {
          "roomType": {
            "code": "12345#DBL",
            "name": "Single room city view",
            "area": 25,
            "bedTypes": [
              {
                "code": "DBL",
                "name": "single bed",
                "quantity": 1
              }
            ],
            "maxOccupancy": 1,
            "maxAdults": 1,
            "maxChildren": 0,
            "relatedCode": {
              "Expedia": "1352345323",
              "HotelBed": "3432423423"
            }
          },
          "options": [
            {
              "token": "12345|12345#DBL#16#RF#32235",
              "ratePlanCode": "17",
              "ratePlanName": "Room Only",
              "mealPlan": {
                "code": "RO",
                "name": "Room Only",
                "isIncludeChildren": false
              },
              "price": {
                "net": 99.99,
                "gross": 99.99,
                "currency": "USD",
                "commission": 0
              },
              "fees": [
                {
                  "type": "TAX_AND_SERVICE_FEE",
                  "name": "tax and service fee",
                  "amount": 12.12,
                  "currency": "USD",
                  "included": false
                },
                {
                  "type": "EXTRA_PERSON_FEE",
                  "name": "Resort Fee",
                  "amount": 12.12,
                  "currency": "USD",
                  "included": true
                }
              ],
              "taxes": [
                {
                  "type": "CITY_TAX",
                  "name": "city tax",
                  "amount": 12.12,
                  "currency": "USD",
                  "included": false
                }
              ],
              "refundable": true,
              "cancelPenalties": [
                {
                  "deadline": "2026-04-17T16:58:48.131Z",
                  "penaltyType": "PERCENT",
                  "value": 100,
                  "currency": "USD"
                },
                {
                  "deadline": "2026-04-15T16:58:48.131Z",
                  "penaltyType": "AMOUNT",
                  "value": 20.2,
                  "currency": "USD"
                }
              ],
              "nightlyRate": {
                "2026-04-17": {
                  "net": 99.99,
                  "gross": 99.99,
                  "allotment": 9
                }
              },
              "allotment": 9,
              "onRequest": false,
              "remark": ""
            }
          ]
        }
      ]
    }
  ]
}

Prebook ​

Call this API before making a reservation. This operation will verify the real-time price and availability of the selected room type and return a bookingToken for use in subsequent booking requests. The bookingToken must be valid for at least 10 minutes. Timeout: 12s

API Call Schema

NameValue
Request URL/prebook
Request methodPOST
Request Fields
requestId: stringRequired
A UUID generated by the caller for tracing.
hotelCode: stringRequired
checkIn: stringRequired
Format: YYYY-MM-DD
checkOut: stringRequired
Format: YYYY-MM-DD. Must be after checkIn.
roomCode: stringRequired
Room type code from the search results (SearchRoom.roomType.code).
ratePlanCode: stringRequired
Rate plan code from the search results (Option.ratePlanCode).
optionToken: string
The Option.token from the search results. Required by some suppliers to precisely identify the rate.
nationality: string
ISO 3166-1 alpha-2 country code, e.g. CN, US.
Response Fields
requestId: stringRequired
Matches the requestId sent in the request.
json
{
  "requestId": "16c74e57-9a86-4e17-843c-3dd6653453434",
  "hotelCode": "12345",
  "checkIn": "2026-03-23",
  "checkOut": "2026-03-24",
  "occupancies": [
    {
      "roomId": 1,
      "adults": 2,
      "childrenAges": null
    }
  ],
  "roomCode": "12345#DBL",
  "ratePlanCode": "1734534",
  "optionToken": "12345|12345#DBL#16#RF#32235",
  "nationality": "US"
}
json
{
  "requestId": "16c74e57-9a86-4e17-843c-3dd6653453434",
  "errors": null,
  "data": {
    "hotelCode": "12345",
    "hotelName": "hotel name",
    "roomCode": "12345#DBL",
    "roomName": "Single room city view",
    "ratePlanCode": "17",
    "ratePlanName": "Room Only",
    "bookingToken": "12345|12345#DBL#16#RF#32235|2026-03-23|2026-03-24|2",
    "mealPlan": {
      "code": "RO",
      "name": "Room Only",
      "isIncludeChildren": true
    },
    "price": {
      "net": 99.99,
      "gross": 99.99,
      "currency": "USD",
      "commission": 0
    },
    "fees": [
      {
        "type": "VALUE_ADDED_TAX",
        "name": "Resort Fee",
        "amount": 12.12,
        "currency": "USD",
        "included": false
      }
    ],
    "taxes": [
      {
        "type": "VALUE_ADDED_TAX",
        "name": "Resort Fee",
        "amount": 12.12,
        "currency": "USD",
        "included": true
      }
    ],
    "nightlyRate": {
      "2026-04-17": {
        "net": 99.99,
        "gross": 99.99,
        "allotment": 2
      }
    },
    "refundable": true,
    "cancelPenalties": [
      {
        "deadline": "2026-08-03T14:15:22.123Z",
        "penaltyType": "PERCENT",
        "value": 100,
        "currency": "USD"
      }
    ],
    "allotment": 2,
    "onRequest": true,
    "remark": ""
  }
}

Booking ​

The Booking operation requests a reservation confirmation for the specified rate option Timeout: 60s.

API Call Schema

NameValue
Request URL/booking
Request methodPOST
Request Fields
requestId: stringRequired
A UUID generated by the caller for tracing and idempotency control.
referenceId: stringRequired
Tourmind Booking id
hotelCode: stringRequired
checkIn: stringRequired
Format: YYYY-MM-DD
checkOut: stringRequired
Format: YYYY-MM-DD
bookingToken: stringRequired
From Prebook Response.data.bookingToken.
totalPrice: numberRequired
From Prebook Response.data.price.net.
currency: stringRequired
Currency for totalPrice as an ISO 4217 code, e.g. USD, CNY.
nationality: string
ISO 3166-1 alpha-2 country code, e.g. CN, US.
customerRequirements: string
Response Fields
requestId: stringRequired
Matches the requestId sent in the request.
json
{
  "requestId": "16c74e57-9a86-4e34-843c-3dd66534ef434",
  "referenceId": "532432532",
  "hotelCode": "12345",
  "checkIn": "2026-08-24",
  "checkOut": "2026-08-25",
  "bookingToken": "12345|12345#DBL#16#RF#32235|2026-03-23|2026-03-24|2",
  "holder": {
    "firstName": "Shan",
    "lastName": "Zhang",
    "phone": "13212341234",
    "email": "xxx@xx.com"
  },
  "occupancies": [
    {
      "roomId": 1,
      "paxes": [
        {
          "firstName": "Shan",
          "lastName": "Zhang",
          "type": "ADULT"
        },
        {
          "age": 8,
          "type": "CHILD"
        }
      ]
    }
  ],
  "totalPrice": 99.99,
  "currency": "USD",
  "nationality": "US",
  "customerRequirements": "xxxxx"
}
json
{
  "requestId": "16c74e57-9a86-4e34-843c-3dd66534ef434",
  "errors": null,
  "data": {
    "bookingCode": "fef2fsf",
    "status": "CONFIRMED",
    "referenceId": "532432532",
    "hotelConfirmationNumber": "KHKHG324",
    "hotelCode": "12345",
    "hotelName": "hotel name",
    "checkIn": "2026-08-24",
    "checkOut": "2026-08-25",
    "holder": {
      "firstName": "Shan",
      "lastName": "Zhang",
      "phone": "13212341234",
      "email": "xxx@xx.com"
    },
    "rooms": [
      {
        "roomId": 1,
        "paxes": [
          {
            "firstName": "Shan",
            "lastName": "Zhang",
            "type": "ADULT"
          },
          {
            "age": 8,
            "type": "CHILD"
          }
        ]
      }
    ],
    "totalPrice": 99,
    "penaltyAmount": 0,
    "currency": "USD",
    "commission": 0,
    "cancelPenalties": [
      {
        "deadline": "2026-08-03T14:15:22.123Z",
        "penaltyType": "PERCENT",
        "value": 100,
        "currency": "USD"
      }
    ],
    "remark": "",
    "customerRequirements": "xxxxx",
    "bookedTime": "2026-08-20T14:15:22.123Z"
  }
}

Cancel ​

Cancel a confirmed reservation using the referenceId or bookingCode. Returns the cancellation status and the actual penalty amount incurred. Timeout: 60s.

API Call Schema

NameValue
Request URL/cancel
Request methodPOST
Request Fields
requestId: stringRequired
A UUID generated by the caller for tracing and idempotency control.
referenceId: string
Tourmind booking id
bookingCode: string
Response Fields
requestId: stringRequired
json
{
  "requestId": "16c74e57-9a86-4e17-843c-3dd66cf86524",
  "referenceId": "532432532"
}
json
{
  "requestId": "16c74e57-9a86-4e17-843c-3dd66cf86524",
  "errors": null,
  "data": {
    "referenceId": "532432532",
    "bookingCode": "fef2fsf",
    "status": "CANCELED",
    "penaltyAmount": 99.99,
    "currency": "USD"
  }
}

Booking List ​

Search for booking details using the following criteria:

  1. referenceId: TourMind booking ID
  2. bookingCode: Supplier booking ID
  3. date range: Check-in / Booking Time Note: The supplier must support searching for bookings by referenceId or date range. When create or canceling a booking, network timeouts may prevent us from receiving a response; in such cases, we can only retrieve the booking status using the referenceId or date range. Timeout: 30s.

API Call Schema

NameValue
Request URL/bookings
Request methodPOST
Request Fields
requestId: stringRequired
bookingCode: string
referenceId: string
dateType: string
Used with startDate/endDate. CHECKIN filters by check-in date; BOOK filters by booking creation date.
startDate: string
Format: YYYY-MM-DD. Used in combination with endDate and dateType.
endDate: string
Format: YYYY-MM-DD. Used in combination with startDate and dateType.
Response Fields
requestId: stringRequired
json
{
  "requestId": "16c74e57-9a86-4e34-843c-3dd66534ef434",
  "referenceId": "532432532"
}
json
{
  "requestId": "16c74e57-9a86-4e34-843c-3dd66534ef434",
  "errors": null,
  "data": [
    {
      "bookingCode": "fef2fsf",
      "status": "CONFIRMED",
      "referenceId": "532432532",
      "hotelConfirmationNumber": "KHKHG324",
      "hotelCode": "12345",
      "hotelName": "hotel name",
      "checkIn": "2026-08-24",
      "checkOut": "2026-08-25",
      "holder": {
        "firstName": "Shan",
        "lastName": "Zhang",
        "phone": "13212341234",
        "email": "xxx@xx.com"
      },
      "rooms": [
        {
          "roomId": 1,
          "paxes": [
            {
              "firstName": "Shan",
              "lastName": "Zhang",
              "type": "ADULT"
            },
            {
              "age": 8,
              "type": "CHILD"
            }
          ]
        }
      ],
      "totalPrice": 99,
      "penaltyAmount": 0,
      "currency": "USD",
      "commission": 0,
      "cancelPenalties": [
        {
          "deadline": "2026-08-03T14:15:22.123Z",
          "penaltyType": "PERCENT",
          "value": 100,
          "currency": "USD"
        }
      ],
      "remark": "",
      "customerRequirements": "xxxxx",
      "bookedTime": "2026-08-20T14:15:22.123Z"
    }
  ]
}

Static Data ​

Hotel List ​

Retrieve hotel static data including basic hotel information and room type lists. Supports filtering by hotel code, country, or last update time. Results are paginated.

API Call Schema

NameValue
Request URL/hotels
Request methodPOST
Request Fields
hotels[]: string
Specific hotel codes to query. Maximum 100. Mutually exclusive with countryCode. If neither is provided, all hotels are returned (paginated).
countryCode: string
ISO 3166-1 alpha-2 country code to filter hotels by country, e.g. CN, JP.
updateTime: string
Returns only hotels that have changed since this timestamp. Used for incremental static data sync. Format: ISO 8601.
page: integer
Starts from 1.
perPage: integer
Number of hotels per page. Range: 1–100. Defaults to 100.
Response Fields
json
{
  "hotels": [
    "12345"
  ],
  "page": 1,
  "perPage": 100
}
json
{
  "errors": null,
  "data": {
    "pagination": {
      "page": 1,
      "perPage": 100,
      "pages": 1,
      "total": 1
    },
    "hotels": [
      {
        "hotelCode": "12345",
        "hotelName": "hotel name",
        "starRating": 3,
        "category": "Hotel",
        "countryCode": "US",
        "country": "USA",
        "cityCode": "CA",
        "city": "Burlingame",
        "address": "600 Airport Boulevard",
        "latitude": "37.59002",
        "longitude": "-122.342915",
        "email": "",
        "phone": "1-650-340-8500",
        "relatedCode": {
          "expedia": "1232353"
        },
        "rooms": [
          {
            "code": "DBL",
            "name": "Double Room",
            "area": 20,
            "bedTypes": [
              {
                "code": "2",
                "name": "Single Bed",
                "quantity": 2
              }
            ],
            "maxOccupancy": 2,
            "maxAdults": 2,
            "maxChildren": 0,
            "relatedCode": {
              "expedia": "3253252"
            }
          }
        ]
      }
    ]
  }
}

Reference ​

Booking Status ​

ValueDescription
PENDINGBooking is being processed; confirmation is pending.
CONFIRMEDBooking has been confirmed by the supplier.
FAILUREBooking failed to be confirmed.
CANCELEDBooking has been cancelled.

Meal Plan Codes ​

CodeDescription
RORoom Only
BBBed & Breakfast
HBHalf Board (Breakfast + Dinner)
FBFull Board (Breakfast + Lunch + Dinner)
AIAll Inclusive
BF1Breakfast for 1 person
BF2Breakfast for 2 persons
BF3Breakfast for 3 persons
BF4Breakfast for 4 persons
LCLunch
DNDinner
LDLunch & Dinner

Fee / Tax Types ​

ValueDescription
VALUE_ADDED_TAXValue Added Tax (VAT)
SALES_TAXSales Tax
CITY_TAXCity Tax
TOURISM_TAXTourism Tax
TAX_AND_SERVICE_FEECombined Tax & Service Fee
PROPERTY_FEEProperty Fee
DEPOSITSecurity Deposit
RESORT_FEEResort Fee
EXTRA_PERSON_FEEExtra Person Fee
PLATFORM_FEEPlatform Fee

Date Type ​

ValueDescription
CHECKINFilter bookings by check-in date.
BOOKFilter bookings by booking creation date.

Guest Type ​

ValueDescription
ADULTAdult (18 years or older).
CHILDChild (17 years or younger).

Error Codes ​

CodeDescription
VALIDATION_ERRORRequest parameter validation failed.
TIMEOUTThe upstream supplier request timed out.
RATE_LIMITRequest rate limit exceeded.
SYSTEM_ERRORInternal system error.
NO_AVAILABILITYNo availability for the requested criteria.
PRICE_CHANGEDThe price has changed since the last search or prebook.
INSUFFICIENT_CREDITAccount credit is insufficient to complete the booking.
UNKNOWNAn unknown error occurred.