Beds24 Authentication API

Refresh and access token management and diagnostics.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/beds24-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

beds24-authentication-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Beds24 API V2 Accounts Authentication API
  description: 'The Beds24 API V2 lets you read, create, and alter data across almost all aspects of a Beds24 account, including properties, room inventory, bookings, prices, invoices, channels, and account settings. Beds24 is a vacation rental and hotel channel manager, property management system, and booking engine.

    Base URL is https://api.beds24.com/v2. Authentication uses expiring access tokens that are generated from a refresh token (or a read-only long-life token) obtained via the /authentication endpoints; the token is sent in the "token" request header. Every category except /authentication requires a matching scope. Usage is governed by an account-level credit limit over a rolling 5-minute window, reported via the x-five-min-limit-remaining, x-five-min-limit-resets-in, and x-request-cost response headers.

    This document models the public V2 surface from Beds24''s Swagger UI (https://api.beds24.com/v2/) and wiki. Endpoint shapes marked as modeled are grounded in the published documentation but were not byte-verified against the live Swagger JSON, which requires an authenticated token to retrieve.'
  version: '2.0'
  contact:
    name: Beds24
    url: https://beds24.com
  license:
    name: Proprietary
    url: https://beds24.com/terms.html
servers:
- url: https://api.beds24.com/v2
  description: Beds24 API V2 production
security:
- tokenAuth: []
tags:
- name: Authentication
  description: Refresh and access token management and diagnostics.
paths:
  /authentication/setup:
    get:
      operationId: getSetup
      tags:
      - Authentication
      summary: Get a refresh token from an invite code
      description: Exchanges an invite code (created in SETTINGS > ACCOUNT > ACCESS) for a refresh token and an initial access token, with the requested scopes.
      parameters:
      - name: code
        in: header
        required: true
        schema:
          type: string
        description: The invite code generated in the Beds24 control panel.
      - name: deviceName
        in: header
        required: false
        schema:
          type: string
      responses:
        '200':
          description: A refresh token and access token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TokenSetup'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /authentication/token:
    get:
      operationId: getToken
      tags:
      - Authentication
      summary: Get an access token from a refresh token
      description: Generates a short-lived access token from a long-life refresh token.
      parameters:
      - name: refreshToken
        in: header
        required: true
        schema:
          type: string
      responses:
        '200':
          description: A new access token and its expiry.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Token'
        '401':
          $ref: '#/components/responses/Unauthorized'
    delete:
      operationId: deleteToken
      tags:
      - Authentication
      summary: Revoke the current token
      description: Invalidates the refresh token used to authenticate this request.
      responses:
        '200':
          description: Token revoked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Success'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /authentication/details:
    get:
      operationId: getAuthenticationDetails
      tags:
      - Authentication
      summary: Get token diagnostics
      description: Returns diagnostics about the current token, including scopes and validity.
      responses:
        '200':
          description: Token diagnostics.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthenticationDetails'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    Error:
      type: object
      properties:
        success:
          type: boolean
          example: false
        code:
          type: integer
          example: 401
        error:
          type: string
          example: Token is missing
    AuthenticationDetails:
      type: object
      properties:
        validToken:
          type: boolean
        token:
          type: object
          properties:
            expiresIn:
              type: integer
        scopes:
          type: array
          items:
            type: string
    TokenSetup:
      type: object
      properties:
        token:
          type: string
        expiresIn:
          type: integer
        refreshToken:
          type: string
    Success:
      type: object
      properties:
        success:
          type: boolean
        new:
          type: object
          additionalProperties: true
        modified:
          type: object
          additionalProperties: true
        warnings:
          type: array
          items:
            type: string
    Token:
      type: object
      properties:
        token:
          type: string
        expiresIn:
          type: integer
  responses:
    Unauthorized:
      description: The token is missing, invalid, expired, or lacks the required scope.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    tokenAuth:
      type: apiKey
      in: header
      name: token
      description: Short-lived access token generated from a refresh token via the /authentication endpoints, sent in the "token" request header.