Marriott International

Marriott International is the world's largest hotel group by room count, headquartered in Bethesda, Maryland, United States, operating and franchising roughly thirty brands from The Ritz-Carlton, St. Regis and W through Marriott Hotels, Sheraton, Westin and Courtyard down to Fairfield, Moxy and StudioRes, plus the Homes & Villas by Marriott Bonvoy home-rental marketplace and the Marriott Bonvoy loyalty program. It sits on the supply side of the travel distribution chain: it publishes rates and availability into every major global distribution system — Marriott's own travel-agent site states it "participates in the following GDS: Amadeus, Sabre, Travelport (Apollo/Galileo, and Worldspan)" — sells through the OTAs, connects short-term-rental supply through a channel-connectivity partner program, and spends heavily to pull demand back to direct booking on Marriott.com and the Bonvoy app. Its API posture is closed. A Broadcom Layer7 developer portal exists at devportalprod.marriott.com and returns HTTP 200, but its anonymous API catalog is literally empty and the portal's own home content returns HTTP 401 — there is no self-serve signup, no public API reference, no published rates/availability/booking API, no sandbox, no SDK, no changelog and no exit path. The only Marriott OpenAPI documents that can be read without a contract are eight internal and partner-facing specifications left publicly readable on SwaggerHub under the "marriott-api" owner; six are mirrored here verbatim as evidence. Everything a developer would actually want is behind a partner relationship, a travel-agent registration, or a GDS or channel-manager contract.

Marriott International publishes 6 APIs on the APIs.io network, including Marriott TIP Internet Portal API, Marriott Loyalty Account Merge API, Marriott Data Collection API, and 3 more. Tagged areas include Travel, United States, Hospitality, Hotels, and Booking.

Marriott International’s developer surface includes authentication, support, engineering blog, signup flow, and 29 more developer resources.

32.9/100 thin Agent 61/100 agent native Full breakdown ↓
scored 2026-07-28 · rubric v0.5
6 APIs
TravelUnited StatesHospitalityHotelsBookingDistributionLoyaltyShort Term RentalCorporate Travel

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.5
Composite quality — 32.9/100 · thin
Contract Quality 9.4 / 25
Developer Ergonomics 6.5 / 20
Commercial Clarity 6.8 / 20
Operational Transparency 1.4 / 13
Governance 0.0 / 12
Discoverability 8.8 / 10
Agent readiness — 61/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 5 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 3 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/marriott: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 6

Individual APIs this provider publishes, each with its own machine-readable definition.

Marriott TIP Internet Portal API

Partner-facing API used by Marriott's in-hotel internet (TIP) provider integration to generate a guest landing-page URL, validate a guest's room number and last name against the...

Marriott Loyalty Account Merge API

Internal Marriott Bonvoy loyalty operation that merges or transfers one member profile into another, keyed on a member account type code and member account unique identifier. Do...

Marriott Data Collection API

Internal Marriott stay-event API that captures and publishes additional event data for a reservation confirmation number, described by its own OpenAPI as feeding a downstream co...

Marriott Commerce Payment Processor API

Internal Marriott commerce API that submits a payment to a payment processor over an XML FreedomPay Freeway service operation. Its OpenAPI info block names the "Marriott API Tea...

Marriott Finance Status Notifier API

Internal Marriott finance application API that receives processing status for files generated by Marriott's finance adapters, with status, data, config-watcher and Spring Boot a...

Marriott Hotel Operations ARA Preview Submit API

Internal Marriott hotel-operations API that submits a preview request for ARA automated room assignment. The OpenAPI document declares no servers at all, which is itself the fin...

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Marriott Authentication

http/oauth2 · 4 schemes

SECURITY

Marriott Domain Security

TLSv1.3 · DMARC

SECURITY

Marriott Vulnerability Disclosure

Hackerone · security.txt · contact published

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Marriott Scopes

2 scopes · authorizationCode/clientCredentials

2 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Marriott Agentic Access

13 operations · 11 acting · 1 human-in-the-loop

13 operations · 11 acting

AGENTIC

Resources

Get Started 4

Portal, sign-up, and the first successful call

Agent Surfaces 5

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 8

Authentication, authorization, and security posture

Scroll for all 8

Operate 1

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 4

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: marriott
url: https://raw.githubusercontent.com/api-evangelist/marriott/refs/heads/main/apis.yml
name: Marriott International
kind: company
description: 'Marriott International is the world''s largest hotel group by room count, headquartered in Bethesda, Maryland,
  United States, operating and franchising roughly thirty brands from The Ritz-Carlton, St. Regis and W through Marriott Hotels,
  Sheraton, Westin and Courtyard down to Fairfield, Moxy and StudioRes, plus the Homes & Villas by Marriott Bonvoy home-rental
  marketplace and the Marriott Bonvoy loyalty program. It sits on the supply side of the travel distribution chain: it publishes
  rates and availability into every major global distribution system — Marriott''s own travel-agent site states it "participates
  in the following GDS: Amadeus, Sabre, Travelport (Apollo/Galileo, and Worldspan)" — sells through the OTAs, connects short-term-rental
  supply through a channel-connectivity partner program, and spends heavily to pull demand back to direct booking on Marriott.com
  and the Bonvoy app. Its API posture is closed. A Broadcom Layer7 developer portal exists at devportalprod.marriott.com and
  returns HTTP 200, but its anonymous API catalog is literally empty and the portal''s own home content returns HTTP 401 —
  there is no self-serve signup, no public API reference, no published rates/availability/booking API, no sandbox, no SDK,
  no changelog and no exit path. The only Marriott OpenAPI documents that can be read without a contract are eight internal
  and partner-facing specifications left publicly readable on SwaggerHub under the "marriott-api" owner; six are mirrored
  here verbatim as evidence. Everything a developer would actually want is behind a partner relationship, a travel-agent registration,
  or a GDS or channel-manager contract.'
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/marriott-international.png
tags:
- Travel
- United States
- Hospitality
- Hotels
- Booking
- Distribution
- Loyalty
- Short Term Rental
- Corporate Travel
created: '2026-07-28'
modified: '2026-07-28'
specificationVersion: '0.19'
apis:
- aid: marriott:marriott-tip-internet-portal-api
  name: Marriott TIP Internet Portal API
  description: Partner-facing API used by Marriott's in-hotel internet (TIP) provider integration to generate a guest landing-page
    URL, validate a guest's room number and last name against the cloud PMS, and post an internet purchase back to the PMS.
    Bearer and Basic security schemes are declared and an SSO token operation is included. This is not part of any public
    Marriott developer program; the OpenAPI document is readable on SwaggerHub under the "marriott-api" owner and the only
    server it names is a Marriott UAT gateway host that is not open to the public.
  humanURL: https://api.swaggerhub.com/apis/marriott-api/tip-internet-portal-api-spec/1.0.2
  baseURL: https://gatewaydsapuat3.marriott.com
  tags:
  - Partners
  - Property Management System
  - Guest Services
  properties:
  - type: OpenAPI
    url: openapi/marriott-tip-internet-portal-api-openapi.json
  - type: Overlay
    url: overlays/marriott-tip-internet-portal-overlay.yaml
  - type: APIReference
    url: https://api.swaggerhub.com/apis/marriott-api/tip-internet-portal-api-spec/1.0.2
- aid: marriott:marriott-loyalty-account-merge-api
  name: Marriott Loyalty Account Merge API
  description: Internal Marriott Bonvoy loyalty operation that merges or transfers one member profile into another, keyed
    on a member account type code and member account unique identifier. Documented only as an OpenAPI document publicly readable
    on SwaggerHub under the "marriott-api" owner; the only server listed is a SwaggerHub auto-mock, so no callable Marriott
    host is published.
  humanURL: https://api.swaggerhub.com/apis/marriott-api/account-merge/1.0.2
  baseURL: https://virtserver.swaggerhub.com/marriott-api/lylt-v1-merge-profile/1.0.1
  tags:
  - Loyalty
  - Member Profile
  properties:
  - type: OpenAPI
    url: openapi/marriott-loyalty-account-merge-api-openapi.json
  - type: Overlay
    url: overlays/marriott-loyalty-account-merge-overlay.yaml
  - type: APIReference
    url: https://api.swaggerhub.com/apis/marriott-api/account-merge/1.0.2
- aid: marriott:marriott-data-collection-api
  name: Marriott Data Collection API
  description: Internal Marriott stay-event API that captures and publishes additional event data for a reservation confirmation
    number, described by its own OpenAPI as feeding a downstream consumer called PACD and associated with digital-key events.
    Servers named are SwaggerHub auto-mocks plus Marriott dev and test gateway hosts; there is no production or public endpoint.
    Publicly readable on SwaggerHub under the "marriott-api" owner.
  humanURL: https://api.swaggerhub.com/apis/marriott-api/Data_Collection_API/1.0.0
  baseURL: https://gatewaydsapdev1.marriott.com
  tags:
  - Stays
  - Events
  - Digital Key
  properties:
  - type: OpenAPI
    url: openapi/marriott-data-collection-api-openapi.json
  - type: Overlay
    url: overlays/marriott-data-collection-overlay.yaml
  - type: APIReference
    url: https://api.swaggerhub.com/apis/marriott-api/Data_Collection_API/1.0.0
- aid: marriott:marriott-commerce-payment-processor-api
  name: Marriott Commerce Payment Processor API
  description: Internal Marriott commerce API that submits a payment to a payment processor over an XML FreedomPay Freeway
    service operation. Its OpenAPI info block names the "Marriott API Team" with contact URL https://api.marriott.com/ and
    email apidevteam@marriott.com and a license named "Marriott Consumer License" — the only place Marriott's API-team identity
    is publicly asserted. Declares Basic, Bearer and OAuth2 authorization-code security. No public server is listed.
  humanURL: https://api.swaggerhub.com/apis/marriott-api/commerce-payment-processor/1.0.0
  baseURL: https://virtserver.swaggerhub.com/marriott-api/commerce-payment-processor/1.0.0
  tags:
  - Payments
  - Commerce
  properties:
  - type: OpenAPI
    url: openapi/marriott-commerce-payment-processor-api-openapi.json
  - type: Overlay
    url: overlays/marriott-commerce-payment-processor-overlay.yaml
  - type: APIReference
    url: https://api.swaggerhub.com/apis/marriott-api/commerce-payment-processor/1.0.0
- aid: marriott:marriott-finance-status-notifier-api
  name: Marriott Finance Status Notifier API
  description: Internal Marriott finance application API that receives processing status for files generated by Marriott's
    finance adapters, with status, data, config-watcher and Spring Boot actuator logger operations, secured with an OAuth2
    client-credentials flow. This is one of only two Marriott SwaggerHub documents marked published rather than draft. No
    Marriott host is listed as a server.
  humanURL: https://api.swaggerhub.com/apis/marriott-api/finance-all-statusnotifier/1.0.2
  baseURL: https://virtserver.swaggerhub.com/marriott-api/finance-all-statusnotifier/1.0.2
  tags:
  - Finance
  - Operations
  properties:
  - type: OpenAPI
    url: openapi/marriott-finance-status-notifier-api-openapi.json
  - type: Overlay
    url: overlays/marriott-finance-status-notifier-overlay.yaml
  - type: APIReference
    url: https://api.swaggerhub.com/apis/marriott-api/finance-all-statusnotifier/1.0.2
- aid: marriott:marriott-hotel-operations-ara-api
  name: Marriott Hotel Operations ARA Preview Submit API
  description: Internal Marriott hotel-operations API that submits a preview request for ARA automated room assignment. The
    OpenAPI document declares no servers at all, which is itself the finding — the operation is real but no host, environment
    or access route is published anywhere. Publicly readable on SwaggerHub under the "marriott-api" owner.
  humanURL: https://api.swaggerhub.com/apis/marriott-api/hotel-operations-ara-preview-submit-api/1.0.0
  tags:
  - Hotel Operations
  - Room Assignment
  properties:
  - type: OpenAPI
    url: openapi/marriott-hotel-operations-ara-api-openapi.json
  - type: Overlay
    url: overlays/marriott-hotel-operations-ara-overlay.yaml
  - type: APIReference
    url: https://api.swaggerhub.com/apis/marriott-api/hotel-operations-ara-preview-submit-api/1.0.0
common:
- type: AgenticAccess
  url: agentic-access/marriott-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/marriott-vulnerability-disclosure.yml
- type: Security
  url: https://hackerone.com/marriott?type=team&view_policy=true
- type: DomainSecurity
  url: security/marriott-domain-security.yml
- type: OAuthScopes
  url: scopes/marriott-scopes.yml
- type: Authentication
  url: authentication/marriott-authentication.yml
- type: WellKnown
  url: well-known/marriott-well-known.yml
- type: SecurityTxt
  url: well-known/marriott-security.txt
- type: Conventions
  url: conventions/marriott-conventions.yml
- type: ErrorCatalog
  url: errors/marriott-problem-types.yml
- type: Lifecycle
  url: lifecycle/marriott-lifecycle.yml
- type: Conformance
  url: conformance/marriott-conformance.yml
- type: DataModel
  url: data-model/marriott-data-model.yml
- type: Packages
  url: packages/marriott-packages.yml
- type: MCPAssessment
  url: mcp/marriott-mcp.yml
- type: MockServer
  url: sandbox/marriott-sandbox.yml
- type: LLMsTxt
  url: llms/marriott-llms.txt
- type: AgentSkill
  url: skills/_index.yml
- type: Website
  url: https://www.marriott.com/
- type: DeveloperPortal
  url: https://devportalprod.marriott.com/
- type: TravelAgentPortal
  url: https://www.travelagents.marriott.com/
- type: GDSChainCodes
  url: https://www.travelagents.marriott.com/travelagents/GDSResInfo.mi
- type: ConnectivityPartners
  url: https://homes-and-villas.marriott.com/en/connectivity-partners
- type: PartnerOnboarding
  url: https://partners.homes-and-villas.marriott.com/s/connectivity-partner-contact-us
- type: Support
  url: https://help.marriott.com/
- type: Blog
  url: https://news.marriott.com/
- type: SignUp
  url: https://www.travelagents.marriott.com/travelagents/createAccount.mi
- type: TermsOfService
  url: https://www.marriott.com/en-us/about/terms-of-use.mi
- type: LoyaltyProgramTerms
  url: https://www.marriott.com/loyalty/terms/default.mi
- type: PrivacyPolicy
  url: https://www.marriott.com/about/us-consumer.mi
- type: VulnerabilityDisclosure
  url: https://www.marriott.com/.well-known/security.txt
- type: BugBounty
  url: https://hackerone.com/marriott
- type: LinkedIn
  url: https://www.linkedin.com/company/marriott-international
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com