HomeAway * · Authentication Profile

Homeaway Authentication

Authentication

HomeAway * secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials and authorizationCode flow(s).

CompanyConsumerVacation RentalsTravelHospitalityMarketplaceBookingsProperty Management
Methods: oauth2 Schemes: 1 OAuth flows: clientCredentials, authorizationCode API key in:

Security Schemes

OAuth2 oauth2
· flows: clientCredentials, authorizationCode

Source

Authentication Profile

homeaway-authentication.yml Raw ↑
generated: '2026-07-19'
method: searched
source: https://github.com/homeaway/homeaway_api_ruby
docs: https://www.homeaway.com/platform/myClients
note: >-
  No OpenAPI is available for HomeAway (brand retired into Expedia Group / Vrbo),
  so this profile is derived from the first-party Ruby SDK documentation rather
  than a machine-readable spec. The HomeAway API used OAuth 2.0: applications
  register for a client id and client secret at the developer platform, then use
  either two-legged (client-credentials) access for public data or a three-legged
  authorization-code flow to access a user's personal HomeAway data.
summary:
  types: [oauth2]
  oauth2_flows: [clientCredentials, authorizationCode]
schemes:
- name: OAuth2
  type: oauth2
  flows:
  - flow: clientCredentials
    description: Two-legged client authentication for public API access.
  - flow: authorizationCode
    description: Three-legged flow to access an end user's personal HomeAway data.
  credentials:
  - client_id
  - client_secret
  registration: https://www.homeaway.com/platform/myClients
  sources: [github.com/homeaway/homeaway_api_ruby]