Wyndham Hotels & Resorts · Authentication Profile

Wyndham Hotels Authentication

Authentication

Wyndham Hotels & Resorts secures its APIs with none and oauth2 across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

TravelUnited StatesHospitalityHotelsBookingFranchisingDistributionLoyaltyGDS
Methods: none, oauth2 Schemes: 4 OAuth flows: authorizationCode API key in:

Security Schemes

anonymous none
wyndham-business-mcp-oauth oauth2
· flows: authorizationCode
wordpress-privileged cookie+nonce / application-password
human-login-walls none-machine-readable

Source

Authentication Profile

wyndham-hotels-authentication.yml Raw ↑
generated: '2026-07-28'
method: searched
source: |
  live probes 2026-07-28 plus
  https://www.wyndhambusiness.com/.well-known/oauth-authorization-server (RFC 8414)
  and https://www.wyndhambusiness.com/.well-known/oauth-protected-resource (RFC 9728)
note: |
  Probed rather than derived — Wyndham Hotels & Resorts publishes no OpenAPI or
  other specification, so there are no securitySchemes to aggregate. Three distinct
  authentication realms exist on the estate:

    1. Anonymous. The WordPress REST APIs on www.wyndhambusiness.com and
       development.wyndhamhotels.com answer read requests with no credential at all.
       The /wp-json/ discovery document on wyndhambusiness.com advertises only
       application-passwords, which is a WordPress admin flow, not a partner
       credential path.
    2. OAuth 2.1. The MCP server route on www.wyndhambusiness.com is a genuine
       OAuth-protected resource with published RFC 8414 and RFC 9728 metadata,
       mandatory PKCE S256, public-client support via client_id_metadata_document,
       and a single scope, `mcp`. It is standards-correct and completely
       undocumented.
    3. WordPress privileged. Settings, the wp-abilities registry and the second MCP
       adapter reject anonymous callers with 401 and require a cookie + X-WP-Nonce
       or an application password that Wyndham issues to no third party.

  There is no API key program, no client-credentials grant, no self-serve
  registration and no published route to request a credential of any kind.
summary:
  types:
  - none
  - oauth2
  api_key_in: []
  oauth2_flows:
  - authorizationCode
  public_read_requires_auth: false
  self_serve_registration: false
  dynamic_client_registration: false
  api_key_program: false
schemes:
- name: anonymous
  type: none
  applies_to:
  - https://www.wyndhambusiness.com/wp-json/wp/v2
  - https://development.wyndhamhotels.com/wp-json/wp/v2
  evidence: |
    GET /wp-json/ returns HTTP 200 with "authentication":
    {"application-passwords":{...}} only. Anonymous HTTP 200 confirmed on
    /wp/v2/posts, /wp/v2/pages, /wp/v2/media, /wp/v2/categories, /wp/v2/tags,
    /wp/v2/users, /wp/v2/types, /wp/v2/taxonomies, /wp/v2/statuses,
    /wp/v2/comments, /wp/v2/search and /wp/v2/blocks on www.wyndhambusiness.com.
- name: wyndham-business-mcp-oauth
  type: oauth2
  applies_to:
  - https://www.wyndhambusiness.com/wp-json/mcp/mcp-oauth-server
  source: well-known/wyndham-hotels-wyndhambusiness-oauth-authorization-server.json
  issuer: https://www.wyndhambusiness.com
  authorization_server_metadata: https://www.wyndhambusiness.com/.well-known/oauth-authorization-server
  protected_resource_metadata: https://www.wyndhambusiness.com/.well-known/oauth-protected-resource
  resource: https://www.wyndhambusiness.com/wp-json/mcp/mcp-oauth-server
  flows:
  - flow: authorizationCode
    authorizationUrl: https://www.wyndhambusiness.com/oauth/authorize
    tokenUrl: https://www.wyndhambusiness.com/oauth/token
    refreshUrl: https://www.wyndhambusiness.com/oauth/token
    scopes:
      mcp: Access the WordPress MCP server on www.wyndhambusiness.com
  revocation_endpoint: https://www.wyndhambusiness.com/oauth/revoke
  response_types_supported:
  - code
  grant_types_supported:
  - authorization_code
  - refresh_token
  code_challenge_methods_supported:
  - S256
  token_endpoint_auth_methods_supported:
  - none
  client_id_metadata_document_supported: true
  registration_endpoint: null
  bearer_methods_supported:
  - header
  client_credentials: false
  evidence: |
    Anonymous JSON-RPC tools/list returns 401 mcp_unauthorized with
    WWW-Authenticate: Bearer realm="https://www.wyndhambusiness.com",
    resource_metadata="https://www.wyndhambusiness.com/.well-known/oauth-protected-resource"
  note: |
    PKCE S256 is the only code-challenge method and the token endpoint accepts no
    client authentication, which is the OAuth 2.1 public-client profile the MCP
    authorization spec expects. There is no registration endpoint; clients are
    expected to present a client-id metadata document URL.
- name: wordpress-privileged
  type: cookie+nonce / application-password
  applies_to:
  - https://www.wyndhambusiness.com/wp-json/
  - https://development.wyndhamhotels.com/wp-json/
  public: false
  application_passwords_endpoint: https://www.wyndhambusiness.com/wp-admin/authorize-application.php
  evidence: |
    GET /wp-json/wp/v2/settings returns 401 rest_forbidden;
    GET /wp-json/wp-abilities/v1/abilities returns 401 rest_forbidden;
    POST /wp-json/mcp/mcp-adapter-default-server returns 401 rest_forbidden.
    CORS advertises Authorization and X-WP-Nonce in access-control-allow-headers.
- name: human-login-walls
  type: none-machine-readable
  applies_to:
  - https://www.wyndhambusiness.com/ (Wyndham Business account)
  - https://www.wyndhamhotels.com/wyndham-rewards (Wyndham Rewards member)
  - https://wyndham.supplierone.co/ (supplier procurement, third party)
  note: |
    Human sign-in surfaces only. Wyndham Business / Wyndham Direct access is
    approval-gated on a submitted request with a corporate code, company name,
    website URL and anticipated travel spend; none of it produces an API credential.
docs: null
docs_note: |
  Wyndham publishes no authentication documentation. The upstream semantics for the
  WordPress surfaces are documented by WordPress, not by Wyndham:
  https://developer.wordpress.org/rest-api/using-the-rest-api/authentication/
cross_references:
  scopes: scopes/wyndham-hotels-scopes.yml
  well_known: well-known/wyndham-hotels-well-known.yml
  mcp: mcp/wyndham-hotels-mcp.yml
  conventions: conventions/wyndham-hotels-conventions.yml