OAuth (Open Authorization)
OAuth (Open Authorization) is an open standard that lets one system access another system's data or functions on a user's behalf using time-limited access tokens, without sharing the user's password. In hospitality technology it is widely used to authorize integrations between PMS, channel managers, booking engines, revenue tools and OTA extranets.
How it works
- The property (or user) grants an application permission, choosing the scopes it may use (for example, read reservations, write rates).
- The authorization server issues an access token with limited lifetime and scope, plus often a refresh token to obtain new access tokens.
- The application presents the token with each API call. The property can revoke access at any time without changing credentials.
Example
A hotel connects a revenue management tool to its PMS. Instead of giving the vendor the PMS login, the hotel approves a connection that grants only read access to reservations and rates. If the hotel ends the contract, it revokes the token and the connection stops immediately.
Why it matters
OAuth reduces security risk compared with shared credentials, supports granular permissions and makes onboarding of integrations faster for hotels. As connectivity moves from point-to-point XML links to modern REST APIs and marketplaces, OAuth 2.0 has become the common authorization method for partner integrations, and clear scopes help hotels meet data-protection expectations.