Hostaway developer for hire: API integration and custom operator dashboards (2026)
Hire a Hostaway developer for API integration and custom operator dashboards. What the Public API covers, channel IDs, rate limits, scopes and cost.
A Hostaway developer builds software against the Hostaway Public API: a booking site that reads live rates and creates reservations, an operator dashboard, or a connection to another system. STYLABS has built four such stacks on operators' own Hostaway accounts, each with its own dashboard. Hostaway stays the PMS. Below: what the API allows, typical scopes, cost and limits.
Who this page is for
The operator, or the operator's tech lead, with a specific piece of Hostaway work in mind: an integration, a dashboard, a checkout, a channel migration. It assumes you already know why you want it and need to know what is possible and what it involves.
If you want the finished product, a branded booking site on your own domain sold as one offer, that is custom Hostaway booking sites. If you are still deciding between Hostaway's builder and a custom build, read the comparison first.
What the Hostaway Public API covers
Hostaway publishes one reference for its Public API. It is a REST API, JSON over HTTPS, currently at version 1. Everything in this section is from that reference (Hostaway Public API Reference, retrieved 3 October 2026).
| Area | What the API does | What to plan for |
|---|---|---|
| Authentication | OAuth 2.0 client-credentials grant at POST /v1/accessTokens. The client_id is the Hostaway account ID, the secret comes from the Hostaway dashboard, and the scope is general. A token lasts 24 months and can be revoked. | Store the token and reuse it. Hostaway asks integrators not to request one per call. A new token becomes valid one second after it is issued. A 403 means the token is no longer valid. |
| Listings | Read, create, update and delete listings. Images, fee settings and price settings sit under each listing. Amenities, bed types and property types are reference lists. | The amenity object is an ID and a name. Grouping, ordering and editorial content belong in your own data model. Pass specialStatus[]=active to leave archived listings out. |
| Calendar and rates | Read a listing's calendar day by day: availability, status, price, minimum and maximum stay, closed-on-arrival and closed-on-departure. Update single days or whole intervals, including blocks. | Reservations attached to calendar days are returned only when includeResources=1 is passed. |
| Price calculation | A dedicated endpoint prices a stay for given dates and guests, with fee components and coupons. | Version 2 (a POST) replaces a deprecated GET. This is the call a booking site makes every time a guest changes dates. |
| Reservations | List, retrieve, create, update and cancel. Create with card validation. A reservation-logs endpoint, added on 4 August 2026, returns the field-level audit trail. | The list endpoint now pages with an afterId cursor; offset is deprecated there. One-sided date filters changed behaviour on 21 August 2026. |
| Payments | Stripe endpoints return the connected account's publishable key and create a setup intent. Other endpoints attach a payment method to a reservation, list guest charges and record offline charges. | The card is captured in the guest's browser with the payment provider's own library. The API stores the resulting payment method against the reservation. |
| Messaging and reviews | List and read conversations, send a message, read message templates, list reviews. | Sending messages has its own limit: 30 a minute per account. |
| Finance | Financial reports, owner statements, expenses and extras, tax settings. | Read these rather than recomputing them. Hostaway is the system of record. |
| Webhooks | Unified webhooks call your endpoint on three events: reservation created, reservation updated, new message received. | Covered below. They are the supported alternative to polling. |
Channel IDs after 24 August 2026
Every reservation in Hostaway belongs to a channel. The reference lists fifteen channel IDs, including 2018 (airbnbOfficial), 2005 (bookingcom), 2013 (bookingengine) and 2022 (google). Those describe where a reservation came from. An integration can only create reservations on three of them.
channelId | Channel | Create a reservation through the API |
|---|---|---|
2000 | direct | Accepted |
2002 | homeaway | Accepted |
2020 | partner | Accepted |
2017 | wordpress | Rejected since 24 August 2026 |
| Any other | Rejected |
The changelog entry for 24 August 2026 gives the reason: message automations cannot target the WordPress channel, so automated guest messages never fired for reservations created on it. Existing 2017 reservations can still be retrieved, updated and cancelled. Anything still sending 2017 has to move to 2000 or 2020. The operator's side of that change is in Hostaway's WordPress plugin is deprecated.
Webhooks
Hostaway's unified webhooks are one or more endpoints you register, by API or in the dashboard, that Hostaway calls when something changes. Five behaviours shape the design of any integration:
- No filtering. You receive every supported event and filter on your side. Hostaway says more event types will be added, so unknown events should be acknowledged, not rejected.
- Order is not guaranteed. A message event can arrive before the reservation it belongs to.
- Duplicates happen. The same update can be delivered more than once, so handlers must be idempotent.
- Retries are limited. A delivery that fails on a network error, a 5xx or a 429 is retried up to three times within about an hour. Any other 4xx is treated as permanent and not retried. Hostaway expects an acknowledgement within 20 seconds, and disables a webhook that has failed for five consecutive days.
- Fixed source addresses. Deliveries come from a published set of IP addresses, which can be allow-listed.
The practical consequence: acknowledge fast, queue the work, and reconcile against the API on a schedule, because a missed webhook is silent.
Rate limits
| Requests | Window | Applies to | Counted per |
|---|---|---|---|
| 30 | 1 minute | Send conversation message | Account |
| 400 | 10 seconds | Calculate reservation price | Account |
| 200 | 10 seconds | Create a reservation | Account |
| 200 | 10 seconds | All other endpoints | Account |
| 200 | 10 seconds | All other endpoints | IP address |
The windows slide; they do not reset on the clock. Going over returns HTTP 429 with headers naming the limit that was hit and when to retry. The retry header is a Unix timestamp, not a number of seconds, which is an easy bug to ship. Enterprise customers can ask Hostaway support for higher limits.
A guest site should not call Hostaway on every page view. Listings and calendars are cached and refreshed by webhook; the price calculation and the reservation call are the live ones.
The API is still moving
The changelog carries eight dated entries between 22 July and 10 September 2026. Among them: the WordPress channel rejection, the corrected rate limits, the webhook acknowledgement timeout going from a documented 30 seconds to 20, a 50-character limit on the provider parameter that now rejects a longer value instead of truncating it, and a restricted set of accepted cancellationPolicy values. None is dramatic. Together they mean an integration needs an owner who reads the changelog.
What a custom operator dashboard models that Hostaway's UI does not
Hostaway's dashboard is built for running a PMS: calendars, channels, reservations. An operator's own back-office is built for how that operator sells. In the four STYLABS builds, the dashboard covers:
- Listings, media and reviews. Managed in the operator's own back-office, not in Hostaway's UI.
- Display order. The order listings appear in is the operator's decision, set in the dashboard.
- Amenity groups. The API's amenity object is an ID and a name. The dashboard groups amenities the way the operator sells the property.
- A portfolio view. A listings view with occupancy and nightly rate on each property, and an availability calendar across the whole portfolio.
- Operations beyond the PMS. For Hireavilla, an ERP that gives the team one view of inventory, bookings and guest communication across five destinations.

Every operator has their own dashboard. Nothing is a shared theme, and none of it replaces Hostaway. Reservations, calendars and channel connections stay there, and the team keeps working in it.
Typical integration scopes
A guest site with its own checkout. Search, location pages and property pages read listings and calendars. The price calculation runs when dates change. The reservation is created on a supported channel and the card is captured through the operator's payment provider. Makarska Exklusiv's checkout takes card, PayPal or bank transfer, including a deposit split.
An operator dashboard. A separate data model for what Hostaway does not hold, joined to listings by ID and kept current by webhooks.
A marketplace across destinations, with an ERP. One Hostaway-connected booking layer under several destinations, plus the operational tooling behind it. This is what Hireavilla runs across Goa, Alibaug, Mangalore, Bali and Dubai.
Moving off the WordPress channel. Change the channel a legacy integration writes to, test a booking end to end, and check that automated messages fire. Small in code, urgent in consequence.
Connecting another system. Accounting, a CRM or a messaging tool, fed by webhooks and reconciled against the reservations list.
STYLABS's four builds combine the first two, and Hireavilla adds the third. STYLABS takes any of these scopes on its own. An API integration or a dashboard does not have to come with a guest site.
What it costs
STYLABS quotes a fixed project fee after a scoping call. API or dashboard work on its own typically runs from $4,000 to $15,000, and a guest site with an operator dashboard from $12,000 to $45,000.
Public figures from the market, for orientation:
| Source | What is priced | Published figure |
|---|---|---|
| CraftedStays, custom build | Bespoke design on its template platform | From $4,500, scoped per project |
| CraftedStays, estimate for agency builds | A custom agency website | $5,000 to $10,000 or more upfront, then $100 to $300 a month |
| CraftedStays, estimate for WordPress agency builds | A custom WordPress vacation rental site | $15,000 to $50,000 upfront, 8 to 14 weeks |
The first and third rows are from CraftedStays' pricing page, the second from its vacation rental websites page, both retrieved 3 October 2026. The estimates are a competitor's view of agencies, so read them as that. All three price a guest-facing website. None prices an operator dashboard or an ERP.
Two agencies that advertise Hostaway API builds, Fullstay and Bolder Technologies, show no price on those pages (checked 3 October 2026). Per-project quotes are the norm for this work.
The fee is not the whole cost. A custom integration has to be hosted, monitored and kept in step with the API. STYLABS maintains what it builds on a monthly retainer after launch.
How an engagement runs
It starts with a scoping call and a fixed proposal. The standard STYLABS engagement is twelve weeks from kickoff to launch. Makarska Exklusiv, which covered brand, public site, booking stack and dashboard, shipped in twelve weeks.
The build works against the Hostaway account you already have. There is no migration and no replacement PMS. Whatever the scope, the technical order is the same:
- Credentials and a read model. A client secret from your Hostaway dashboard, then listings and calendars mirrored into the new system.
- Webhooks. An endpoint that acknowledges quickly and queues the work, plus a scheduled reconciliation.
- Price and reservation. The price calculation, then reservation creation on a supported channel.
- Payment. Card capture through your payment provider, with the payment method stored against the reservation.
- An end-to-end test booking. A real date, a real card, and a check that the reservation, the calendar block and the automated messages all appear in Hostaway.
Where hiring a developer is the wrong call
You run fewer than about 15 listings. Hostaway's Booking Website is included in the subscription and nobody has to maintain it. The arithmetic for when a custom channel pays back is in The economics of direct bookings.
You need a search bar on a site you already like. Hostaway's embeddable search and calendar widgets do that without a developer. Checkout then happens on Hostaway's page.
You need it live this month. A template platform is live in days. A custom build is weeks. The options are compared in Hostaway website builder alternatives.
Nobody will own the result. An integration that nobody monitors fails quietly: a webhook is disabled, a token expires, a changelog entry goes unread. An unmaintained integration is worse than a maintained template.
You are not on Hostaway. The options by PMS are in direct booking websites.
The limit you are hitting is Hostaway's. Higher rate limits are a request to Hostaway support, and only for Enterprise customers. A developer cannot code around them.
Proof: four builds on Hostaway
| Operator | Region | What was built |
|---|---|---|
| Makarska Exklusiv | Croatia | Brand, public site, Hostaway-backed booking stack, and a separate dashboard for listing order, media, reviews and amenity groups. Calendar sync, live rates, checkout by card, PayPal or bank transfer with a deposit split. Shipped in twelve weeks. |
| Hireavilla | India, UAE, Indonesia | A marketplace across Goa, Alibaug, Mangalore, Bali and Dubai: brand, Hostaway-connected booking layer, ERP, and its own dashboard. |
| Manzil | Dubai | A booking site for luxury holiday homes and serviced apartments across Downtown, Marina, Palm Jumeirah and Business Bay, with its own dashboard. Each property is a Hostaway listing underneath. |
| Stayscape | Maharashtra | A booking site for private luxury villas in Lonavala, Karjat, Pali and Igatpuri, with its own dashboard for listings, content and bookings. |
Makarska Exklusiv is the reference build: 110 luxury stays, more than 100,000 guests served, and a 4.95 average guest rating. The live sites are makarska-exklusiv.com, hireavilla.in, manzil.life and stayscape.in.
If you have a Hostaway integration to scope, talk to us or write to hello@stylabs.com. Bring the account size, what the team does outside Hostaway today, and the date it has to work by.
FAQ
What does a Hostaway developer do? A Hostaway developer builds software on the Hostaway Public API. Typical work is a booking site that reads live availability and rates and creates reservations, an operator dashboard that models what Hostaway's own UI does not, or a connection between Hostaway and another system. Hostaway remains the PMS and the system of record throughout.
How does Hostaway API authentication work? Hostaway uses the OAuth 2.0 client-credentials grant. You post your account ID and a client secret from the Hostaway dashboard to the access token endpoint and receive a bearer token valid for 24 months. Hostaway asks integrators to store and reuse the token, not request one per call, and a token can be revoked.
Which channel IDs can the Hostaway API create reservations on? Three. Since 24 August 2026 the create-reservation endpoint accepts only 2000 (direct), 2002 (homeaway) and 2020 (partner). The WordPress channel, 2017, is rejected, because message automations could not target it. Existing reservations on 2017 can still be retrieved, updated and cancelled, but any integration still sending it must switch.
What are the Hostaway API rate limits? Per account, Hostaway allows 200 requests per 10 seconds on most endpoints, 200 per 10 seconds for creating reservations, 400 per 10 seconds for price calculation, and 30 messages a minute. A separate limit of 200 per 10 seconds applies per IP address. Exceeding a limit returns HTTP 429 with retry headers.
Can a custom dashboard replace Hostaway's dashboard? No, and it should not try. Hostaway stays the system of record for calendars, channels and reservations. A custom dashboard sits beside it and holds what the operator needs that Hostaway does not model: display order, media, amenity groups, reviews and portfolio views. STYLABS has built four, one per operator, each on that operator's own Hostaway account.
How long does a Hostaway integration take? The STYLABS standard engagement is twelve weeks from kickoff to launch. Makarska Exklusiv, which covered brand, public site, a Hostaway-backed booking stack and a separate operator dashboard, shipped in twelve weeks. Narrow work, such as moving an existing integration off the deprecated WordPress channel, is far smaller than a full build.
Sources
- Hostaway, Public API Reference: introduction, rate limits, webhook events, authentication, reservation channels, calendar, Stripe, unified webhooks and changelog entries from 22 July to 10 September 2026. https://api.hostaway.com/documentation (retrieved 3 October 2026). Verified: fetched and read.
- CraftedStays, Pricing. https://craftedstays.co/pricing/ (retrieved 3 October 2026). Verified: fetched and read.
- CraftedStays, Vacation Rental Websites. https://craftedstays.co/vacation-rental-websites/ (retrieved 3 October 2026). Verified: fetched and read; source of the agency-build estimate.
- Fullstay, Hostaway Website Design & Open API Integration. https://fullstay.io/hostaway-website-design/ (checked 3 October 2026). No price published.
- Bolder Technologies, Direct Booking Website with API Integration. https://www.boldertechnologies.net/vacation-rental-api-integration/ (checked 3 October 2026). No price published.
- STYLABS delivered work: https://www.stylabs.com/work/hostaway.