{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-connectivity/docs/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Managing endpoint access","siteUrl":"https://developers.booking.com"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"managing-endpoint-access","__idx":0},"children":["Managing endpoint access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the Endpoint access tab in the Machine Accounts page of the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://connect.booking.com/machine-account"},"children":["Provider Portal"]}," to restrict endpoint-specific access. Use this to directly control how each machine account is configured and the Connectivity API endpoints it can call."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"before-you-begin","__idx":1},"children":["Before you begin"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To configure endpoint access, you need:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/connectivity/docs/authentication#introducing-machine-accounts"},"children":["machine account"]}," with token-based authentication enabled."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/connectivity/docs#managing-your-connections"},"children":["connection"]}," from each property for the APIs you want to call."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"who-can-manage-endpoint-access","__idx":2},"children":["Who can manage endpoint access?"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Only admin users can change endpoint access for machine accounts. For more information on how to manage user access, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://connectivity.booking.com/s/article/Managing-your-information-on-the-Connectivity-Hub?language=en_US"},"children":["Managing your information on the Connectivity Hub"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-does-endpoint-access-work-with-connection-types","__idx":3},"children":["How does endpoint access work with connection types?"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Endpoint access is just one part of the authorization context for a Connectivity API request. Note that enabling an endpoint for a machine account does not automatically grant access to the endpoint for a linked property. It depends on the connection type with individual properties and fulfilling any certification requirement."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When you call a Booking.com API endpoint using an access token generated from the machine account credentials, the following access rules apply:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The property referenced in the API request must be linked to the machine account. You manage property links using the Provider Portal under Machine Accounts. Endpoint access settings apply to all properties linked to a machine account."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The provider must have accepted a connection from the property with the corresponding connection type for the API that is being called. For a list of connection types mapping to APIs and endpoints, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/connectivity/docs/connections-api/mapping-connections"},"children":["Mapping connection types with endpoints"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The requested endpoint must be enabled for the machine account."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The provider must have implemented and obtained any certifications required to implement the API solution. Most of the Connectivity APIs require self-certification. For example, ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/connectivity/docs/property-api/property-api-self-assessment-tutorial"},"children":["Property API"]},". Whereas, some API solutions that handle PII and PCI data might require providers to be PII and PCI compliant. For more information, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://portal.connectivity.booking.com/s/article/Introduction-on-PCI-and-PII-compliance?language=en_US"},"children":["Introduction on PCI and PII compliance"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The access token generated based on the machine account credentials hasn’t expired."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A connection type from a property defines the API capabilities a provider can use for a property. Endpoint access then lets you control which of those available capabilities a specific machine account can use. For more information on connection types and how they relate to access restrictions, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/connectivity/docs#managing-your-connections"},"children":["Managing your connections"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If you remove a connection type to a property or change it, the machine account loses access to endpoints that were previously available for that property."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"creating-new-machine-accounts","__idx":4},"children":["Creating new machine accounts"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When you create new machine accounts, the system assigns specific endpoints, by default. After creating a machine account, review its endpoint access before using it in production."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"updating-endpoint-access","__idx":5},"children":["Updating endpoint access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Using the Endpoint access tab, choose the API endpoints the machine account is allowed to call."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For each machine account, you can:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Review the existing endpoints access settings"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enable endpoints that the machine account needs"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Disable endpoints that the machine account should not use"]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Disabling endpoints"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Disabling an endpoint removes access to that endpoint for every property linked to the machine account. This change takes effect immediately and may cause API requests or integrations for multiple properties to fail. Before disabling an endpoint, verify which properties and integrations use it."," ","Note that disabling endpoint access for a machine account does not remove the provider-property connection type or the provider's API certification."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"migrating-existing-machine-accounts","__idx":6},"children":["Migrating existing machine accounts"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["During the Endpoint access launch, existing machine accounts carry forward the current access so current integrations continue to work. You can review and update the endpoint access for each machine account after launch."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If an endpoint is not available in the Provider Portal, contact ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://portal.connectivity.booking.com/s/CaseForm?language=en_US"},"children":["Connectivity Support"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"troubleshooting-error-response","__idx":7},"children":["Troubleshooting error response"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This section covers possible error responses related to endpoint access change and any proposed resolutions."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"why-do-i-get-a-http-403-error","__idx":8},"children":["Why do I get a HTTP 403 error?"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["An API returns the following HTTP/1.1 403 response when the endpoint access fails:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"http","header":{"controls":{"copy":{}}},"source":"Access denied: Request path <request path> not authorized\n","lang":"http"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To resolve the error, perform the following checks:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The endpoint is enabled for the machine account;"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The provider is certified for the API, when certification is required;"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The property has the correct connection type set up with your provider, when the API depends on a provider-property connection;"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The machine account belongs to the provider you are managing."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If these settings look correct and the request still returns 403, contact ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://portal.connectivity.booking.com/s/CaseForm?language=en_US"},"children":["Connectivity Support"]}," with the RUID details from the response."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"useful-resources","__idx":9},"children":["Useful resources"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/connectivity/docs/authentication#understanding-the-access-scope-using-machine-accounts"},"children":["Understanding the access scope using machine accounts"]},"."]}]}]},"headings":[{"value":"Managing endpoint access","id":"managing-endpoint-access","depth":1},{"value":"Before you begin","id":"before-you-begin","depth":2},{"value":"Who can manage endpoint access?","id":"who-can-manage-endpoint-access","depth":2},{"value":"How does endpoint access work with connection types?","id":"how-does-endpoint-access-work-with-connection-types","depth":2},{"value":"Creating new machine accounts","id":"creating-new-machine-accounts","depth":3},{"value":"Updating endpoint access","id":"updating-endpoint-access","depth":2},{"value":"Migrating existing machine accounts","id":"migrating-existing-machine-accounts","depth":2},{"value":"Troubleshooting error response","id":"troubleshooting-error-response","depth":2},{"value":"Why do I get a HTTP 403 error?","id":"why-do-i-get-a-http-403-error","depth":3},{"value":"Useful resources","id":"useful-resources","depth":2}],"frontmatter":{"title":"Managing endpoint access","description":"Learn how to manage endpoint access for machine accounts in the Provider Portal, including how connection types, certifications, and property links determine access to Connectivity API endpoints.","keywords":{"includes":["machine account","endpoint access","connection type","Provider Portal","Connectivity APIs"]},"seo":{"title":"Managing endpoint access"}},"lastModified":"2026-08-19T13:58:15.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/connectivity/docs/managing-endpoint-access","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}