HostAgent

Multi-vendor booking

One guest. Three vendors. One unwind.

The desk is yours. The room is Cloudbeds. Tickets are Skyline. The table is Skyline Dining. Payment is Stripe Connect — unless the hotel collects. If the gondola is gone, the room never sticks.

  1. 01

    One intent

    Maya asks your desk for a lakeview, the gondola, and dinner. One thread. Three vendors she will never speak to.

  2. 02

    Quote each system

    Cloudbeds remaining keys. Skyline Tickets cabin capacity. Skyline Dining 19:30. If any is gone, we say so before we touch the rest.

  3. 03

    Hold the hotel first

    The room is the anchor. Atomic remaining > 0 on Cloudbeds. If that fails, we stop. No orphan gondola tickets.

  4. 04

    Hold tickets and the table

    Skyline Tickets and Dining in parallel, each with their own idempotency key. Confirmations come back as GQ- and SF-.

  5. 05

    If one hold fails, unwind

    Compensating release: drop the gondola, drop the table, drop the room. Guest sees one sentence, not a half-booked night.

  6. 06

    Take payment

    Stripe Connect by default — one charge, split to each vendor. Or Windcave. Or the hotel collects at check-in. Card data never hits our servers.

  7. 07

    Confirm every vendor

    Hold becomes a reservation on each native system. Webhooks fire back. The itinerary is three confirmation numbers, not a promise.

  8. 08

    Itinerary in the thread

    Maya gets the room, GQ-4821, SF-1904. You see the same in Bookings. A later Booking.com sale cannot take that lakeview.

Systems in this night

  • REST book

    The Ridge

    Cloudbeds

  • REST + webhook

    Skyline

    Tickets + Dining

  • PCI token

    Stripe Connect

    One charge, split

  • Signed webhook

    Itinerary

    Three confirmations

One intent — in progress.

Patterns on the wire

REST book with idempotency

GET availability, then POST /holds with an Idempotency-Key. Same key twice is one booking.

Signed webhooks

They POST our /api/v1/webhooks/partner. HMAC of the body, timestamp window, replay-safe.

OAuth2 app credentials

Client credentials or authorization code. Tokens in the vault, never in the chat.

Channel-manager hub

We write remaining keys once. The hub pushes Booking.com, Airbnb, Expedia. Inbound sales come back as one reservation.

iCal two-way

Pull their .ics, block the night, push our .ics. Poll every 15 minutes. Weaker than REST — we say so.

Availability poll

Cron GET /availability. Cache for seconds, not hours. Book still goes to their POST.

Money