Sixto APIAvailable

Build on Sixto, with the same rules as your team.

Everything your team does in Sixto goes through shared actions, and the API uses the same ones. A key only does what it has been granted and what its account is allowed, every call is logged, and sensitive actions are never on by default. Use it for reports, your own tools or your connected agent.

Available. A versioned REST API with scoped keys covers reservations, guests, tasks, finance, check-in, locks, channels and more.

[ WHAT IT DOES ]

What it does

  • Broad coverage

    Tasks, reservations, guests, reviews, messages, check-in, compliance, locks, channels, e-invoices, bank and ledger, market benchmarks, search and settings.

  • Scoped keys from one permission catalog

    Keys draw from the same permission catalog as people. An Owner can trim a key at any time and the next call is refused.

  • Self-describing

    Ask the API who you are and what you may do (whoami and capabilities), including each route's required permissions.

  • Safe retries and an activity log

    Idempotency keys make retries safe on write actions. Every request has an ID and appears in the activity log.

  • Fair limits

    Each key has its own allowance of 600 requests a minute, so one busy key never slows another.

[ HOW IT WORKS ]

How it works

  1. 01

    An Owner creates a key under Settings and ticks the permissions it needs. The key is shown once.

  2. 02

    Send it as a Bearer token. Call whoami and capabilities to see what the key can do.

  3. 03

    Read or write through the endpoints. Writes run the same checks as the app.

  4. 04

    Watch calls in the API activity view, and revoke a key whenever you want.

[ DATA ]

What syncs

DataDirectionDetails
Data you readInto SixtoFrom Sixto to your tool, only what the key may see. Guest contact details and ID numbers are masked.
Changes you makeFrom SixtoFrom your tool into Sixto, as audited actions.
[ PRIVACY ]

Permissions and privacy

  • Sensitive permissions are never on a key by default, and some can never be given to a key at all (for example remote unlock and managing integrations or team members).

  • Door code values, guest ID numbers and unmasked contact details need their own permission, are not in default answers, and each use is logged.

  • Keys are stored as hashes, so Sixto cannot show you a key again after you create it.

[ FAQ ]

Common questions

Is there a developer guide?

Yes. Ask us for the API reference and we will send it with your first key.

Can a key unlock a door?

No. Remote unlock is never available through the API.

Is the API versioned?

Yes, it lives under /api/v1.

Connect what you use. Skip what you do not.