Build on Sixto, with the same rules as your team.
Everything your team does in Sixto goes through shared actions, and the API uses the same ones. A key only does what it has been granted and what its account is allowed, every call is logged, and sensitive actions are never on by default. Use it for reports, your own tools or your connected agent.
Available. A versioned REST API with scoped keys covers reservations, guests, tasks, finance, check-in, locks, channels and more.
What it does
Broad coverage
Tasks, reservations, guests, reviews, messages, check-in, compliance, locks, channels, e-invoices, bank and ledger, market benchmarks, search and settings.
Scoped keys from one permission catalog
Keys draw from the same permission catalog as people. An Owner can trim a key at any time and the next call is refused.
Self-describing
Ask the API who you are and what you may do (whoami and capabilities), including each route's required permissions.
Safe retries and an activity log
Idempotency keys make retries safe on write actions. Every request has an ID and appears in the activity log.
Fair limits
Each key has its own allowance of 600 requests a minute, so one busy key never slows another.
How it works
- 01
An Owner creates a key under Settings and ticks the permissions it needs. The key is shown once.
- 02
Send it as a Bearer token. Call whoami and capabilities to see what the key can do.
- 03
Read or write through the endpoints. Writes run the same checks as the app.
- 04
Watch calls in the API activity view, and revoke a key whenever you want.
What syncs
Common questions
Is there a developer guide?
Yes. Ask us for the API reference and we will send it with your first key.
Can a key unlock a door?
No. Remote unlock is never available through the API.
Is the API versioned?
Yes, it lives under /api/v1.