Expedia Rapid API integration

Expedia API integration: Rapid API, booking flow and go-live

Everything an OTA, agency or travel startup needs to connect Expedia Group: which Expedia API fits your business, how the Rapid booking flow and signature work, what the launch review checks, what it costs, and how PHPTRAVELS gets you live with the hotel flow already built.

  • Rapid Lodging API
  • API key and SHA-512 signature
  • Sandbox and test bookings
  • Launch review and go-live

The Expedia Group APIs

Which Expedia API fits your business

Expedia Group runs separate API programs for sellers, affiliates, hotels and travel agents. Pick by one question first: where does the traveller pay?

  • Demand side

    Rapid API

    Our focus
    Built for
    OTAs, travel agencies, travel apps and loyalty programs that sell travel under their own brand.
    What you get
    Live Expedia inventory and the full booking path: shopping, price check, booking, changes and cancellations.
    Where the traveller books
    On your website or app, in your own checkout.
    With PHPTRAVELS
    The hotel flow is built into the stays module; you configure, map and certify it.
  • Affiliate side

    Travel Redirect API

    Built for
    Content sites, travel blogs and metasearch-style pages that earn a commission on referrals.
    What you get
    Lodging and flight listings to show on your pages, with links to the Expedia brand you choose.
    Where the traveller books
    On Expedia, Hotels.com or Vrbo, after a redirect.
    With PHPTRAVELS
    Usable as listings and links on a PHPTRAVELS site; no booking happens on your site.
  • Supply side

    Supply and connectivity APIs

    Built for
    Hotels, property management systems and channel managers.
    What you get
    Push rates, availability and restrictions to Expedia and pull the reservations it takes.
    Where the traveller books
    On Expedia; the property receives the booking.
    With PHPTRAVELS
    For hotels that sell on Expedia, through the extranet or a channel manager.
  • Travel agents

    Expedia TAAP

    Built for
    Travel agents who book for clients and earn commission.
    What you get
    Expedia's agent portal with agent rates and commission tracking.
    Where the traveller books
    In the TAAP portal, booked by the agent.
    With PHPTRAVELS
    Agents can record TAAP bookings in your back office; the API route is Rapid.

Expedia has paused new Travel Redirect API applications because of request volume.

Rapid API products

  • Rapid Lodging APIBuilt in PHPTRAVELS
  • Rapid Car APICustom integration
  • Rapid Flight APICustom integration
  • Rapid Activities APICustom integration

StaysTravel affiliate programExpedia ExtranetExpedia TAAP API integrationCustom API integration

The Rapid booking flow

How an Expedia hotel booking runs, call by call

Rapid Lodging bookings follow a fixed chain. Pick a step to see the call, what PHPTRAVELS does with it and what to watch for in certification.

Rapid call

GET /v3/properties/content
What PHPTRAVELS does
Imports property names, addresses, images, amenities, room types and policies into the hotel pages, and refreshes them on a schedule.
Watch for
Use the property content file for a full catalogue and the content API for updates; never scrape the shopping response for content.

Rapid call

GET /v3/properties/availability
What PHPTRAVELS does
Searches by dates, occupancy and property IDs, then shows each room with its rate, taxes and fees, and cancellation policy.
Watch for
Show the total price with taxes and fees before checkout, and send the traveller's IP and session headers with every request.

Rapid call

GET {price_check link}
What PHPTRAVELS does
Calls the price check link of the chosen rate just before payment, and only continues on a matched price.
Watch for
A changed or sold-out rate must stop the checkout and offer a new choice, never charge the old price.

Rapid call

POST /v3/itineraries
What PHPTRAVELS does
Creates the itinerary with guest details and payment, stores the Expedia itinerary ID and sends the voucher.
Watch for
Holdable rates support a two-step model: hold a room without a charge, then resume to complete the booking.

Rapid call

GET /v3/itineraries/{itinerary_id}
What PHPTRAVELS does
Reads the itinerary back to confirm dates, room, price, confirmation numbers and status in the admin.
Watch for
After a timeout, retrieve first and only retry if no itinerary exists, so a guest is never booked twice.

Rapid call

DELETE /v3/itineraries/{id}/rooms/{room_id}
What PHPTRAVELS does
Runs changes and cancellations from the admin and the customer account, following the rate's policy.
Watch for
Penalties come from the rate's cancellation policy; show them to the traveller before confirming.

Rapid call

POST https://your-site/webhooks/expedia
What PHPTRAVELS does
Receives webhook events for itinerary changes at a URL in your install and updates the booking.
Watch for
Answer the webhook quickly, and treat Expedia's record as the source of truth for status.

Call paths as documented for Rapid v3; always check the current Expedia Group Developer Hub.

API key and signature

How Expedia Rapid API authentication works

Each Rapid request carries an authorization header with your API key and a signature: a SHA-512 hash of the API key, the shared secret and the current UNIX timestamp in seconds.

Five-minute window
The timestamp must be within five minutes of Expedia's server time, and the one you hash must match the one in the header.
Secret stays server-side
The shared secret is a password. PHPTRAVELS keeps it in the server configuration, never in the browser or an app.
Test endpoint
Sandbox calls go to test.ean.com and create no real bookings or card charges; a test header simulates outcomes such as sold out or price changed.
Why it says EAN
EAN is Expedia Affiliate Network, the program's former name. It lives on in the header scheme and the endpoints.
Signing a Rapid request (PHP)
 1// keys come from the server config, never from the browser 2$key    = getenv('EXPEDIA_API_KEY'); 3$secret = getenv('EXPEDIA_SHARED_SECRET'); 4$ts     = time(); // UNIX seconds, within 5 minutes of Expedia 5 6$signature = hash('sha512', $key . $secret . $ts); 7 8$headers = [ 9  "Authorization: EAN APIKey=$key,Signature=$signature,timestamp=$ts",10  'Accept: application/json',11  'Accept-Encoding: gzip',12  'Customer-Ip: ' . $travellerIp,13];1415// sandbox: https://test.ean.com  ·  live: https://api.ean.com
SHA-512±5 mintest.ean.com → api.ean.com

Implementation guide

Expedia API integration, step by step

From partner application to the first live booking. Each step shows who does the work.

  1. 01

    Apply as an Expedia Group partner

    Apply through Expedia Group partner solutions with your company, domain and business model. Commercial terms are agreed with Expedia for your region and volume.

    YouExpedia
  2. 02

    Receive the API key and shared secret

    Once approved, you get Rapid credentials and documentation access in the developer hub.

    Expedia
  3. 03

    Configure the Expedia connector

    Add the credentials in the PHPTRAVELS admin, import content, set markups and currencies, and map rooms and policies to the hotel pages.

    PHPTRAVELSYou
  4. 04

    Run the test bookings

    Book against the test endpoint and simulate sold-out rooms, price changes, timeouts and error codes until every case is handled.

    PHPTRAVELSYou
  5. 05

    Pass the launch review

    Expedia reviews your site against its launch requirements and asks for a PCI Attestation of Compliance before production.

    ExpediaYou
  6. 06

    Switch to production and sell

    Production credentials go in the admin, live bookings start, and the supplier logs stay on for support cases.

    YouPHPTRAVELS

Timelines and alternatives

Four ways to sell Expedia inventory

Building on Rapid from scratch gives full control but costs months of engineering. A ready booking engine, an affiliate redirect and the agent portal each trade something different.

RouteTime to launchCheckout on your siteWho maintains itBest for
Build in-house on RapidTime to launchMonths: search, checkout, admin and certification built from zeroCheckout on your siteYesWho maintains itYour developers, for every Expedia API changeBest forLarge OTAs with their own engineering team
Ready booking engine (PHPTRAVELS)PHPTRAVELSTime to launchWeeks: the hotel flow exists, the time goes into setup and Expedia's reviewCheckout on your siteYesWho maintains itThe engine's updates, with the full source code in your handsBest forAgencies and startups that want their own brand and checkout fast
Affiliate redirectTime to launchDays, if Expedia accepts the applicationCheckout on your siteNoWho maintains itExpedia runs the booking pathBest forContent and blog sites that earn referral commission
Agent portal (TAAP)Time to launchNo build: agents book in Expedia's portalCheckout on your siteNoWho maintains itExpediaBest forAgents booking one trip at a time for clients

Launch requirements

What Expedia checks before you go live

The review looks at how your site behaves, not only whether calls succeed. Tick off what your build already does; PHPTRAVELS covers every item in its standard hotel flow.

0 of 8 ready

Costs

How much does an Expedia API integration cost?

Expedia does not publish a price list for API access; you earn on bookings under the terms you agree with Expedia. Your own costs are the software, the hosting and compliance.

  • Expedia access

    Agreed with Expedia: commission or margin on bookings, depending on your contract, region and volume.

  • Booking engine

    PHPTRAVELS is a one-time licence from $2,499 with the full source code, so no monthly fee per booking.

  • Hosting

    Your own server or our managed hosting; the Expedia connector runs inside your install.

  • Payments and PCI

    A payment gateway and PCI compliance for card data, which Expedia asks you to prove at launch.

FAQ

Expedia API integration questions

Short answers to what agencies ask before they apply.

Talk to sales

Expedia does not charge a published fee for Rapid API access. You need an approved partnership, and you earn through commission or margin under the terms you agree with Expedia. Your costs are your booking software, hosting and PCI compliance.

Apply as a partner through Expedia Group partner solutions. After approval you receive an API key and a shared secret for Rapid, with sandbox access to build and test before the launch review.

Rapid is Expedia Group's REST and JSON API for selling travel under your own brand. It covers lodging, cars, flights and activities, with shopping, price check, booking and management calls.

EAN, the Expedia Affiliate Network, was the former name of Expedia's partner program. Rapid is the current API; the EAN name remains in the authorization header and the endpoint addresses.

Use Rapid if travellers should book on your own website or app. Use TAAP if your agents book trips for clients in Expedia's portal and earn commission.

Yes. Requests to the test endpoint do not create real bookings or card charges, and a test header lets you simulate outcomes such as sold-out rooms or price changes.

Building from scratch takes months. With PHPTRAVELS the hotel flow already exists, so the time goes into configuration, content mapping and Expedia's launch review, which Expedia schedules.

The Expedia hotel flow is built into the stays module. Rapid cars, flights and activities can be added as a custom integration on top of the cars, flights and tours modules.