Expedia Rapid API integration
Expedia API integration: Rapid API, booking flow and go-live
Everything an OTA, agency or travel startup needs to connect Expedia Group: which Expedia API fits your business, how the Rapid booking flow and signature work, what the launch review checks, what it costs, and how PHPTRAVELS gets you live with the hotel flow already built.
- Rapid Lodging API
- API key and SHA-512 signature
- Sandbox and test bookings
- Launch review and go-live
The Expedia Group APIs
Which Expedia API fits your business
Expedia Group runs separate API programs for sellers, affiliates, hotels and travel agents. Pick by one question first: where does the traveller pay?
- Demand side
Rapid API
Our focus- Built for
- OTAs, travel agencies, travel apps and loyalty programs that sell travel under their own brand.
- What you get
- Live Expedia inventory and the full booking path: shopping, price check, booking, changes and cancellations.
- Where the traveller books
- On your website or app, in your own checkout.
- With PHPTRAVELS
- The hotel flow is built into the stays module; you configure, map and certify it.
- Affiliate side
Travel Redirect API
- Built for
- Content sites, travel blogs and metasearch-style pages that earn a commission on referrals.
- What you get
- Lodging and flight listings to show on your pages, with links to the Expedia brand you choose.
- Where the traveller books
- On Expedia, Hotels.com or Vrbo, after a redirect.
- With PHPTRAVELS
- Usable as listings and links on a PHPTRAVELS site; no booking happens on your site.
- Supply side
Supply and connectivity APIs
- Built for
- Hotels, property management systems and channel managers.
- What you get
- Push rates, availability and restrictions to Expedia and pull the reservations it takes.
- Where the traveller books
- On Expedia; the property receives the booking.
- With PHPTRAVELS
- For hotels that sell on Expedia, through the extranet or a channel manager.
- Travel agents
Expedia TAAP
- Built for
- Travel agents who book for clients and earn commission.
- What you get
- Expedia's agent portal with agent rates and commission tracking.
- Where the traveller books
- In the TAAP portal, booked by the agent.
- With PHPTRAVELS
- Agents can record TAAP bookings in your back office; the API route is Rapid.
Expedia has paused new Travel Redirect API applications because of request volume.
Rapid API products
- Rapid Lodging APIBuilt in PHPTRAVELS
- Rapid Car APICustom integration
- Rapid Flight APICustom integration
- Rapid Activities APICustom integration
StaysTravel affiliate programExpedia ExtranetExpedia TAAP API integrationCustom API integration
The Rapid booking flow
How an Expedia hotel booking runs, call by call
Rapid Lodging bookings follow a fixed chain. Pick a step to see the call, what PHPTRAVELS does with it and what to watch for in certification.
Rapid call
GET /v3/properties/content- What PHPTRAVELS does
- Imports property names, addresses, images, amenities, room types and policies into the hotel pages, and refreshes them on a schedule.
- Watch for
- Use the property content file for a full catalogue and the content API for updates; never scrape the shopping response for content.
Rapid call
GET /v3/properties/availability- What PHPTRAVELS does
- Searches by dates, occupancy and property IDs, then shows each room with its rate, taxes and fees, and cancellation policy.
- Watch for
- Show the total price with taxes and fees before checkout, and send the traveller's IP and session headers with every request.
Rapid call
GET {price_check link}- What PHPTRAVELS does
- Calls the price check link of the chosen rate just before payment, and only continues on a matched price.
- Watch for
- A changed or sold-out rate must stop the checkout and offer a new choice, never charge the old price.
Rapid call
POST /v3/itineraries- What PHPTRAVELS does
- Creates the itinerary with guest details and payment, stores the Expedia itinerary ID and sends the voucher.
- Watch for
- Holdable rates support a two-step model: hold a room without a charge, then resume to complete the booking.
Rapid call
GET /v3/itineraries/{itinerary_id}- What PHPTRAVELS does
- Reads the itinerary back to confirm dates, room, price, confirmation numbers and status in the admin.
- Watch for
- After a timeout, retrieve first and only retry if no itinerary exists, so a guest is never booked twice.
Rapid call
DELETE /v3/itineraries/{id}/rooms/{room_id}- What PHPTRAVELS does
- Runs changes and cancellations from the admin and the customer account, following the rate's policy.
- Watch for
- Penalties come from the rate's cancellation policy; show them to the traveller before confirming.
Rapid call
POST https://your-site/webhooks/expedia- What PHPTRAVELS does
- Receives webhook events for itinerary changes at a URL in your install and updates the booking.
- Watch for
- Answer the webhook quickly, and treat Expedia's record as the source of truth for status.
Call paths as documented for Rapid v3; always check the current Expedia Group Developer Hub.
API key and signature
How Expedia Rapid API authentication works
Each Rapid request carries an authorization header with your API key and a signature: a SHA-512 hash of the API key, the shared secret and the current UNIX timestamp in seconds.
- Five-minute window
- The timestamp must be within five minutes of Expedia's server time, and the one you hash must match the one in the header.
- Secret stays server-side
- The shared secret is a password. PHPTRAVELS keeps it in the server configuration, never in the browser or an app.
- Test endpoint
- Sandbox calls go to test.ean.com and create no real bookings or card charges; a test header simulates outcomes such as sold out or price changed.
- Why it says EAN
- EAN is Expedia Affiliate Network, the program's former name. It lives on in the header scheme and the endpoints.
1// keys come from the server config, never from the browser 2$key = getenv('EXPEDIA_API_KEY'); 3$secret = getenv('EXPEDIA_SHARED_SECRET'); 4$ts = time(); // UNIX seconds, within 5 minutes of Expedia 5 6$signature = hash('sha512', $key . $secret . $ts); 7 8$headers = [ 9 "Authorization: EAN APIKey=$key,Signature=$signature,timestamp=$ts",10 'Accept: application/json',11 'Accept-Encoding: gzip',12 'Customer-Ip: ' . $travellerIp,13];1415// sandbox: https://test.ean.com · live: https://api.ean.com
Implementation guide
Expedia API integration, step by step
From partner application to the first live booking. Each step shows who does the work.
- 01
Apply as an Expedia Group partner
Apply through Expedia Group partner solutions with your company, domain and business model. Commercial terms are agreed with Expedia for your region and volume.
YouExpedia - 02
Receive the API key and shared secret
Once approved, you get Rapid credentials and documentation access in the developer hub.
Expedia - 03
Configure the Expedia connector
Add the credentials in the PHPTRAVELS admin, import content, set markups and currencies, and map rooms and policies to the hotel pages.
PHPTRAVELSYou - 04
Run the test bookings
Book against the test endpoint and simulate sold-out rooms, price changes, timeouts and error codes until every case is handled.
PHPTRAVELSYou - 05
Pass the launch review
Expedia reviews your site against its launch requirements and asks for a PCI Attestation of Compliance before production.
ExpediaYou - 06
Switch to production and sell
Production credentials go in the admin, live bookings start, and the supplier logs stay on for support cases.
YouPHPTRAVELS
Timelines and alternatives
Four ways to sell Expedia inventory
Building on Rapid from scratch gives full control but costs months of engineering. A ready booking engine, an affiliate redirect and the agent portal each trade something different.
| Route | Time to launch | Checkout on your site | Who maintains it | Best for |
|---|---|---|---|---|
| Build in-house on Rapid | Time to launchMonths: search, checkout, admin and certification built from zero | Checkout on your siteYes | Who maintains itYour developers, for every Expedia API change | Best forLarge OTAs with their own engineering team |
| Ready booking engine (PHPTRAVELS)PHPTRAVELS | Time to launchWeeks: the hotel flow exists, the time goes into setup and Expedia's review | Checkout on your siteYes | Who maintains itThe engine's updates, with the full source code in your hands | Best forAgencies and startups that want their own brand and checkout fast |
| Affiliate redirect | Time to launchDays, if Expedia accepts the application | Checkout on your siteNo | Who maintains itExpedia runs the booking path | Best forContent and blog sites that earn referral commission |
| Agent portal (TAAP) | Time to launchNo build: agents book in Expedia's portal | Checkout on your siteNo | Who maintains itExpedia | Best forAgents booking one trip at a time for clients |
Launch requirements
What Expedia checks before you go live
The review looks at how your site behaves, not only whether calls succeed. Tick off what your build already does; PHPTRAVELS covers every item in its standard hotel flow.
Costs
How much does an Expedia API integration cost?
Expedia does not publish a price list for API access; you earn on bookings under the terms you agree with Expedia. Your own costs are the software, the hosting and compliance.
Expedia access
Agreed with Expedia: commission or margin on bookings, depending on your contract, region and volume.
Booking engine
PHPTRAVELS is a one-time licence from $2,499 with the full source code, so no monthly fee per booking.
Hosting
Your own server or our managed hosting; the Expedia connector runs inside your install.
Payments and PCI
A payment gateway and PCI compliance for card data, which Expedia asks you to prove at launch.
FAQ
Expedia API integration questions
Short answers to what agencies ask before they apply.
Talk to salesExpedia does not charge a published fee for Rapid API access. You need an approved partnership, and you earn through commission or margin under the terms you agree with Expedia. Your costs are your booking software, hosting and PCI compliance.
Apply as a partner through Expedia Group partner solutions. After approval you receive an API key and a shared secret for Rapid, with sandbox access to build and test before the launch review.
Rapid is Expedia Group's REST and JSON API for selling travel under your own brand. It covers lodging, cars, flights and activities, with shopping, price check, booking and management calls.
EAN, the Expedia Affiliate Network, was the former name of Expedia's partner program. Rapid is the current API; the EAN name remains in the authorization header and the endpoint addresses.
Use Rapid if travellers should book on your own website or app. Use TAAP if your agents book trips for clients in Expedia's portal and earn commission.
Yes. Requests to the test endpoint do not create real bookings or card charges, and a test header lets you simulate outcomes such as sold-out rooms or price changes.
Building from scratch takes months. With PHPTRAVELS the hotel flow already exists, so the time goes into configuration, content mapping and Expedia's launch review, which Expedia schedules.
The Expedia hotel flow is built into the stays module. Rapid cars, flights and activities can be added as a custom integration on top of the cars, flights and tours modules.
Keep exploring
More from the platform
- Expedia TAAP API integrationTAAP hotels, commissions and changes in your portal
- Expedia ExtranetPartner portal for rates, inventory and bookings
- Hotelbeds API integrationLive Hotelbeds rates, bookings and vouchers
- Booking.com and Priceline APIsBooking.com, Priceline and Expedia hotel API access
- StaysBedbanks and direct contracts
- Custom API integrationConnect any supplier or partner API to PHPTRAVELS
