A compiled reference of 31 verified statistics on API access across 19 vacation rental property management systems: who lets customers self-serve credentials and who requires partner agreements, every published rate limit from 60 to 2,000 requests per minute, which platforms run official MCP servers, and who publishes llms.txt for AI agents. Every figure comes from the platform's own developer documentation or help center, fetched and checked in August 2026 before publishing.
Key statistics
6 highlights from this report
Key statistics
Key takeaways
The vacation rental software industry talks "open API" almost universally, but in practice fewer than half of the 19 platforms audited let a customer mint credentials without talking to sales, a partner team, or a billing department. AI-agent readiness is thinner still: three live MCP servers, and an llms.txt landscape where half the files are SEO-plugin exhaust.
Only 9 of 19 vacation rental PMSs let customers self-serve API credentials.
3 of 19 run a live official MCP server; Hospitable's was the industry's first.
13 of 19 publish developer docs you can read without logging in.
Published rate limits span 33x, from 60 to 2,000 requests per minute.
8 of 19 publish llms.txt, and half of those are SEO-plugin autogenerated.
Escapia is the only PMS that says outright it won't publish its rate limits.
How we built this report
Every figure was compiled in August 2026 directly from each platform's own developer documentation, help center, or marketing site, then independently re-verified before publishing.
- Primary sources only
We read each platform's official developer docs, API reference, and help-center articles. No third-party blogs, no vendor comparison sites, no hearsay.
- Direct fetch checks
Binary claims were tested directly: all 19 llms.txt URLs were fetched, all 5 claimed MCP pages were loaded, and login walls were confirmed by requesting the gated docs.
- Disagreements shown, not averaged
Where a platform's own pages conflict (Hostfully publishes two different rate limits), we report both rather than picking one.
- Independent review
Written by one co-founder, reviewed by the other before publishing.
Scope caveat: this audit reflects what each platform publicly documents as of August 1, 2026. API programs change, docs move, and some platforms offer access paths they don't document publicly. "Not documented" means we could not find it on the platform's own public pages, not that the capability is impossible to obtain. Confirm against the specific platform before building.
Vacation rental PMS API access, by the numbers
All 31 figures, grouped by theme. Each traces to a named page on the platform's own domain, fetched and checked in August 2026.
Who can actually get in: access models
The single most useful thing to know before building against a PMS is whether credentials exist without a conversation. According to each platform's own documentation, 9 of 19 offer a self-serve path: Guesty, Hostaway, OwnerRez, Hospitable, Lodgify, Smoobu, Beds24, Tokeet, and Track all document generating a key or token inside the app. The other 10 route through partner programs, paid add-ons, or sales. The gating language is explicit when you read the primary sources: CiiRUS's partner docs require "a Mutual Non-Disclosure Agreement," an RFI, and "a mutual agreement on commercial terms" before credentials are issued; Escapia's help center says to "work with your assigned Escapia relationship manager"; Hostfully's help center says missing API keys mean "you haven't added API access to your subscription... contact our billing team." Platform-by-platform detail lives on our developer access pages.
Statistic 1
13 of 19 vacation rental PMSs (68%) publish developer documentation readable without a login.
Audit of 19 platforms' developer portals (Aug 2026)
Statistic 2
Only 9 of 19 (47%) let a customer generate API credentials for their own account in-app.
Each platform's official auth/getting-started docs (Aug 2026)
Statistic 3
3 of those 9 self-serve platforms still gate by plan or account flag: Hospitable excludes Essentials, Smoobu requires Professional, Guesty requires API access enabled on the account.
help.hospitable.com; support.smoobu.com; open-api-docs.guesty.com (2026)
Statistic 4
Hostfully sells API access as a subscription add-on: a missing key means "you haven't added API access to your subscription" and routes you to the billing team.
Hostfully Help Center, "Exporting data through the Hostfully API" (2026)
Statistic 5
CiiRUS requires an NDA, an RFI, a commercial agreement, and integration certification before an integration can go live.
CiiRUS Partner-API docs, "Steps to Success" (2026)
Statistic 6
Escapia (Expedia Group) routes all API access through your "assigned Escapia relationship manager" plus signed agreements before access is set up.
Escapia Support, "Accessing Data via the Escapia API" (2026)
Statistic 7
Streamline's API documentation sits behind a partner-portal login; third parties are told to "contact us to request more information about becoming a Streamline third-party partner."
streamlinevrs.com Open API page; partner.streamlinevrs.com (2026)
Statistic 8
Barefoot's only public API surface is an auto-generated SOAP endpoint listing; documented access starts with an email to partner relations.
barefoot.com Partners page; portals.barefoot.com web service (2026)
Statistic 9
Avantio provides API documentation only "upon request," with integrations built and QA'd through Avantio's own team.
Avantio, "API Integrations" (2026)
Statistic 10
Uplisting shows an API key in-app, but usable V2 client IDs and V3 OAuth clients are issued only by emailing the partner team and signing a Partner API Integration agreement.
Uplisting Support, "API partner integration" (2026)
Statistic 11
iGMS requires developer-program registration, and its pricing page lists Open API access as "Upon request" on every plan.
iGMS API docs; igms.com/pricing (2026)
What this means: "We have an open API" and "you can get credentials today" are different claims. If you're evaluating a PMS partly on data access, the self-serve nine are the only platforms where the answer doesn't depend on someone else's approval queue.
The scorecard: all 19 platforms
One row per platform: how credentials are issued, the documented auth scheme, the published rate limit, and the three AI-era signals (official MCP server, root llms.txt, documented iCal export). Everything in this table traces to the sources listed at the bottom of the page.
| Platform | API access | Auth | Published limit | MCP | llms.txt | iCal |
|---|---|---|---|---|---|---|
| Hostaway | Self-serve | OAuth2 client creds | 15/10s IP, 20/10s acct | |||
| OwnerRez | Self-serve | PAT / OAuth2 | 300 / 5 min | |||
| Lodgify | Self-serve | API key | 600-750 / min | |||
| Beds24 | Self-serve | Token (invite code) | 100 credits / 5 min | |||
| Tokeet | Self-serve | API key | none published | |||
| Track | Self-serve | Basic / HMAC | 10,000 / 5 min | |||
| Guesty plan flag | Plan-gated | OAuth2 client creds | 15/s, 5,000/hr | |||
| Hospitable not Essentials | Plan-gated | PAT / OAuth2 | per-endpoint | |||
| Smoobu Professional | Plan-gated | HMAC | 1,000 / min | |||
| Hostfully paid add-on | Add-on | API key / OAuth2 | 1,000-10,000 / hr | |||
| Uplisting | Partner-gated | Basic / OAuth2 PKCE | 100/min IP, 15/min prop | |||
| iGMS | On request | OAuth2 | 1,000 / min | |||
| Escapia | Partner-gated | Basic + OAuth Bearer | refuses to publish | |||
| CiiRUS | NDA + cert | Basic | none published | |||
| Streamline | Partner-gated | Portal tokens | none published | |||
| Barefoot | Partner-gated | SOAP credentials | none published | |||
| LiveRez | No public docs | not documented | none published | |||
| Avantio | Docs on request | not documented | none published | |||
| RentalReady | No public docs | not documented | none published |
What this means: the openness leaders aren't the biggest brands. Track pairs public docs with self-serve keys and the highest published limit in the audit; Beds24 and Tokeet, both indie-host tools, are more self-serve than most enterprise-tier platforms. The professional-manager legacy stack (Escapia, Streamline, Barefoot, CiiRUS) is uniformly partner-gated.
Rate limits and token mechanics
Rate limits are where API marketing meets engineering reality, and the spread is enormous. According to Track's developer documentation, its limit is 10,000 requests every 5 minutes; according to OwnerRez's support docs, its limit is 300 requests every 5 minutes, a 33x difference between the two platforms that publish per-window IP limits at the extremes. Token mechanics diverge just as widely: Guesty's quick-start guide allows only five access tokens per key per 24 hours, while Hostaway's documentation gives a single token a 24-month lifetime.
Statistic 12
10 of 19 platforms (53%) publish numeric API rate limits.
Audit of each platform's official docs (Aug 2026)
Statistic 13
Escapia is the only platform that explicitly refuses to publish limits: "We reserve the right to change the limits... Consequently we will not publish the exact limits."
Escapia Gateway API documentation (2026)
Statistic 14
Published per-IP limits span 33x: OwnerRez allows 300 requests per 5 minutes, Track allows 10,000 per 5 minutes.
OwnerRez API rate limiting docs; Track developer docs (2026)
Statistic 15
Guesty allows only 5 access tokens per API key per 24 hours; integrations that don't cache tokens lock themselves out for the day.
Guesty Open API quick start guide (2026)
Statistic 16
Hostaway's access tokens live 24 months, the longest documented token lifetime in the audit.
Hostaway Public API documentation (2026)
Statistic 17
OwnerRez limits any single IP address to accessing 2 different user accounts per 24 hours, a documented anti-scraping control unique in the audit.
OwnerRez API authentication docs (2026)
Statistic 18
Smoobu sunsets legacy API-key auth on September 25, 2026; all requests must move to HMAC signatures with a timestamp and single-use nonce.
Smoobu API documentation (2026)
Statistic 19
Beds24 meters API usage in credits (100 per 5-minute window by default) and is the only platform publishing an API price: 10 EUR per month per additional 100 credits.
Beds24 API V2 wiki (2026)
Statistic 20
Hostfully's own pages disagree on its rate limit: the developer portal says 10,000 calls per hour, the help center says the default is 1,000 per hour.
dev.hostfully.com; Hostfully Help Center API FAQ (2026)
Statistic 21
Tokeet publishes a full API reference but no rate limits at all; Uplisting publishes three: 5/second per IP, 100/minute per IP, and 15/minute per property.
Tokeet Client API docs; Uplisting API docs (2026)
What this means: if you're syncing a 200-unit portfolio, the difference between OwnerRez's 60 requests a minute and Track's 2,000 is the difference between a nightly batch job and near-real-time sync. Check the limit before you design the architecture, not after.
AI readiness: MCP servers and llms.txt
The newest openness signal is whether a platform serves AI agents directly. According to Hospitable's changelog, its April 2026 launch was "the first official MCP server from a short-term rental platform," and its help center documents write access: connected agents can send guest messages, not just read data. Track followed with a hosted MCP server that makes live API calls, and Guesty's is live in beta but read-only ("assistants can look up and summarize data, but cannot create, update, or delete Guesty records," per its docs). Everyone else is a waitlist, a marketing page, or absent. The llms.txt picture is similar: 8 of 19 root domains serve one, but half of those files are generated by SEO plugins rather than written for agents.
Statistic 22
5 of 19 platforms (26%) have any official MCP presence; 14 have none at all.
Audit of official platform domains (Aug 2026)
Statistic 23
Only 3 run a live, documented MCP server today: Hospitable, Track, and Guesty (beta).
hospitable.com; developer.trackhs.com; open-api-docs.guesty.com (Aug 2026)
Statistic 24
Hospitable shipped the industry's first official MCP server in April 2026; it is write-capable (sends guest messages) and available on all plans except Essentials.
Hospitable changelog and MCP help article (2026)
Statistic 25
Guesty's MCP server is beta and read-only: "assistants can look up and summarize data, but cannot create, update, or delete Guesty records."
Guesty Open API docs, "Guesty MCP Server (beta)" (2026)
Statistic 26
Track's hosted MCP server both searches its API docs and makes live API calls against your account.
Track developer docs, "MCP Setup in Claude Code" (2026)
Statistic 27
Lodgify's MCP is waitlist-gated; RentalReady advertises MCP on a feature page with zero technical documentation.
mcp.lodgify.com; rentalready.com/features/mcp (Aug 2026)
Statistic 28
8 of 19 platforms (42%) serve llms.txt at their root domain: Hostaway, Hospitable, Hostfully, Tokeet, Track, CiiRUS, Avantio, and RentalReady.
Direct fetch of all 19 root llms.txt URLs (Aug 1, 2026)
Statistic 29
4 of those 8 llms.txt files are SEO-plugin autogenerated (Yoast, All in One SEO, or Rank Math) rather than hand-written for AI agents.
File contents of each llms.txt (Aug 2026)
Statistic 30
Guesty and OwnerRez publish llms.txt only on their API-docs subdomains, both explicitly addressed to agents; OwnerRez's opens "This file orients AI agents."
open-api-docs.guesty.com/llms.txt; api.ownerrez.com/llms.txt (Aug 2026)
Statistic 31
14 of 19 platforms (74%) officially document iCal calendar export, the universal fallback when API access is gated.
Each platform's help center or feature pages (Aug 2026)
What this means: AI agents are becoming a real client of PMS data, and three platforms have noticed. If your platform is in the other sixteen, iCal is usually the honest floor for getting bookings data into anything you build. If you're building against these APIs, our developer access hub and reference data model are built for exactly that.
Cite this study
Academic or press use: copy a ready-made reference. RapidEye is the publisher.
Quick FAQ
Which vacation rental PMSs have open, self-serve APIs?
9 of the 19 platforms audited in August 2026 let a customer generate API credentials for their own account inside the app: Guesty, Hostaway, OwnerRez, Hospitable, Lodgify, Smoobu, Beds24, Tokeet, and Track. Three of those still gate by plan or account flag: Hospitable excludes its Essentials plan, Smoobu requires the Professional plan, and Guesty requires API access to be enabled on the account. The other 10 platforms require a partner application, an agreement, a paid add-on, or a sales conversation before credentials exist.
Do any vacation rental PMSs have official MCP servers?
Yes. As of August 2026, 3 of 19 platforms run a live, documented MCP server: Hospitable (launched April 2026, the first official MCP server from a short-term rental platform, write-capable and available on all plans except Essentials), Track (a hosted server that makes live API calls), and Guesty (in beta and read-only). Lodgify has announced an MCP behind a waitlist, and RentalReady advertises MCP on a marketing page with no technical documentation.
Which vacation rental PMSs have no public API documentation?
6 of 19 audited platforms publish no login-free developer documentation: Streamline (docs sit behind a partner-portal login), LiveRez (claims an open API but publishes no docs), Avantio (documentation provided on request only), RentalReady (references an API in marketing with no developer docs), and Barefoot (only an auto-generated SOAP endpoint listing). Escapia publishes docs publicly but gates all access behind an assigned relationship manager and signed agreements.
Data sources
Every figure on this page traces to one of these platforms' own developer docs, help centers, or official pages, each fetched and checked against the original on August 1, 2026.

