Skip to content

Setup guide

Connect Beds24 safely

Operators create credentials in Beds24, limit them to the properties they need, enter them directly in Acori, and can revoke them from Beds24 at any time.

What you need

  • An account that can administer Beds24
  • Access to the properties you will use with Acori
  • A credit card only when you are ready to activate production

From connection to activation

  1. Sign in to Beds24 and open Settings → Marketplace → API. Open the API V2 settings
  2. Select "Generate invite code" and grant every permission listed below. Enable "Allow linked properties" only when you use linked properties; leave the IP whitelist empty unless you were given a fixed IP.
  3. Enter an unused invite code less than 24 hours old directly in Acori, then import only the properties you will use. Do not send the code through email, chat, or a support record.
  4. Confirm only the required information Acori cannot infer.
  5. Review the content, send time, properties, and enabled state for each automated message. Nothing is sent during initial setup.
  6. Review the billing effect, agree to the content, and explicitly activate production.

Official Beds24 API V2 instructions

Required Beds24 permissions

This is the same permission list checked during connection validation and production activation.

  • Properties and room types · Read read:properties
  • Bookings · Read read:bookings
  • Bookings · Write write:bookings
  • Guest data and messages · Read read:bookings-personal
  • Guest data and messages · Write write:bookings-personal
  • Channel settings · Read read:channels
  • Channel settings · Write write:channels

Revocation, expiry, and reconnection

Revoking the credentials in Beds24 stops Acori from operating on the PMS. Acori keeps the property settings in a disconnected state so you can reconnect with a new invite code. Follow the on-screen diagnosis for expired credentials or missing permissions.

Where credentials do not belong

Do not store credentials in source code, browser storage, analytics events, public URLs, email, chat, or support notes. Acori encrypts credentials after entry and does not display them again.