Authenticate
Exchange your API username, password and microsite id for a token. Every other endpoint needs it in the auth-token header, and one token must carry a whole booking flow.
Behaviour
One token per booking flow
- Quote, Quote single, Confirm, Prebook and Book must all use the same token. This is mandatory.
- A new token mid-flow means starting again from Quote. An auto-refresh interceptor that swaps the token silently breaks flows.
- Before Quote, check the token has at least 60 minutes left. If it doesn't, authenticate first and start the flow on the new token.
Static content and back-office calls
- Static content calls don't need the booking-flow token. Any valid token works.
- For a long-running catalogue sync or back-office job, cache one token per credential and refresh it before it expires.
- We recommend one forced re-authentication on a 401 or 403 for these jobs, then failing and alerting. Never do this inside a booking flow, where a new token means a new flow.
Errors
| Status | Cause | What to do | |
|---|---|---|---|
| 401 | Wrong password or a deleted API user. Both return the same body: {"error":["User not authorized to access"],"status":"UNAUTHORIZED"} | Check the credential. If it was working before, ask your Nava account manager whether the API user still exists. | |
| 400 | micrositeId is missing from the body. | Send all three fields. | |
| 401 on a later call | User … not allowed to access here: the token is valid, but your account isn't enabled for that endpoint in this environment. | Don't re-authenticate or retry. Ask your Nava account manager to enable it. |
When a working integration suddenly gets 401 on every call, the API user has usually been deleted or its password rotated. Stop retrying, alert a person, and confirm the user with your Nava account manager. Then update the credential in every service that uses it.
Related
- Authentication guide
- OTP
- Quote, the first call of a booking flow
- Environments
- Conventions