Environments and credentials
The two base URLs, one for your test account and one for production, the credentials that go with each, what to expect from test suppliers, and what depends on your microsite.
Base URLs
Your test account and production have different base URLs. Prefix every path in this documentation with the base URL of the environment you are calling: the paths, headers and bodies are the same in both, only the host changes.
For example, Quote is POST https://sandbox.nava.travel/resources/booking/accommodations/quote in your test account and POST https://nava.travel/resources/booking/accommodations/quote in production. The OpenAPI specification is at /openapi.json and /openapi.yaml.
Getting credentials
Your Nava account manager issues two sets of credentials. Each set is a username, a password and a micrositeId. There is no self-registration.
| Set | When you get it | What it reaches |
|---|---|---|
| Test credentials | When you start your integration | The sandbox, https://sandbox.nava.travel/resources: a test account whose microsite only has test suppliers. Build, test and make your certification bookings here. |
| Production credentials | After certification | Production, https://nava.travel/resources: your own microsite and the real suppliers connected to it. |
- Keep them in environment variables or a secrets manager, never in code. The examples on this site read
NAVA_BASE_URL,NAVA_USERNAME,NAVA_PASSWORDandNAVA_MICROSITE_ID. - Each set belongs to one base URL: test credentials with the sandbox, production credentials with production. The sandbox refuses production credentials: authenticate succeeds, but every call made with that token answers
403withThis is the Nava Hotels API sandbox. It accepts test accounts only.Production doesn't refuse test credentials, so keep each set next to its base URL, in separate files or secret stores. We recommend a flag such asNAVA_ENV=testthat any test which makes real bookings checks, together with the base URL, before it runs. - If a credential changes, update it in every service that uses it. A deleted or rotated API user makes every call return
401. See Everything returns 401.
# Test account: the sandbox base URL and your test credentials
NAVA_ENV=test
NAVA_BASE_URL=https://sandbox.nava.travel/resources
NAVA_USERNAME=your-test-user
NAVA_PASSWORD=your-test-password
NAVA_MICROSITE_ID=your-test-microsite-id
# Production: a different file or secret store, with your production credentials
# NAVA_ENV=production
# NAVA_BASE_URL=https://nava.travel/resourcesYou exchange either set for a token with POST /authentication/authenticate. See Authentication.
Testing in your test account
Your test microsite only has test suppliers. Plan your tests around these points.
| Behaviour | What to do | |
|---|---|---|
Test suppliers may not behave exactly like real suppliers, for example after Refresh or Cancel. Some answer every Refresh with CANCELED. | Ask your Nava account manager how they respond before a test depends on a particular status. | |
| Any supplier, test suppliers included, can ask for more guest data than you expect, such as a birth date for every guest. | Build the guest form from Confirm's requiredField, never from a fixed template. | |
fakeBooking forces a Book outcome (BOOKED or BOOK_ERROR), but a fake booking is not saved and not sent to suppliers, even in production. | Use it to test your failure path. Test post-booking calls on real bookings in your test account: booking detail answers 404 for a fake booking. | |
| The sample dates in the official documentation are in the past. | Use future dates. A search for past dates returns no hotels. | |
| Several JSON samples in the official documentation have syntax errors. | Don't paste them as test fixtures. The samples on this site are valid JSON. |
Destination codes for your test microsite come from GET /destination/{micrositeId}, called with your test microsite id. The test microsite only has test suppliers, so the same search can return different hotels than it does in production.
What depends on your microsite
Your micrositeId decides more than which account you log in to. The same request can behave differently on two microsites.
| What | How it varies | |
|---|---|---|
| Suppliers | Which providers are connected decides which hotels you can search and book. GET /providers/configurations/{micrositeId} lists them; check it when a destination returns nothing. | |
| Currency | Every price comes in the microsite currency. You cannot request another currency per call, so convert for display yourself. | |
| Hotel catalogue | Which hotels GET /accommodations returns depends on the providers connected to the microsite. Meal plans, preferred hotels and destinations are per microsite too. | |
| Net or commissionable rates | Either is possible, set per microsite and credential. Responses don't say which one you have, so ask your Nava account manager. | |
| Price-change tolerance | The gap allowed between the confirmed price and the supplier's closing price before a booking closes PRICE_ERROR. A percentage or a fixed amount; default 0.5 %. | |
| Webhooks | Each microsite needs its own webhook endpoint, up to 3 per microsite. A microsite without one never notifies you. | |
| Bookings listing | GET /booking/bookings only returns bookings made on the microsite you query. |
Going live
Production credentials come after certification. Before you get them, the request and response of every call you use is reviewed, and you make three bookings in your test account: one room with two adults, two rooms, and adults with children. See Certification.
To go live, switch to your production credentials and the production base URL, https://nava.travel/resources. Paths and request bodies stay the same.
Related
Authentication
Exchange your credentials for a token that lasts two hours, send it in the auth-token header, and use the same token for a whole booking flow.
Requests and responses
The headers every call sends, the auditData block most responses carry, trace ids, token redaction, errors, retries, date formats, timeouts, currency and lenient parsing.