Postman collection
Download a ready-made Postman collection for the whole accommodation flow, from authentication to cancellation, with scripts that chain every call and block bookings outside your test account.
Run every call of the accommodation flow from Postman, without writing code. The collection's scripts do what your integration has to do: they keep one token for the whole flow, forward the newest combinationKey, build the guests Prebook needs from Confirm's requiredField, and save both booking references for the post-booking calls.
Download
- Nava Hotels API collection: the accommodation flow, the catalogue and the post-booking calls, in five folders.
- Test environment: for your test account, on the sandbox base URL.
- Production environment: for your production account, after certification. Book, Cancel and Refresh are blocked here until you unblock them.
The collection is generated from the OpenAPI specification, so its paths and parameters match this documentation.
Set it up
Import. In Postman, choose Import and drop in the collection and the test environment.
Select the environment. Pick Nava Hotels API · Test in the environment menu at the top right.
Add your test credentials. In the environment, fill in username, password and micrositeId from your Nava account manager. password is a secret variable, so Postman masks it. Don't share or export an environment that holds credentials.
Run the flow
Open 3. Booking flow and send Quote, Quote single, Confirm, Prebook and Book in order, then the requests in 4. After booking. Or choose Run collection to run every folder in order: a full run makes one booking in your test account and then cancels it.
| Folder | Requests | What the scripts do |
|---|---|---|
| 1. Authentication | Authenticate | Save the token. Optional: other requests renew a missing or expired token, except Confirm, Prebook and Book. |
| 2. Hotel catalogue | Destinations, Destination, Countries, Meal plans, Accommodation list, Datasheet, Datasheets (batch), Preferred hotels, Accommodation facilities, Room facilities, Provider configurations | Destinations checks that destinationId exists on your microsite. Accommodation list saves hotel codes for the datasheet requests. |
| 3. Booking flow | Quote, Quote single, Confirm, Prebook, Book | Forward the newest combinationKey, build the guests, compare Prebook with Confirm and save the references. |
| 4. After booking | Booking detail, Get booking (whole trip), List bookings, Cancellation fee, Cancel | Read, price and cancel the booking from Book. |
| 5. More examples | Quote by hotel codes, Refresh | Variations to run on their own. |
Open the Postman Console to see the hotel each Quote picked, the guests Prebook sent, and the traceId and x-request-id of every call. Keep those ids for support.
To run it from a terminal or in CI, use Newman, Postman's command-line runner, and pass your credentials from environment variables:
npx newman run nava-hotels-api.postman_collection.json \
-e nava-hotels-test.postman_environment.json \
--env-var "username=$NAVA_USERNAME" \
--env-var "password=$NAVA_PASSWORD" \
--env-var "micrositeId=$NAVA_MICROSITE_ID"What the scripts enforce
- One token per booking flow. Every call from Quote to Book uses the same token. Quote starts a flow only on a token with at least 60 minutes left, and authenticates first if it has less. Confirm, Prebook and Book refuse to run on any other token: run Quote again.
- The newest key. Each step saves the
combinationKeyfrom its response for the next step. - Guests that match the quote. Prebook repeats the rooms, order and ages of the Quote, and each
requestedAgeequals the quoted age. Names are in Latin script. Every guest gets a birth date, the contact person an email and phone, and each guest any other fieldrequiredFieldlists for them. Prebook answers400when a required field is missing. - No silent changes. Prebook's tests fail when the price, meal plan or cancellation policies differ from Confirm, and Confirm's
warnings[]show up as a test result. In your integration, show any change to the guest and get consent again. - Status, not HTTP 200. Book's test checks
status, and the references are saved whatever it is. See Booking statuses. - No automatic retries. Nothing in the collection re-sends Book or Cancel. Book has no idempotency key, so after a timeout, read the booking before you try again.
Bookings are blocked outside your test account
The test environment points at the sandbox and the production environment at production. See Environments. Book, Cancel and Refresh run only when the environment's navaEnv is test and its baseUrl is not the production base URL. The production environment ships with navaEnv set to production and allowBookingWrites set to false. A blocked request is never sent: Postman shows a pre-request script error instead.
To make one of these calls in production on purpose, for example to cancel a booking, set allowBookingWrites to true, send the request, and set it back to false.
Test your failure path
Set the collection variable fakeBookingStatus to BOOK_ERROR and run the booking flow again. Book returns HTTP 200 with that status. A fake booking is not saved and never reaches a supplier, even in production. Booking detail answers 404 for it. Clear the variable afterwards.
Make the certification bookings
Certification asks for three real bookings in your test account. For each one, check that fakeBookingStatus is empty, set distributions in the Quote body, run Quote to Book, and keep the booking: don't run Cancel. Quote single repeats the rooms of the Quote, and Prebook builds guests for them.
| Booking | Quote distributions |
|---|---|
| One room, two adults (the default) | [{ "persons": [{ "age": 30 }, { "age": 30 }] }] |
| Two rooms | [{ "persons": [{ "age": 30 }, { "age": 30 }] }, { "persons": [{ "age": 45 }, { "age": 42 }] }] |
| Adults and children | [{ "persons": [{ "age": 30 }, { "age": 30 }] }, { "persons": [{ "age": 40 }, { "age": 5 }] }] |
See Certification for what the review checks.
Variables you can change
| Collection variable | Default | What it does |
|---|---|---|
language | EN | Language of names and descriptions. |
sourceMarket | AE | The country your customer books from. It can change prices and availability. |
destinationId | MAD | Where Quote searches. Destinations replaces it when your microsite has no such destination. |
checkIn | empty: 42 days from today | Check-in date, yyyy-MM-dd. Use future dates. |
nights | 4 | Length of stay, at most 30 nights. |
fakeBookingStatus | empty | BOOK_ERROR or BOOKED forces that Book outcome. |
The other collection variables are set by the scripts. The environments hold baseUrl (the sandbox in the test environment, production in the production environment), your credentials, navaEnv and allowBookingWrites.
What it doesn't cover
The generic Booking API endpoints (Cancel service, Service cancellation fee, Refund, Client requests) and OTP sign-in are not in the collection. The Booking API endpoints need an API user enabled for that API, so ask your Nava account manager first. To try them, import the OpenAPI specification into Postman.
Keep responses private
- Most responses echo your token in
auditData.authToken. Remove it before you share a response, an exported run or Console output. combinationKeyvalues can contain net prices. In your integration, keep them on your server and give your front end an id of your own.
Related
- Quickstart: the same flow with cURL.
- The booking flow
- Environments and credentials
- Certification
Quickstart
Make your first booking in your test account with cURL and jq. Authenticate, quote Madrid, confirm, prebook two adults, book, then read, price and cancel the booking.
Authentication
Exchange your credentials for a token that lasts two hours, send it in the auth-token header, and use the same token for a whole booking flow.