Room Saint Docs
Skip to documentation content
Browse documentation

Connectors and developers

Account API and tokens

Use personal API tokens for authorized trip, vote, and contribution operations.

Create a personal access token

Sign in and open API Tokens from the account menu. Give the token a descriptive name and select only the permissions your application needs. Copy the token when it is shown and store it securely; do not put it in public URLs, source code, or shared prompts.

Send the token with Authorization: Bearer YOUR_TOKEN and request JSON with Accept: application/json. Public discovery endpoints do not need a token. To connect Claude or ChatGPT normally, use their OAuth sign-in flow instead of manually supplying a token.

Token abilities

  • read: authenticated discovery features, including AI/RAG endpoints and vote status.
  • trips: manage your trips, cities, and saved hotel candidates.
  • vote: cast or remove your community votes.
  • contribute: submit hotel photos, subject to normal permissions and validation.

Account MCP also requires a verified email. Tokens do not grant access to another user's trips or bypass account restrictions.

Account REST routes

Routes below are under /api/v1. They are separate from anonymous discovery:

RoutesPurpose
GET /meRead your account identity and token abilities
GET, POST /trips; GET, PATCH, DELETE /trips/{id}List, create, inspect, update, or delete your trips
POST /trips/{id}/cities; DELETE /trip-cities/{id}Add or remove a city in your trip
POST /trip-cities/{id}/hotels; PATCH, DELETE /trip-saves/{id}Save hotels or update/remove a saved entry
POST /hotels/{id}/vote; DELETE /votes/{id}Manage your own vote
POST /hotels/{id}/photosUpload a photo using multipart form data

Example: list your trips

curl 'https://www.roomsaint.com/api/v1/trips' \
  -H 'Accept: application/json' \
  -H 'Authorization: Bearer YOUR_TOKEN'

Use a token with the trips ability. A 401 response means sign-in is required or the token is invalid. A 403 response indicates insufficient permission. A 422 response identifies fields to correct. Follow rate-limit responses before retrying.

Revoke unused access

Delete a token from API Tokens when its application no longer needs access. This does not remove your trips or favorites. Disconnect OAuth-based assistant connections through the assistant's connection settings.

Still stuck? Check troubleshooting or contact us.