Connectors and developers
Account API and tokens
Use personal API tokens for authorized trip, vote, and contribution operations.
Create a personal access token
Sign in and open API Tokens from the account menu. Give the token a descriptive name and select only the permissions your application needs. Copy the token when it is shown and store it securely; do not put it in public URLs, source code, or shared prompts.
Send the token with Authorization: Bearer YOUR_TOKEN and request JSON with Accept: application/json. Public discovery endpoints do not need a token. To connect Claude or ChatGPT normally, use their OAuth sign-in flow instead of manually supplying a token.
Token abilities
read: authenticated discovery features, including AI/RAG endpoints and vote status.trips: manage your trips, cities, and saved hotel candidates.vote: cast or remove your community votes.contribute: submit hotel photos, subject to normal permissions and validation.
Account MCP also requires a verified email. Tokens do not grant access to another user's trips or bypass account restrictions.
Account REST routes
Routes below are under /api/v1. They are separate from anonymous discovery:
| Routes | Purpose |
|---|---|
GET /me | Read your account identity and token abilities |
GET, POST /trips; GET, PATCH, DELETE /trips/{id} | List, create, inspect, update, or delete your trips |
POST /trips/{id}/cities; DELETE /trip-cities/{id} | Add or remove a city in your trip |
POST /trip-cities/{id}/hotels; PATCH, DELETE /trip-saves/{id} | Save hotels or update/remove a saved entry |
POST /hotels/{id}/vote; DELETE /votes/{id} | Manage your own vote |
POST /hotels/{id}/photos | Upload a photo using multipart form data |
Example: list your trips
curl 'https://www.roomsaint.com/api/v1/trips' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer YOUR_TOKEN'
Use a token with the trips ability. A 401 response means sign-in is required or the token is invalid. A 403 response indicates insufficient permission. A 422 response identifies fields to correct. Follow rate-limit responses before retrying.
Revoke unused access
Delete a token from API Tokens when its application no longer needs access. This does not remove your trips or favorites. Disconnect OAuth-based assistant connections through the assistant's connection settings.