Updated: August 31, 2026
These Developer and API Terms ("Developer Terms") govern access to and use of the Haven public API by an approved third-party developer organization.
These Developer Terms are an agreement between Book With Haven LLC ("Haven," "we," "us," or "our") and the organization that applies for API access and accepts these Developer Terms ("Developer," "you"). They take effect when an administrator of the Developer's organization accepts them, and they remain in effect until terminated under Section 35.
These Developer Terms do not apply to Hosts and do not apply to Guests. Hosts continue to use the Services under the Book With Haven LLC Terms of Service. Guests continue to use the Services under the Terms of Service and the Privacy Policy.
If you do not accept these Developer Terms, do not apply for or use the API.
Haven provides software that lets short-term rental Hosts operate direct booking sites, calendars, guest portals, guidebooks, and payment workflows.
Haven is not a hotel, property manager, broker, travel agency, or insurer. Haven is not a party to any Stay and is not a party to any agreement between a Host and a Guest.
The API is a controlled interface that allows an approved Application to read and write a Host's Haven data after that Host has authorized the Application. Access is never self-serve. Every application for access is reviewed by Haven staff, and every account connection depends on a separate authorization by the Host who controls that account.
"API" means the Haven public API made available at the endpoint Haven designates for approved developer access, together with its authorization endpoints, event delivery, and accompanying documentation.
"Application" means the Developer's software product that Haven has approved to call the API, as described in the Developer's application materials.
"Client" means a registered set of API credentials and redirect destinations that Haven issues to an Application. An Application may have separate Sandbox and production Clients.
"Credentials" means client secrets, authorization codes, access tokens, refresh tokens, signing secrets, and any other secret value Haven issues to the Developer or that the Developer receives through the authorization or event-delivery process.
"Developer" means the organization that accepts these Developer Terms, including its personnel, contractors, and vendors.
"Grant" means a Host's authorization of one Application to access one Haven account, limited to the Scopes the Host approved.
"Guest" has the meaning given in the Terms of Service.
"Haven Data" means information the Developer receives through the API or through event delivery, including Host Content, account and listing information, calendar and rate information, reservation information, Guest information, message content, and derived or inferred information created from any of it.
"Host" has the meaning given in the Terms of Service.
"Personal Data" means information within Haven Data that identifies, relates to, describes, or can reasonably be linked to an identified or identifiable individual, including a Guest or a Host, under applicable privacy law.
"Sandbox" means the non-production environment Haven provides for development and testing against test accounts.
"Scope" means a named permission that authorizes a specific class of read or write access. Scopes are least-privilege and are not wildcards.
"Scope Ceiling" means the maximum set of Scopes Haven staff have approved for an Application. A Grant may include some or all of the Scope Ceiling. A Grant can never exceed it.
"Services" has the meaning given in the Terms of Service.
"Terms of Service" means the Book With Haven LLC Terms of Service that govern Hosts and Guests.
The Terms of Service and the Privacy Policy govern Haven's relationship with Hosts and Guests. These Developer Terms govern Haven's relationship with the Developer. Neither modifies the other.
The agreement between a Host and a Guest for a Stay is unchanged by these Developer Terms and by anything the Developer does through the API.
The Developer's own agreement with a Host is between the Developer and that Host. Haven is not a party to it, does not negotiate it, does not enforce it, and takes on no obligation under it. The Developer must not present Haven as a party to, guarantor of, or participant in that agreement.
Nothing in these Developer Terms makes the Developer an agent, partner, joint venturer, or representative of Haven.
To apply for and hold API access, the Developer must:
Haven may decline an application, or end an existing relationship, for any lawful reason.
Every Application is reviewed by Haven staff before it receives production access. Approval is a judgment about the fit between the Application described in the application materials and the access requested. It is not a certification, audit, inspection, endorsement, security assessment, or guarantee of the Application, the Developer, or the Developer's practices.
The Developer must not state or imply that Haven has certified, audited, vetted, endorsed, secured, or verified the Application or the Developer.
Approval covers the Application as described. If the Application's purpose, data handling, hosting arrangement, ownership, or requested access changes in a material way, the Developer must tell Haven at the partner intake address before making the change, and Haven may re-review.
Haven staff set a Scope Ceiling for each approved Application. The Scope Ceiling reflects what the Application needs to do the job described in its application materials.
The following rules apply to Scopes:
The Developer must request the narrowest set of Scopes its product actually needs, and must not request a Scope in anticipation of a feature that does not exist.
The API does not expose, and a Grant never authorizes, the following:
Damage protection, screening, and claims workflows are governed by their own terms between Haven, the Host, and the relevant provider. They are not made available through the API, and the Developer must not represent otherwise.
The Developer must not attempt to reach any of the excluded functionality above by any means, including through the Host dashboard, an automated browser, a Host's login credentials, or an undocumented endpoint.
Sandbox is for development and testing. The full authorization flow runs in Sandbox, but only against test accounts. Sandbox Credentials never reach a real Host account.
Production access is granted separately after staff review. Only a production Client may connect to real Host accounts.
The Developer must not use production access for development, load testing, performance testing, penetration testing, or automated test suites that generate volume a real deployment would not generate. Testing belongs in Sandbox.
Sandbox is provided without any commitment as to availability, data retention, or fidelity to production behavior.
Subject to these Developer Terms, Haven grants the Developer a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to call the API through an approved Client, for the sole purpose of operating the Application for Hosts who have granted it access.
This license ends automatically on suspension, revocation, or termination.
Haven and its licensors own the API, the documentation, the Services, and all related intellectual property. Nothing in these Developer Terms transfers ownership of any of it.
No license is granted by implication, estoppel, or otherwise. In particular:
The Developer may give Haven feedback about the API. If it does, Haven may use that feedback without restriction, obligation, or payment.
While these Developer Terms are in effect and the Developer holds production access, Haven grants a limited, non-exclusive, non-transferable, revocable right to state factually that the Application works with Haven, using the phrase "Works with Haven" or a plainly factual equivalent, in the Developer's own marketing, documentation, and product interface.
This right is subject to the following limits:
Haven may revoke this right at any time, with or without cause, by notice. The Developer must stop using the phrase and remove it from materials it controls within ten business days of the notice, and immediately on termination.
A Grant is the only lawful basis on which the Developer may access a Host account through the API.
Consent is per account, not per portfolio. One Host, or an agency manager acting on a linked client account, authorizes one Application for one account. Where an agency approves several accounts in a single screen, each account produces its own Grant, and each Grant is independently revocable.
A Grant made by a manager is capped at that manager's permissions in the account. It never includes billing, ownership, or account administration rights the manager does not hold.
The Developer must not:
A Host may revoke a Grant at any time from the connected applications screen in the Host's Haven account. Haven may also end a Grant under Section 27.
Revocation is immediate. Access tokens and refresh tokens issued under that Grant stop working at once, requests presenting them fail, and event delivery for that Grant stops. There is no wind-down period and no grace period.
After revocation the Developer must not attempt to restore access except through a new Host authorization. Repeated authorization prompts intended to pressure a Host into reconnecting are a breach of these Developer Terms.
Revocation triggers the deletion obligations in Section 28.
The Developer may use Haven Data only to provide the Host with the product described in the Developer's application materials, and only for accounts with a live Grant, and only for as long as that Grant remains live.
That is the entire permitted purpose. Any other use requires Haven's prior written approval and, where the Host's data is involved, the Host's own instruction.
The Developer must handle Haven Data under the Host's instruction. Where a Host instructs the Developer to do something with Haven Data that these Developer Terms prohibit, these Developer Terms control as between Haven and the Developer, and the Developer must decline.
The Developer must not:
Haven acts as the Host's service provider or processor for Guest information processed on behalf of that Host in connection with the Host's property, bookings, guest portal, and direct booking site. That role does not change because a Host connects an Application.
When a Host authorizes an Application, the Host instructs Haven to disclose Haven Data to the Developer. The disclosure is made for the Host's business purpose, at the Host's direction.
The Developer receives that data as a service provider, processor, or sub-processor acting for the Host, under the Host's instruction. The exact characterization depends on the arrangement between the Host and the Developer and on the law that applies to that Host.
The Developer is not Haven's vendor, service provider, processor, or sub-processor. The Developer does not process Haven Data for Haven's own purposes, and Haven does not engage the Developer to perform any function on Haven's behalf. The Developer must not describe itself to Hosts, Guests, regulators, or the public as a Haven sub-processor or as processing data on Haven's behalf.
Haven does not sell Haven Data and does not share it for cross-context behavioral advertising. The Developer must not treat a Grant as authorization for advertising, audience building, or any purpose that would be a sale or share under applicable privacy law.
The Developer is an independent business, controller, or third party with respect to its own records, including its billing of the Host, its own account and support records, and its own security and audit logs.
The Developer is responsible for entering into whatever data protection terms applicable law and the Host require, directly with the Host. Haven is not a party to those terms and does not supply them.
The Developer must publish and maintain a privacy policy that accurately describes how it collects, uses, discloses, secures, and retains Host and Guest information, including information it receives through the API.
A Host's authorization of an Application is consent to the disclosure described on the Haven authorization screen. It is not consent to any other processing by the Developer. The Developer must obtain any consent or provide any notice its own processing requires.
The Developer must:
The Developer may use vendors to help operate the Application, including hosting, storage, monitoring, and support providers.
The Developer remains fully responsible for its vendors' acts and omissions with respect to Haven Data, as if they were the Developer's own.
Before giving a vendor access to Haven Data, the Developer must bind that vendor in writing to obligations at least as protective as Sections 14, 15, 18, 19, 20, 21, 25, 26, and 28. The Developer must not use a vendor that processes Haven Data for the vendor's own purposes.
On Haven's written request, the Developer will identify the vendors that process Haven Data and the countries in which they process it.
The Developer may store and process Haven Data outside the country where it was collected only if a lawful transfer mechanism is in place with the Host.
Establishing that mechanism is the Developer's responsibility, together with the Host. Haven does not supply it, is not a party to it, and makes no representation that any particular transfer is lawful.
The Developer must tell Haven, on request, where Haven Data is stored and processed.
The Developer must protect Haven Data with administrative, technical, and organizational measures that are reasonable and appropriate to the sensitivity of the data and consistent with recognized industry practice. At minimum, the Developer must:
Credentials are secrets. They identify the Developer and, together with a Grant, unlock a Host's data.
The Developer must:
Where Haven delivers events to an endpoint the Developer registers, the Developer must:
An endpoint that is unreachable, that fails signature verification repeatedly, or that leaks payload contents may result in suspension under Section 27.
The API enforces rate limits. Requests that exceed a limit fail rather than queue. The Developer must handle those failures gracefully, back off, and must not retry in a way that amplifies load.
Write operations require an idempotency key. The Developer must generate a distinct key for each distinct operation, must reuse the same key only when retrying that same operation, and must never reuse a key across different operations.
The Developer must not:
The Developer must not use the API or Haven Data to:
Each party may receive non-public information from the other. The Developer's confidential information includes its application materials. Haven's confidential information includes Credentials, non-public API documentation, pre-release features, security information, and the terms of any non-standard arrangement between the parties.
The receiving party must protect that information with at least reasonable care, use it only for the purposes of these Developer Terms, and disclose it only to personnel and vendors who need it and who are bound to protect it.
These obligations do not apply to information that is or becomes public without breach, that the receiving party already had without a duty of confidence, that it develops independently, or that it lawfully receives from a third party. Disclosure required by law is permitted if the receiving party gives reasonable advance notice where it lawfully can.
These obligations continue for three years after termination, and continue for as long as the information remains confidential in the case of Credentials, security information, and Personal Data.
The Developer must notify Haven without undue delay, and in any event within seventy-two hours of becoming aware, of:
Where the incident involves Credentials, or where a Grant, Client, or token may have been compromised, the Developer must notify Haven within twenty-four hours of becoming aware, because Haven needs that time to revoke.
Notice must go to hello@bookwithhaven.com and to the security contact channel Haven identifies to the Developer, and must be sent from or copy the security contact address on the Developer's organization record. Notice must include, to the extent known: what happened, when it happened and when the Developer learned of it, the Hosts and categories of information affected, the number of individuals affected, what the Developer has done to contain it, what it will do to remediate it, and a named contact.
The Developer must:
The Developer must not notify Hosts, Guests, regulators, or the public in Haven's name, on Haven's behalf, using Haven's marks, or in terms that describe the Developer's incident as a Haven incident. The Developer remains responsible for its own notification obligations to Hosts and, where applicable, to Guests and regulators, and should coordinate the timing and content of Host notice with Haven where practical.
Haven may suspend or revoke, immediately and without prior notice, any of the following: a single Grant, a Client, an Application, or the Developer's entire organization.
Haven may do so for any of the following reasons:
Suspension takes effect at once. Tokens issued to the suspended Grant, Client, or organization stop working immediately, requests presenting them fail, in-flight and queued operations are not completed, and event delivery stops.
Haven will notify the Developer at its security contact address, and will describe the reason at the level of detail Haven can safely share. Haven may restore access when the underlying cause is resolved to Haven's satisfaction, and is not obligated to do so.
Haven may also narrow an Application's Scope Ceiling at any time. Narrowing takes effect immediately for all Grants. Widening requires a new Host authorization for each affected account.
A Host's revocation under Section 13 operates independently of this section and does not require Haven's involvement.
On any of the following, the Developer must stop processing the affected Haven Data:
The Developer must delete or irreversibly de-identify all affected Haven Data, including derived and inferred copies, within thirty days, or sooner if the Host instructs or applicable law requires.
Backup copies must be purged on the next scheduled backup cycle, and in any event within ninety days. Until they are purged, backup copies remain subject to Sections 14, 15, 20, and 25, and must not be restored into active use.
The Developer may retain:
On Haven's written request, the Developer will certify in writing, signed by an officer, that it has met the obligations in this section. The Developer will provide that certification within ten business days.
Haven does not charge a fee for API access as of the effective date of these Developer Terms.
Haven may introduce fees for API access, for particular Scopes, or for usage above a stated level, on at least thirty days' notice to the Developer's contact addresses. Continued use of the API after a fee takes effect is acceptance of that fee. A Developer that does not accept a new fee may terminate under Section 35 before it takes effect.
Haven may add, change, deprecate, or remove endpoints, fields, Scopes, events, limits, and behavior.
Haven will give reasonable advance notice of a change it expects to break existing integrations, where doing so is practical. Haven may make a change immediately, without notice, where security, legal obligation, abuse, or platform stability requires it.
The Developer is responsible for keeping the Application working against the current API. Haven does not commit to maintaining any prior behavior, version, or field.
Haven makes no commitment about uptime, latency, throughput, error rates, or support response, and provides no service levels for the API.
Each published version of these Developer Terms carries a version identifier that is an ISO date. An administrator of the Developer's organization accepts a specific version, and Haven records that version against the organization.
Haven may publish a new current version. Haven will give notice to the Developer's contact addresses.
For a change that materially affects data use, security obligations, deletion obligations, fees, or liability, Haven will require an administrator of the Developer's organization to accept the new version before the Developer's API access continues. For any other change, continued use of the API after the new version's effective date is acceptance.
If the Developer does not accept a version that Haven requires, the Developer's API access ends, all Grants end, and Section 28 applies.
The API, the Sandbox, the documentation, and any related materials are provided "as is" and "as available."
To the fullest extent permitted by law, Haven disclaims all warranties, express, implied, and statutory, including warranties of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, and any warranty arising from course of dealing or usage of trade.
Haven does not warrant that the API will be uninterrupted, timely, secure, or error-free, that defects will be corrected, or that any particular endpoint, field, Scope, or behavior will remain available.
Haven Data originates with Hosts, Guests, and connected systems. It may be incomplete, inaccurate, stale, duplicated, out of sequence, or entered incorrectly. Haven does not verify it and does not warrant it. The Developer is responsible for validating anything it relies on, and for the consequences of acting on Haven Data.
Haven is not a party to any Stay and warrants nothing about any booking, cancellation, payment, refund, payout, tax outcome, or Guest or Host conduct.
Staff review of an application is not a certification, audit, or endorsement, and Haven disclaims any warranty arising from it.
To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost goodwill, lost business, or loss of data, arising out of or relating to these Developer Terms, however caused and on any theory of liability, even if the party was advised of the possibility.
To the fullest extent permitted by law, Haven's total aggregate liability arising out of or relating to these Developer Terms and the API will not exceed the greater of one thousand United States dollars and the total amount the Developer paid Haven under these Developer Terms in the twelve months before the event giving rise to the claim.
The limitations in this section do not apply to:
These limitations apply even if a limited remedy fails of its essential purpose, and they reflect an agreed allocation of risk between two businesses in exchange for access provided without charge.
The Developer will defend, indemnify, and hold harmless Haven and its members, managers, officers, employees, contractors, and agents from and against any claim, demand, investigation, proceeding, loss, damage, liability, penalty, fine, settlement, and reasonable attorneys' fees and costs arising out of or relating to:
Haven will notify the Developer of a claim within a reasonable period, and the Developer will control the defense with counsel reasonably acceptable to Haven. The Developer may not settle a claim in a way that imposes an obligation on Haven, admits Haven's liability or wrongdoing, or affects Haven's rights, without Haven's prior written consent. Haven may participate in the defense with its own counsel at its own expense.
These Developer Terms begin when an administrator of the Developer's organization accepts them and continue until terminated.
The Developer may terminate at any time by ceasing all use of the API, deleting its Credentials, and meeting Section 28.
Haven may terminate for convenience on thirty days' notice, and may terminate immediately for any reason listed in Section 27.
On termination, the license in Section 9 and the right in Section 11 end, all Grants end, all Credentials stop working, and Section 28 applies. Termination does not relieve either party of an obligation that accrued before it.
Sections 2, 3, 10, 14, 15, 16, 17, 18, 19, 25, 26, 28, 29, 32, 33, 34, 36, 37, 38, 39, and 40 survive termination, along with any other provision that by its nature should survive.
Haven will give notice to the Developer at the security contact address and the support contact address on the Developer's organization record, or through the developer console. The Developer must keep those addresses accurate and monitored. Notice is effective when sent.
The Developer will give notice to Haven as follows:
Postal notice to Haven may be sent to Book With Haven LLC, 34 Thurston Point Rd, Gloucester, MA 01930, but does not replace the email notice required by Section 26.
The Developer may not assign or transfer these Developer Terms, or any right or obligation under them, without Haven's prior written consent. A merger, acquisition, reorganization, or sale of all or substantially all of the Developer's assets or equity is a transfer for this purpose.
The Developer must notify Haven at the partner intake address before a change of control takes effect, or as soon as it is legally able to do so. Haven may re-review the Application, narrow the Scope Ceiling, or terminate under Section 35 following a change of control.
Haven may assign these Developer Terms without restriction.
Delaware law governs these Developer Terms and any dispute arising out of or relating to them, without regard to conflict of law rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
The state and federal courts located in New Castle County, Delaware have exclusive jurisdiction over any dispute arising out of or relating to these Developer Terms. Each party consents to personal jurisdiction and venue in those courts and waives any objection based on inconvenient forum.
The arbitration provision and class-action waiver in the Terms of Service do not apply to these Developer Terms and do not govern any dispute between Haven and the Developer.
Each party waives any right to a trial by jury.
Each party waives any right to bring or participate in a class, collective, consolidated, or representative action against the other.
Either party may seek injunctive or other equitable relief in any court of competent jurisdiction to protect Haven Data, Credentials, confidential information, or intellectual property, without the need to post a bond and without waiving this section.
Independent parties. The parties are independent contractors. These Developer Terms create no partnership, joint venture, agency, franchise, fiduciary, or employment relationship.
No third-party beneficiaries. These Developer Terms are for the benefit of Haven and the Developer only. No Host, Guest, or other person is a third-party beneficiary or has a right to enforce them.
Entire agreement and precedence. These Developer Terms, together with the API documentation and the Developer's approved application materials, are the entire agreement between Haven and the Developer about the API, and replace any prior understanding on that subject. If a separate written agreement signed by both parties conflicts with these Developer Terms, that agreement controls for the conflicting provision only. If the documentation conflicts with these Developer Terms, these Developer Terms control.
Events beyond reasonable control. Neither party is liable for a failure or delay caused by an event beyond its reasonable control, other than an obligation to pay.
Severability. If a provision is held unenforceable, it is modified to the minimum extent needed to make it enforceable, or severed if it cannot be, and the rest remains in effect.
No waiver. A failure to enforce a provision is not a waiver of it.
Compliance with trade law. The Developer represents that it is not located in, organized under the laws of, or ordinarily resident in a jurisdiction subject to comprehensive sanctions, and that it is not a party with whom United States persons are prohibited from dealing.
Headings. Headings are for convenience and do not affect interpretation.
Electronic acceptance. Clicking the acceptance control constitutes the Developer's electronic signature. Haven may store the acceptance date, time, version, accepting administrator, and related audit information.
For questions about these Developer Terms, contact hello@bookwithhaven.com.
For applications, Scope requests, and partner matters, contact api@bookwithhaven.com.
Book With Haven LLC 34 Thurston Point Rd Gloucester, MA 01930
Version 2026-08-31
© 2026 Book With Haven, LLC.