Stayntouch · PMS Power Index
Composite score: 54.3 / 100 (published snapshot v2026.2, 2026-08-13)
Stayntouch scores 54.3 out of 100 on the PMS Power Index. Evidence-backed diagnostic across ten API capabilities. Vendor-neutral. Open to dispute.
Scores by capability
Marketplace coverage
Score: 6 of 9 (Adequate). Weight 10%.
Reconciliation note: Primary (7) and secondary (7) agree (MAD 0). Reconciled to 7. Anchor evidence: Public /integrations directory listing named partners (IDeaS, Duetto, SiteMinder, SHR, Sabre, Cendyn, Oracle MICROS Simphony, Toast, Salto, Dormakaba, etc.) plus Connect API v2 surface. Primary rationale: Broad partner directory across all hotel categories plus credible API surface; '1400+' marketing claim discounted. Comparable to mid-tier published vendors. Secondary rationale: Independent review reaches the same band: named partners span RMS, channel, payments, POS, locks, spa, F&B, guest-experience — clearly broad, but no machine-readable partner registry to verify counts. [0/3/6/9 rescale: primary 7→6, secondary 7→6, MAD 0 band(s), reconciled 6 — concurrent bands.]
First scorer rationale: Broad partner directory across all hotel categories plus credible API surface; '1400+' marketing claim discounted. Comparable to mid-tier published vendors.
Second scorer rationale: Independent review reaches the same band: named partners span RMS, channel, payments, POS, locks, spa, F&B, guest-experience — clearly broad, but no machine-readable partner registry to verify counts.
- Connect API v2 exposes 19 resource panels including accounts, addons, bills, cancellation_policies, charge_codes, deposit_policies, groups, guests, hotels, hourly_reservations, inventories, memberships, oauth, posting_accounts, rates, reservations, restrictions, room_types and rooms, with ~120 GET/POST/PUT/DELETE endpoints. http://api-specs.stayntouch.com/v2/index.html
- Stayntouch's Integration Hub markets '1400+ PMS integrations' available to PMS customers. https://www.stayntouch.com/integrations/
- Public integrations directory at /integrations lists named partners across categories (RMS, channel, distribution, payments, locks, F&B, etc.) including IDeaS, Duetto, Flyr, SiteMinder, SHR, Sabre, Cendyn, Oracle MICROS Simphony, Toast, Salto, Dormakaba, Lightspeed, Sojern, Monscierge, Duve, Book4Time, GuestTouch, Revbell, Way and Ampliphi. https://www.stayntouch.com/integrations/see-complete-integrations-list
What you can control via the API
Score: 6 of 9 (Adequate). Weight 14%.
Reconciliation note: Primary (7) and secondary (6) diverge by one band. Reconciled to 6. Disagreement driver: the write surface is genuinely solid for front-office and posting (reservations CRUD, check-in/out, posting accounts with semantic types, rate management, inventory sell-limits) but the public specification documents no bulk operations, no transactional or idempotency keys, and no async job model. Anchor evidence: Connect API v2 write surface covering reservations CRUD, check-in/out, posting accounts with HOUSE/GROUP/INTERFACE/PASSERBY types, rate management and inventory sell-limits. The absence of bulk/async/idempotency primitives caps the score at 6. [0/3/6/9 rescale: primary 7→6, secondary 6→6, MAD 0 band(s), reconciled 6 — concurrent bands.]
First scorer rationale: Write surface covers reservations CRUD, check-in/out, cancellation, posting accounts with HOUSE/GROUP/INTERFACE/PASSERBY semantics, rate management and inventory sell-limits.
Second scorer rationale: Independent review: write surface is solid for front-office and posting but no public bulk operations, no transactional/idempotency keys documented, no async job model — lands a notch lower.
- Connect API v2 supports write operations across the core operational surface: POST /reservations, POST /reservations/{id}/cancel, POST /reservations/{id}/check_in, POST /reservations/{id}/check_out, POST /accounts, POST /guests, POST /groups, POST /rates, POST /posting_accounts/{id}/transactions, POST /inventories/sell_limits, POST /hourly_reservations and PUT/DELETE counterparts. http://api-specs.stayntouch.com/v2/index.html
- Posting accounts API distinguishes HOUSE, GROUP, INTERFACE and PASSERBY account types and supports POST /posting_accounts/{id}/transactions and POST /posting_accounts/{id}/payment_methods, enabling programmatic charge posting from third-party systems. http://api-specs.stayntouch.com/v2/index.html
- Rate management endpoints support POST /rates, POST /rates/{id}/date_ranges and POST /rates/{id}/sets, plus DELETE /restrictions/* across house, rate, rate_type, room_rate and room_type scopes. http://api-specs.stayntouch.com/v2/index.html
Real-time updates and webhooks
Score: 6 of 9 (Adequate). Weight 13%.
Reconciliation note: Primary (6) and secondary (6) agree (MAD 0). Reconciled to 6. Anchor evidence: Developers page documenting nine event families covering ~24 named events, JSON-over-HTTPS delivery, HMAC-SHA256 signatures added November 2025. Primary rationale: ~24 documented events across 9 families, JSON-over-HTTPS, HMAC-SHA256 added Nov 2025. No public retry/DLQ/ordering docs caps the score. Secondary rationale: Independent review: event coverage is genuine and recently hardened (HMAC), but absence of delivery guarantees, replay endpoint or subscription self-service keeps it at adequate. [0/3/6/9 rescale: primary 6→6, secondary 6→6, MAD 0 band(s), reconciled 6 — concurrent bands.]
First scorer rationale: ~24 documented events across 9 families, JSON-over-HTTPS, HMAC-SHA256 added Nov 2025. No public retry/DLQ/ordering docs caps the score.
Second scorer rationale: Independent review: event coverage is genuine and recently hardened (HMAC), but absence of delivery guarantees, replay endpoint or subscription self-service keeps it at adequate.
- Stayntouch publishes a webhook product distinct from the REST API. The developer page documents nine event families (Account, EndOfDay, Group, Guest, Inventory, Reservation, ReservationRevenue, RoomStatus, RoomStatusService) covering approximately 24 named events including create_reservation, edit_reservation, cancel_reservation, checkin_completed, checkedout, room_assignment_succeed, room_move, anonymize_guest, complete_end_of_day, update_inventory, room_status and room_status_service. https://www.stayntouch.com/developers/
- Webhook changelog shows continuous additions from 2022 to 2026, including New Webhook: Restrictions (Sep 2022), New Webhook: Direct Bill (Sep 2022), New Webhook: Reverse Check-In (Aug 2022), New Webhook: Rates (May 2022), and 2024–2026 enrichments adding room_id, room_number, is_vip, opted_promotional_emails, chain_id, membership_code and demographic_codes to existing payloads. https://www.stayntouch.com/product-updates/webhooks
- Webhook delivery uses POST over HTTPS with a JSON envelope containing event, hotel_id, action and object fields; example payload published on the developers page for create_reservation. https://www.stayntouch.com/developers/
- No public documentation of retry policy, dead-letter queue, backoff schedule, ordering guarantees or delivery SLA was found on developers, product-updates or status pages. https://www.stayntouch.com/developers/
Readiness for AI agents
Score: 3 of 9 (Limited). Weight 12%.
Reconciliation note: Reconciled score 3. AI Readiness is scored and is included in the composite calculation on the same basis as every other dimension. Assessed against the stored anchors, the anchor-0 conditions are not established and two are contradicted by evidence held on this vendor's own record. Anchor 0 requires no structured API and no public schema. Connect API v2 is evidenced as exposing approximately 120 endpoints across 19 resource panels with OAuth 2.0 and a complete per-endpoint HTML reference. The two rows linked to this dimension establish the absence of an MCP server, an agent-callable tool service, semantic search, embeddings and LLM-friendly documentation. Those are anchor-9 criteria, not anchor-0 conditions. Anchor 3 is met: a REST API exists and is documented, and there is no structured tool schema and no agent-facing primitive. Webhook capability is separately evidenced on this record, which the anchor-3 text does not contemplate; that is recorded rather than treated as lifting the score, since anchor 6 requires a published machine-readable specification, which is not evidenced. [Note — 2026-08-13] The earlier characterisation of the stored value as a sentinel used to satisfy a schema constraint, and the statement that this dimension was excluded from the composite, are withdrawn in full. Both were incorrect. The operative score is 3. [Secondary scorer note — 2026-08-12] No secondary scorer row exists for this dimension in pmsapi_scores. The stored score_secondary value is not derived from a scorer row and is recorded here as such rather than carried forward as a scored value.
First scorer rationale: Assessed at anchor 3. Connect API v2 is a documented REST API with OAuth 2.0 and a complete per-endpoint reference, so the anchor-0 conditions are not met. The observations that follow are anchor-9 criteria and are recorded as absent, not as anchor-0 conditions: no MCP server, agent-callable tool surface, semantic search, embeddings endpoint, or LLM-friendly documentation found across Stayntouch's developer properties. The Stayntouch 2.0 product page contains no AI, agent, copilot, or machine learning positioning. [Anchor correction — 2026-08-12] AI Readiness moves from 0 to 3. Anchor 3 is met: a REST API exists and is documented, and there is no structured tool schema and no agent-facing primitive. Anchor 6 requires a published machine-readable specification, which is not evidenced. [Note — 2026-08-13] The sentinel-value characterisation and the statement that this dimension was excluded from the composite are withdrawn in full. The operative score is 3.
- No Model Context Protocol (MCP) server, agent-callable tool surface, semantic search endpoint, embeddings endpoint or LLM-friendly machine-readable docs (llms.txt, raw .md endpoints) were found across api-specs.stayntouch.com, www.stayntouch.com/developers, /stayntouch-2 or product update history. http://api-specs.stayntouch.com/v2/index.html
- Stayntouch 2.0 product page contains no AI, agent, copilot, machine learning or LLM positioning. https://www.stayntouch.com/stayntouch-2/
- Stayntouch publishes a documented REST API. Connect API v2 exposes 19 resource panels with approximately 120 GET, POST, PUT and DELETE endpoints, authenticated by OAuth 2.0, with a complete per-endpoint HTML reference documenting status codes and response bodies. No machine-readable specification is published. Webhook capability is separately documented. https://api-specs.stayntouch.com/v2/index.html
Data model and multi-property design
Score: 6 of 9 (Adequate). Weight 10%.
Reconciliation note: Reconciled score 6. Primary and secondary agree (MAD 0) on the 0/3/6/9 scale. Anchor evidence: Connect API v2 reservations resource with 10 sub-resources and hotels resource with 19 lookup sub-resources, including hourly_reservations as a first-class type. Primary rationale: 19 hotel sub-resources, 10 reservation sub-resources, hourly_reservations as first-class, guest memberships/likes, posting accounts with semantic types. Strong relational coverage. Secondary rationale: independent review reaches the same band: coverage is wide and operationally complete, but no documented multi-property or chain-level analytics and no first-class group-block hierarchy beyond /groups. [Note — 2026-08-13] Earlier notes on this dimension stated both 7 and 6. The single operative figure is 6; the 7 was a pre-rescale value and is withdrawn.
First scorer rationale: 19 hotel sub-resources, 10 reservation sub-resources, hourly_reservations as first-class, guest memberships/likes, posting accounts with semantic types. Strong relational coverage.
Second scorer rationale: Independent review reaches same band: coverage is wide and operationally complete, but no documented multi-property/chain-level analytics, no first-class group-block hierarchy beyond /groups.
- Reservations resource exposes deep sub-resources including bills, deposits, external_references, notes, pay_link, queue_details, revenue, room_key, selected_payment_method and upsell_room_type_options, plus state-change operations cancel, check_in, check_out, cancel_letter, confirm_letter and restrict_post. http://api-specs.stayntouch.com/v2/index.html
- Hotels resource exposes 19 lookup sub-resources for configuration including availability, hourly_availability, cancellation_policies, deposit_policies, charge_codes, charge_groups, credit_card_types, departments, genders, group_hold_status, languages, likes, markets, memberships, origins, payment_types, purpose_of_stay, queue_details, rate_types, rates, room_types, rooms, segments and sources. http://api-specs.stayntouch.com/v2/index.html
- Hourly_reservations resource exists as a first-class entity alongside reservations, supporting day-use and time-slot operations distinct from overnight stays. http://api-specs.stayntouch.com/v2/index.html
- Guests resource includes /guests/{id}/memberships and /guests/{id}/likes sub-resources with DELETE support for memberships, indicating first-class loyalty and preference modelling. http://api-specs.stayntouch.com/v2/index.html
Developer tooling and sandbox
Score: 3 of 9 (Limited). Weight 10%.
Reconciliation note: Primary (4) and secondary (5) diverge by one band. Reconciled to 5. Key scoring driver: sandbox access requires a signed NDA before any credentials are issued, materially raising onboarding friction. This is the defining differentiator versus peer published vendors — Apaleo offers self-serve developer signup with immediate sandbox credentials, and Cloudbeds offers low-friction partner-portal access without NDA gating. Stayntouch's reference quality and no-fee partner support model offset the absence of SDKs, Postman collection and downloadable OpenAPI, but the NDA gate prevents a score above 5 on this dimension. [0/3/6/9 rescale: primary 4→3, secondary 5→3, MAD 0 band(s), reconciled 3 — concurrent bands.]
First scorer rationale: Single-page reference is functional but NDA-gated sandbox, no SDKs, no Postman, no OpenAPI download, no self-serve onboarding. 'Free certification' is a service motion not a DX surface.
Second scorer rationale: Independent review: same reference quality, but the explicit no-fee partner support model and consistent versioning header offset some absence of SDKs — adequate-minus.
- Connect API documentation is published at api-specs.stayntouch.com/v2 as a single HTML reference covering OAuth 2.0 and all 19 resources; no separate developer portal at developer.stayntouch.com or docs.stayntouch.com resolves a public landing page. http://api-specs.stayntouch.com/v2/index.html
- OAuth 2.0 supports authorization_code, client_credentials and refresh_token grant types and exposes /oauth/authorize, /oauth/token and /oauth/revoke endpoints, with state parameter recommended for CSRF protection. http://api-specs.stayntouch.com/v2/index.html
- API spec mandates an API-Version header on every request (current value 2.0) and returns 'Bad or expired token, Unsupported version' on 401 — providing a versioning contract but no public SDKs, no public Postman/OpenAPI download link, and no self-serve sandbox were found. http://api-specs.stayntouch.com/v2/index.html
- Sandbox access is gated: 'All 3rd party vendors need to sign NDA with Stayntouch before getting access to sandbox environment.' http://api-specs.stayntouch.com/v2/index.html
- Stayntouch markets 'Free, swift API certification. Schedule consultations within a week. No charges for connections or assistance' and 'no additional fees for proprietary connections' on the developers landing page. https://www.stayntouch.com/developers/
Uptime and operational discipline
Score: 6 of 9 (Adequate). Weight 9%.
Reconciliation note: Primary (7) and secondary (7) agree (MAD 0). Reconciled to 7. Anchor evidence: Public Statuspage at status.stayntouch.com showing 100% 90-day uptime, component-level breakdown and browsable incident history. Primary rationale: Public Statuspage, 100% 90-day uptime, component-level breakdown, RSS/Atom feeds, browsable incident history. Strong transparency. Secondary rationale: Independent review reaches same band: transparency is genuine; absence of SLA/RTO/RPO publication caps it below best-in-class. [0/3/6/9 rescale: primary 7→6, secondary 7→6, MAD 0 band(s), reconciled 6 — concurrent bands.]
First scorer rationale: Public Statuspage, 100% 90-day uptime, component-level breakdown, RSS/Atom feeds, browsable incident history. Strong transparency.
Second scorer rationale: Independent review reaches same band: transparency is genuine; absence of SLA/RTO/RPO publication caps it below best-in-class.
- Public Statuspage at status.stayntouch.com reports 'All Systems Operational' with 100.0% 90-day uptime for Stayntouch PMS, Stayntouch Guest Mobility and Stayntouch Guest Kiosk components. https://status.stayntouch.com
- Statuspage incident history is publicly browsable by month with separate uptime, incidents and Atom/RSS feeds (history.atom, history.rss); March–May 2026 page shows no major incidents recorded. https://status.stayntouch.com/history
- No published SLA, RTO/RPO target, multi-region/active-active topology, or DR posture was found on public Stayntouch surfaces. https://www.stayntouch.com/
Security, authentication, and compliance
Score: 3 of 9 (Limited). Weight 8%.
Reconciliation note: Primary (5) and secondary (6) diverge by one band. Reconciled to 5. Disagreement driver: OAuth 2.0, HTTPS-only, HMAC-SHA256 webhook signatures and a GDPR/CCPA-aligned privacy policy establish a baseline-plus posture, but the absence of a public trust centre, SOC 2 / ISO 27001 attestation or subprocessor list prevents a score above 5. Both /security/ and /trust/ returned 404 at review time. Anchor evidence: OAuth 2.0 enforced across the API, HTTPS-only for OAuth and webhook delivery, HMAC-SHA256 webhook signatures (Nov 2025), GDPR/CCPA-aligned privacy policy; no public SOC 2/ISO 27001 attestation or trust centre. [0/3/6/9 rescale: primary 5→3, secondary 6→6, MAD 1 band(s), reconciled 3 — divergent bands resolved to lower band per published methodology.] [Additional clarification note — 2026-08-05] "Stayntouch remains at its baseline score of 3. Subsequent to the 25 May review, certification evidence was captured on a different public surface (the Stayntouch resource library, /resources/, evidence row dated 2026-07-07): ISO 27001 and SOC 2 Type 2. This does not change the score, because the GDPR DPA requirement for the anchor-6 threshold remains unverified. The baseline rationale above is retained unchanged; this note records the current evidence position only." [Evidence update — 2026-08-13] ISO/IEC 27001 and SOC 2 Type 2 are evidenced on the Stayntouch resource library (evidence dated 2026-07-07). The earlier statement that no public attestation exists is superseded on both scorer rows. Under the conjunctive anchor-6 gate, certification and OAuth 2.0 with scoped permissions are evidenced; the GDPR Data Processing Addendum is the sole outstanding leg.
First scorer rationale: OAuth 2.0 enforced everywhere, HTTPS-only OAuth and webhooks, HMAC-SHA256 webhook signatures (Nov 2025), GDPR/CCPA-aligned privacy policy. But no public SOC 2/ISO 27001/PCI attestation, no trust centre, no subprocessor list. [Evidence update — 2026-08-13] Certification evidence has since been located on the Stayntouch resource library (evidence dated 2026-07-07): ISO/IEC 27001 and SOC 2 Type 2. The statement above that no public SOC 2 or ISO 27001 attestation exists is superseded. The anchor-6 gate is conjunctive. Certification is now evidenced and OAuth 2.0 with scoped permissions is evidenced; the GDPR Data Processing Addendum is the sole outstanding leg. The score is unchanged pending that evidence.
Second scorer rationale: Independent review: same evidence, but HMAC and HTTPS-only across the surface plus a GDPR-aligned policy under a US Inc data controller is enough for a baseline-plus score; missing trust centre keeps it sub-7. [Audit-trail annotation — 2026-08-08] "One evidence reference held on this scorer row, 73ee91d1-3e1e-4d13-8e4e-af2ddfc0a0a2, had no matching row in the evidence ledger and was unresolvable. The dangling reference has been removed. The original rationale above is retained unchanged, no evidence content was altered and no score has been changed." [Evidence update — 2026-08-13] Certification evidence has since been located on the Stayntouch resource library (evidence dated 2026-07-07): ISO/IEC 27001 and SOC 2 Type 2. The statement above that no public SOC 2 or ISO 27001 attestation exists is superseded. The anchor-6 gate is conjunctive. Certification is now evidenced and OAuth 2.0 with scoped permissions is evidenced; the GDPR Data Processing Addendum is the sole outstanding leg. The score is unchanged pending that evidence.
- Connect API endpoints are secured by oauth_2_0 on every resource (per security clause on each operation), require HTTPS Authorization Bearer tokens, and the OAuth flow requires an HTTPS redirect_uri. http://api-specs.stayntouch.com/v2/index.html
- As of November 2025, Stayntouch webhooks include an HMAC-SHA256 signature in the request header, generated at chain level using a secret key; verification is optional and existing integrations continue to receive payloads without interruption. All webhook transmissions occur over HTTPS. https://www.stayntouch.com/product-updates/2025-november-webhook-update-hmac-sha256-signature-authentication/
- Privacy policy names Stayntouch Inc (Bethesda, MD) as Data Controller for GDPR purposes and documents lawful bases, data subject rights, CCPA equivalence and GDPR data protection rights exercise. GDPR compliance badges are displayed in the footer. https://www.stayntouch.com/privacy/
- Stayntouch blog post on hotel payments describing PCI DSS compliance, tokenisation, and integration security posture. Same domain, same certification claims as the retired /security/ page. https://www.stayntouch.com/blog/3-ways-to-simplify-payments-for-your-hotel/
- Stayntouch resource library confirming security posture: PCI DSS compliant, GDPR compliant, ISO 27001 and SOC 2 Type 2 certifications on Stayntouch's own domain. https://www.stayntouch.com/resources/
Partner programme and references
Score: 6 of 9 (Adequate). Weight 7%.
Reconciliation note: Primary (6) and secondary (6) agree (MAD 0). Reconciled to 6. Anchor evidence: Named Ambassador Program, partner wiki, public Statuspage, Freshdesk support portal and broad named-partner directory. Primary rationale: Named Ambassador Program, partner wiki, public Statuspage, Freshdesk support, broad named-partner directory. '1400+' claim discounted. Secondary rationale: Independent review reaches same band: programme structure is real; absence of public marketplace listing with verifiable certification dates per partner keeps it adequate. [0/3/6/9 rescale: primary 6→6, secondary 6→6, MAD 0 band(s), reconciled 6 — concurrent bands.]
First scorer rationale: Named Ambassador Program, partner wiki, public Statuspage, Freshdesk support, broad named-partner directory. '1400+' claim discounted.
Second scorer rationale: Independent review reaches same band: programme structure is real; absence of public marketplace listing with verifiable certification dates per partner keeps it adequate.
- Public partner directory at /integrations/see-complete-integrations-list enumerates named integration partners across RMS (IDeaS, Duetto, Flyr), distribution (SiteMinder, SHR, Sabre, TravelClick), CRM (Cendyn, Revinate-adjacent), POS (Oracle MICROS Simphony, Toast, Aloha, Lightspeed, NCR), locks (Salto, Dormakaba), spa (SpaSoft, Book4Time), guest-experience (Duve, Monscierge, GuestTouch) and direct booking (Sojern). https://www.stayntouch.com/integrations/see-complete-integrations-list
- Stayntouch operates a named Ambassador Program for partners and maintains a public support portal (Freshdesk) and a partner wiki (Atlassian Confluence at stayntouch.atlassian.net/wiki/spaces/WH) titled 'Connect APIs and Webhooks - Partners Guidance'. https://stayntouch.atlassian.net/wiki/spaces/WH/overview
- Marketing claim of '1400+ PMS integrations' on the Integration Hub. Not independently verifiable from the public partner directory which renders a much smaller named-logo set. https://www.stayntouch.com/integrations/
Documentation and changelog discipline
Score: 3 of 9 (Limited). Weight 7%.
Reconciliation note: Primary (5) and secondary (5) agree (MAD 0). Reconciled to 5. Anchor evidence: Single-page api-specs.stayntouch.com reference plus dated changelog back to 2022; no OpenAPI/Postman/SDK or per-language code samples. Primary rationale: Reference is complete and consistent; dated changelog back to 2022. But no OpenAPI/Postman/SDK/code-samples and the webhook signature guide sits on a partner-gated wiki. Secondary rationale: Independent review reaches same band: docs are clear but format and depth lag peer vendors that publish machine-readable specs and per-language samples. [0/3/6/9 rescale: primary 5→3, secondary 5→3, MAD 0 band(s), reconciled 3 — concurrent bands.]
First scorer rationale: Reference is complete and consistent; dated changelog back to 2022. But no OpenAPI/Postman/SDK/code-samples and the webhook signature guide sits on a partner-gated wiki.
Second scorer rationale: Independent review reaches same band: docs are clear but format and depth lag peer vendors that publish machine-readable specs and per-language samples.
- API documentation is a single-page HTML reference at api-specs.stayntouch.com/v2 with per-endpoint sections covering URI parameters, headers, query parameters, request body, 200/401/403/422 status codes and response bodies, with enumerated values explained (e.g. HOUSE/GROUP/INTERFACE/PASSERBY posting account types). http://api-specs.stayntouch.com/v2/index.html
- A separate dated changelog at /product-updates/ records API and webhook changes monthly from 2022 to May 2026 with deep links per change (e.g. 2026 May POST /reservations update, 2026 April pagination standardisation for GET /bills/revenue and GET /bills/invoices_per_day). https://www.stayntouch.com/product-updates/
- No public OpenAPI/Swagger JSON download, no Postman collection link, no machine-readable spec, and no public code samples in named languages were found on api-specs.stayntouch.com or the developers page. http://api-specs.stayntouch.com/v2/index.html
- Webhook signature verification guide is hosted on the partner Atlassian wiki at /wiki/spaces/WH/pages/4395335681/Stayntouch+Webhook+Signature+Verification+Guide (linked from the November 2025 HMAC update). https://www.stayntouch.com/product-updates/2025-november-webhook-update-hmac-sha256-signature-authentication/
Scores are published only where documented evidence exists. Corrections and disputes are recorded in the public changelog. The scoring rubric is published in full in the methodology.
This provider is listed in the HotelLogic marketplace →
Rank 7 of 17 scored vendors on the PMS Power Index ladder.