# 9flats > 9flats is a European vacation-rental marketplace, founded in Hamburg, Germany in 2010, listing > privately-owned apartments, houses and rooms for short-term stays. It published a public read API > over its listing data (v1, later v3), authenticated with OAuth 1.0a and shipped with a first-party > Ruby SDK. This file was GENERATED by API Evangelist from the artifacts in this repository. It is not published by 9flats. 9flats serves no /llms.txt of its own — that could not even be confirmed, because every path on every 9flats host answers HTTP 403 behind a Cloudflare managed challenge (probed 2026-09-05). ## Status of the developer surface - **No machine-readable contract is published.** No OpenAPI, Swagger, AsyncAPI, GraphQL SDL, WSDL, Protobuf or Postman collection was found on any 9flats host, on the company's GitHub organisation, or in any public registry. - **The API reference has been withdrawn.** http://9flats.github.com/api_docs/ — the URL the company's own SDK and gemspec point at — returns 404, and the backing repository (9flats/api_docs) is gone. A v3 reference page existed there; it is also gone. - **The only client library is unsupported.** The Ruby gem `nineflats-api` was last released 2011-11-07 (v0.0.9) and its README opens: "This gem is no longer supported and only usefull for v1." - **The live surface could not be probed.** www.9flats.com, 9flats.com and api.9flats.com all return 403 with `cf-mitigated: challenge` to non-browser clients. We do not evade challenges, so nothing below was validated against a live response. ## API - [9flats API v1 base](https://www.9flats.com/api/v1): OAuth 1.0a; JSON; nine read operations. Not verified reachable — see status above. Operations, as implemented by the provider's own SDK: - `GET /api/v1/places` — search places (nested `search[...]` params; 9 per page) - `GET /api/v1/places/{slug}` — a place, with optional `lang` - `GET /api/v1/places/{slug}/photos` — photos for a place - `GET /api/v1/places/{slug}/prices` — price sheet, including seasons - `GET /api/v1/places/{slug}/reviews` — reviews for a place - `GET /api/v1/places/{slug}/calendar/{year}/{month}` — availability for one month - `GET /api/v1/users/{user_id}` — a user - `GET /api/v1/users/{user_id}/favorites` — a user's favourited places - `GET /api/v1/users/{user_id}/bookings` — a user's bookings (OAuth access token required) ## Source of truth - [nineflats-api (first-party Ruby SDK)](https://github.com/9flats/nineflats-api) - [nineflats-api on RubyGems](https://rubygems.org/gems/nineflats-api) - [9flats on GitHub](https://github.com/9flats) - API contact published by 9flats: api@9flats.com ## Profile artifacts (this repository) - [Packages / SDKs](packages/9flats-packages.yml) - [Authentication](authentication/9flats-authentication.yml) - [Conventions](conventions/9flats-conventions.yml) - [Data model](data-model/9flats-data-model.yml) - [Conformance](conformance/9flats-conformance.yml) - [Lifecycle](lifecycle/9flats-lifecycle.yml) - [Rate limits](rate-limits/9flats-rate-limits.yml) - [Plans and pricing](plans/9flats-plans-pricing.yml) - [Well-known probe](well-known/9flats-well-known.yml) - [Domain security](security/9flats-domain-security.yml) ## Not published - OpenAPI / AsyncAPI / GraphQL / WSDL / Protobuf: none found - MCP server: none found - A2A agent card: not found (`/.well-known/agent-card.json` and `/.well-known/agent.json` both answered 403 at the edge on all three hosts — not observed, not confirmed absent) - llms.txt, security.txt, api-catalog, openid-configuration: not observed (403 at the edge) - Status page, SLA, changelog, deprecation policy, developer pricing, rate limits: none published