# Oracle Hospitality > Oracle Hospitality is Oracle Corporation's hotel and food-and-beverage technology line, built on the 2014 acquisition of MICROS Systems. OPERA Cloud is the property management system of record for a large share of the world's branded hotel rooms; OPERA Cloud Distribution is the channel switch that carries a property's availability, rates and inventory out to GDS, OTA and web channels and reservations back; Nor1 handles upsell; Oracle Payment Interface handles card tokenization. The Oracle Hospitality Integration Platform (OHIP) is the single API front door for all of it. Generated by the API Evangelist enrichment pipeline on 2026-07-28. Method: generated from apis.yml and the artifacts in this repository. Oracle publishes no llms.txt (probed: docs.oracle.com/llms.txt 404, www.oracle.com/llms.txt 404). The specification layer is open and the credential layer is not. Oracle publishes 59 Swagger 2.0 documents covering 3,546 operations, plus 76 GraphQL SDL documents, to a public GitHub repository under the Universal Permissive License v1.0, alongside a fully public developer guide. There is no self-serve signup: partners buy Oracle Hospitality Integration Cloud Service through the Oracle Store or a CPQ form, production access needs an Oracle Partner Network reference number, and distribution partners additionally need an Oracle-issued global Channel Code and an Oracle Cloud Marketplace listing. API gateway hostnames are per tenant and are not published. ## Start here - [OHIP developer guide](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/): the complete public documentation - [Getting started](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/c_gs.htm): partner and hotelier onboarding paths - [Specification repository](https://github.com/oracle/hospitality-api-docs): all REST, GraphQL and Postman artifacts, UPL-1.0 - [Postman workspace](https://www.postman.com/hospitalityapis/workspace/oracle-hospitality-apis/overview) - [Oracle Hospitality Integration Platform](https://www.oracle.com/hospitality/integration-platform/): product page and buy flow ## API surfaces - REST, 59 Swagger 2.0 documents, 3,546 operations. Property APIs (OPERA Cloud PMS), Distribution APIs (channel connectivity and ARI), Nor1 upsell, Oracle Payment Interface tokenization and token exchange. - GraphQL, 75 read-only Reporting & Analytics subject areas at `/rna/v1/graphql/`, plus a Business Events streaming schema. - WebSocket, Business Events Streaming API delivered as a GraphQL subscription (push). - Outbound HTTPS callbacks the integration partner implements: ARI publication, content notification, external lookup, CRM outbound, cashiering outbound, front-office room keys. - SOAP, legacy only: OWS, HTNG, OXI and Kiosk, all in documented migration to REST. ## Specs - [REST specifications](https://github.com/oracle/hospitality-api-docs/tree/main/rest-api-specs): Swagger 2.0, one document per functional API - [GraphQL specifications](https://github.com/oracle/hospitality-api-docs/tree/main/graphql): Reporting & Analytics SDL and the streaming introspection schema - Harvested copies live in `openapi/` (59 files) and `graphql/` (77 files) in this repository ## Authentication - [Authenticating (Client Credentials / OCIM)](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/c_authenticating_to_oracle_hospitality_property_apis_ocim.htm) - [Authenticating (Resource Owner Group / SSD)](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/c_authenticating_to_oracle_hospitality_property_apis_ssd.htm) - OAuth 2.0 bearer token plus an `x-app-key` application key on every call. Property calls carry `x-hotelid`; distribution calls carry `x-channelCode`. Scope for OCIM environments: `urn:opc:hgbu:ws:_myscopes_`. - Artifacts: `authentication/oracle-hospitality-authentication.yml`, `scopes/oracle-hospitality-scopes.yml` ## Operating rules - [Limits](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/c_limits.htm): 50 requests/second per gateway shared by all consumers, 100 burst, HTTP 429 over burst; 8KB total headers; 100KB default request body; 100 applications per portal; one streaming consumer per chain/gateway/key. - [Versioning](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/c_versioning.htm): URI-path, current v1, deprecation announced at operation level with a sunset date. - [Upcoming major changes](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/c_upcoming_major_changes.htm): dated ReadMe announcements, the closest thing to a changelog. - [Common HTTP errors](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/c_common_error_messages.htm): status codes and resolutions. Business errors use module-prefixed codes (`RSV00001`, `GENxxxxx`). Not RFC 9457. - No idempotency key exists anywhere in the platform. Retries of writes are not safe by default. - Pagination is `limit`/`offset`. `fetchInstructions` selects which sub-resources are expanded. - Artifacts: `conventions/oracle-hospitality-conventions.yml`, `rate-limits/oracle-hospitality-rate-limits.yml`, `errors/oracle-hospitality-problem-types.yml`, `lifecycle/oracle-hospitality-lifecycle.yml` ## Events - [Business Events](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/c_business_events.htm): resource, event name, old value, new value - [Streaming API (push)](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/c_streaming_api.htm), recommended - [Polling API (pull)](https://docs.oracle.com/cd/F29336_01/doc.201/f27480/t_polling_api.htm), maximum 20 events per call - Derived event and outbound-callback surface: `asyncapi/oracle-hospitality-outbound-asyncapi.yml` ## Testing - Shared partner sandboxes with published test properties: `SAND01` (SSD) and `OHIPSB02` (OCIM). Credentials appear on the Developer Portal Environments page after onboarding. - Artifact: `sandbox/oracle-hospitality-sandbox.yml` ## Agent skills Packaged operating instructions grounded in real operationIds, in `skills/`: - Authenticate to the Oracle Hospitality Integration Platform - Shop availability and create a reservation - Run a guest from arrival to departure - Drive housekeeping room status - Connect a distribution channel to OPERA Cloud - Consume OPERA Cloud Business Events - Extract data in bulk from OPERA Cloud ## Security and compliance - [Reporting vulnerabilities](https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html): secalert_us@oracle.com, no bug bounty - [Oracle Trust](https://www.oracle.com/trust/) and [cloud compliance attestations](https://www.oracle.com/corporate/cloud-compliance/): SOC 1/2/3, ISO/IEC 27001/27017/27018/27701, PCI DSS, HIPAA, HITRUST, FedRAMP, CSA STAR - [OHIP security guide](https://docs.oracle.com/en/industries/hospitality/integration-platform/ohips/toc.htm) - Artifacts: `security/`, `conformance/oracle-hospitality-conformance.yml` ## Legal - [Terms of service](https://www.oracle.com/legal/terms.html) - [Privacy policy](https://www.oracle.com/legal/privacy/) - [Universal Permissive License v1.0](https://oss.oracle.com/licenses/upl), the licence on every published specification