openapi: 3.0.3 info: title: Smoobu Apartments Guests API description: The Smoobu API is a RESTful JSON API for the Smoobu vacation rental channel manager and property management system. It lets Professional subscribers and integration partners read and write apartments (listings), reservations (bookings), rates and availability, guests, and guest messages, and register webhooks for reservation changes. The primary base URL is https://login.smoobu.com/api; the public booking availability check is served under https://login.smoobu.com/booking. Authentication uses an API key sent in the "Api-Key" header (found in the Smoobu account under Settings > For Developers / API Keys). Smoobu additionally offers HMAC-signed requests (X-API-Key, X-Timestamp, X-Nonce, X-Signature headers) as the recommended method and OAuth 2 for partners; the legacy plain Api-Key header is documented as being sunset on 2026-09-25. Endpoints marked in descriptions as "modeled" are inferred from the documentation and should be verified against the live reference before production use. version: '1.0' contact: name: Smoobu url: https://www.smoobu.com servers: - url: https://login.smoobu.com description: Smoobu production security: - apiKey: [] tags: - name: Guests description: Guest contact records. paths: /api/guests: get: operationId: listGuests tags: - Guests summary: List guests description: Lists guest records, with pagination. parameters: - name: page in: query schema: type: integer - name: pageSize in: query schema: type: integer responses: '200': description: A paginated list of guests. '401': $ref: '#/components/responses/Unauthorized' /api/guests/{guestId}: parameters: - name: guestId in: path required: true schema: type: integer get: operationId: getGuest tags: - Guests summary: Get a guest description: Retrieves a single guest record by id. responses: '200': description: The guest. '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' components: responses: Unauthorized: description: Authentication failed or the API key is missing or invalid. NotFound: description: The requested resource was not found. securitySchemes: apiKey: type: apiKey in: header name: Api-Key description: Smoobu API key sent in the Api-Key header. HMAC-signed requests (X-API-Key / X-Timestamp / X-Nonce / X-Signature) are the recommended method; OAuth 2 is available for partners. The plain Api-Key header is documented as being sunset on 2026-09-25.