Build on the API our own apps run on
HiLucy is built API-first: every screen in our production guest and staff apps runs on the same authenticated REST API we open to partners, so nothing you integrate against is a bolt-on. Sandbox access is granted on request — a dedicated, isolated environment with seeded demo data and individually revocable credentials, free while you build. When your integration is validated in sandbox, production access is enabled per-agreement.
What you get in sandbox
Sandbox access is provisioned per partner, on request. Here is what's in it.
An isolated environment
The sandbox is isolated infrastructure with its own database — nothing it touches is production.
A seeded demo hotel
Representative reservations, folios, and menus come pre-loaded, so you can exercise real flows — bookings, charges, orders — from your first request.
Stripe test mode
Payments run against Stripe test keys. You can take a booking through checkout end to end with no real card and no real money.
Per-partner credentials over HTTPS
Credentials are issued individually, scoped to your sandbox property, and can be rotated or revoked without touching anyone else's access.
A named contact
You get a named person on our team while you integrate — not a ticket queue.
Free while you build
Sandbox access costs nothing during the program. Commercial terms only enter the picture with production access.
Integration depth, answered
Every integration page publishes a scope table stating direction, what triggers each sync, and what is not synced — per object. The three partners ask about most:
Cloudbeds
Read-onlyRead-only. We read reservations, guests, and rooms every 15 minutes and never write back — the PMS stays the system of record for the booking, which is the safe default for an integration sitting next to your revenue.
View scope tableStripe
Two-wayTwo-way. In-chat charges and card-on-file holds go out; payment results come back on webhooks. In sandbox, all of it runs in Stripe test mode.
View scope tableWhatsApp Business API
Two-wayTwo-way messaging on the official WhatsApp Business API: inbound guest messages, replies, and Meta-approved templates outside the 24-hour window.
View scope tableWhat we don't offer yet
We would rather you find these edges here than three weeks into a build.
No self-serve API keys
There is no signup form and no developer portal. Credentials are issued per partner, by a person, when sandbox access is granted.
No versioned API contract
The API evolves with the product. We do not yet publish frozen versions or a deprecation policy — build in sandbox first and validate before anything touches production.
No published SLAs
We do not publish uptime numbers or support response guarantees yet. What we offer is a named contact and straight answers.
Production API access is not self-serve: it is enabled per-agreement, after your integration is validated in sandbox.
Request sandbox access
Tell us what you're building and we'll set you up. Sandbox is free while you build; production access follows per-agreement once your integration is validated.
Email [email protected]