Tourical API
A REST API and webhook system for operators running their bookings through Tourical.
The Tourical API gives you programmatic access to the same data your operator team manages from the dashboard — trips, bookings, clients, payments, library catalogs — plus a webhook stream so your own systems can react to changes in real time.
The API is server-to-server only. Tokens are scoped to a single tenant and grant access to that tenant's data only. Browser code should never carry a token directly; route calls through your own backend.
API surface
Every endpoint lives under https://app.tourical.com/api/v1/. The current version is v1.
Seven resources, 23 methods.
| Resource | Capability |
|---|---|
| Token introspection | Read back the tenant, scopes, expiry and environment behind the calling token |
| Trips | List, fetch, create, patch |
| Bookings | List, fetch (creation hands off to the storefront checkout) |
| Clients | List, fetch, create |
| Payments | List (read-only) |
| Libraries | Read your hotels, activities, vehicles, guides |
| Webhooks | Subscribe, list, revoke, send a test event, rotate the signing key, inspect and replay deliveries |
Get going
Quickstart
Make your first request in a minute.
Authentication
Token format, scopes, storage, and rotation.
Webhooks
Subscribe to events and verify signatures.
Endpoint reference
Full request and response shapes per resource.
What you won't find here
These deliberately aren't part of the public API:
- Direct booking creation with payment capture. Travellers go through the public storefront URL so we keep one Stripe Connect flow.
POST /v1/bookingsreturns 501 with the redirect URL. - Internal operator actions like running an autopilot, applying advisor proposals, or generating Annex I documents. Those are session-authenticated only.
- Recipient surfaces (dossier links, traveler portals, leader PWA) — those use short-lived per-recipient tokens, not API keys.
If you need something that isn't exposed, open an issue or write to developers@tourical.com.

