Skip to content

Applications

Applications give you access to all of Wink’s features as a developer. You can access all the same data and even extend Wink’s own features. You can choose to use Wink’s OAuth2 server to authenticate your travel site the same way you would use Google or Facebook. That way you can extend Wink’s features into your own website or application.

Sample application
Sample application entry
  1. Select the account you want to work with from Accounts.
  2. Click on Actions from the bottom of the account card and choose to Manage account.
  3. Click the Applications tab on the following page.
  4. This section will list all your applications.
  5. Rotate or delete an existing one, or create a new one.

As you cannot access the secret key of the app we created for you, you will need to create your own. You can create an application here without first setting up a property or company — it isn’t bound to any specific account.

When creating an application, you choose a client type that determines how the app authenticates. This can’t be changed later — if you need a different type, create a new application.

  • Web application — A server-rendered app that can safely keep a client secret (authorization code flow).
  • Single-page app (SPA) — A browser app with no backend; uses PKCE, with no client secret.
  • Mobile app — A native iOS/Android app; uses PKCE with rotating refresh tokens.
  • Machine-to-machine — A backend service acting as itself (client credentials); no user sign-in.

Here are the steps to creating an application:

  1. From the apps page, click the Create new application button.
  2. Name Give your app a name. e.g. Cool App
  3. Client type Choose the type that matches how your app authenticates — see Client types above.
  4. Redirect URIs At least one redirect URI is required. It is used for validating the redirect domain after a successful authentication. Not used for Machine-to-machine apps. e.g. https://www.cool-site.com
  5. Post-logout redirect URIs (Optional) URLs where users can be redirected after logging out. Leave blank to reuse the redirect URIs above.
  6. Scopes Choose what this application can access on your behalf — see Choosing scopes below.
  7. Click the Create application button to continue.

You are redirected back to your list of applications, and a one-time dialog shows the new Client ID and Client secret. Copy the secret now and save it somewhere safe — it is never shown again, and there is no way to retrieve it later (only rotate it for a new one).

Every application always carries the Sign-in (OpenID Connect) scopes (openid, profile, email, offline_access) — these confirm the user’s identity and keep them signed in, so they’re shown checked and locked; they aren’t a choice.

Everything else is opt-in. The remaining scopes are grouped into the same functional sections documented in Scopes — Account, Inventory & rates, Bookings, Marketing & promotions, Property content, Analytics & reports, Channel manager integrations, Payments, and Accounting & ledger — each with a plain-language description of what it unlocks. Use the All / None links above the list to select or clear every optional scope at once.

Two scope families are deliberately not offered on this form:

  • mcp.* — AI-agent access to the Model Context Protocol transport, which is provisioned separately and only for machine-to-machine clients.
  • Administrator-tier scopes (administrator.*) — platform-level access that isn’t granted per application.

Once an app is created, both this tab and Consented Apps show its granted scopes grouped by section (e.g. “Bookings: booking.read”), so you can see what an app can do at a glance without opening it.

If a client secret may have leaked, or you just want fresh credentials, rotate them instead of recreating the app:

  1. Find the app in your list of applications and click Rotate.
  2. Confirm the dialog — the current Client ID and secret stop working immediately.
  3. Copy the new Client ID and secret from the one-time dialog before closing it.

Rotating keeps the app’s name, client type, redirect URIs, and scopes — only the credentials change.

If you have no further use for an app, you can go ahead and remove it. This is permanent — the credentials are revoked immediately and can’t be recovered.

  1. Find the app in your list of applications and click Delete.
  2. Confirm the dialog to permanently delete the application.