Applications
Applications give you access to all of Wink’s features as a developer. You can access all the same data and even extend Wink’s own features. You can choose to use Wink’s OAuth2 server to authenticate your travel site the same way you would use Google or Facebook. That way you can extend Wink’s features into your own website or application.
- Select the account you want to work with from Accounts.
- Click on
Actionsfrom the bottom of the account card and choose toManage account. - Click the
Applicationstab on the following page. - This section will list all your applications.
- Rotate or delete an existing one, or create a new one.
Create app
Section titled “Create app”As you cannot access the secret key of the app we created for you, you will need to create your own.
You can create an application here without first setting up a property or company — it isn’t bound
to any specific account.
Client types
Section titled “Client types”When creating an application, you choose a client type that determines how the app authenticates. This can’t be changed later — if you need a different type, create a new application.
- Web application — A server-rendered app that can safely keep a client secret (authorization code flow).
- Single-page app (SPA) — A browser app with no backend; uses PKCE, with no client secret.
- Mobile app — A native iOS/Android app; uses PKCE with rotating refresh tokens.
- Machine-to-machine — A backend service acting as itself (client credentials); no user sign-in.
Here are the steps to creating an application:
- From the apps page, click the
Create new applicationbutton. - Name Give your app a name. e.g. Cool App
- Client type Choose the type that matches how your app authenticates — see Client types above.
- Redirect URIs At least one redirect URI is required. It is used for validating the redirect domain after a successful authentication. Not used for Machine-to-machine apps. e.g. https://www.cool-site.com
- Post-logout redirect URIs (Optional) URLs where users can be redirected after logging out. Leave blank to reuse the redirect URIs above.
- Scopes Choose what this application can access on your behalf — see Choosing scopes below.
- Click the
Create applicationbutton to continue.
You are redirected back to your list of applications, and a one-time dialog shows the new Client ID and Client secret. Copy the secret now and save it somewhere safe — it is never shown again, and there is no way to retrieve it later (only rotate it for a new one).
Choosing scopes
Section titled “Choosing scopes”Every application always carries the Sign-in (OpenID Connect) scopes (openid, profile,
email, offline_access) — these confirm the user’s identity and keep them signed in, so they’re
shown checked and locked; they aren’t a choice.
Everything else is opt-in. The remaining scopes are grouped into the same functional sections
documented in Scopes — Account, Inventory & rates, Bookings,
Marketing & promotions, Property content, Analytics & reports, Channel manager integrations,
Payments, and Accounting & ledger — each with a plain-language description of what it unlocks. Use
the All / None links above the list to select or clear every optional scope at once.
Two scope families are deliberately not offered on this form:
mcp.*— AI-agent access to the Model Context Protocol transport, which is provisioned separately and only for machine-to-machine clients.- Administrator-tier scopes (
administrator.*) — platform-level access that isn’t granted per application.
Once an app is created, both this tab and Consented Apps show its granted scopes
grouped by section (e.g. “Bookings: booking.read”), so you can see what an app can do at a glance
without opening it.
Rotate credentials
Section titled “Rotate credentials”If a client secret may have leaked, or you just want fresh credentials, rotate them instead of recreating the app:
- Find the app in your list of applications and click
Rotate. - Confirm the dialog — the current Client ID and secret stop working immediately.
- Copy the new Client ID and secret from the one-time dialog before closing it.
Rotating keeps the app’s name, client type, redirect URIs, and scopes — only the credentials change.
Remove app
Section titled “Remove app”If you have no further use for an app, you can go ahead and remove it. This is permanent — the credentials are revoked immediately and can’t be recovered.
- Find the app in your list of applications and click
Delete. - Confirm the dialog to permanently delete the application.
