API User & Integration Guide

Modified on Sun, 14 Jun at 4:23 PM

Introduction

An API (Application Programming Interface) allows two systems to exchange information securely and efficiently. The Expian API allows access to key features of the Expian platform, such as product availability, creates bookings, membership validation, and entitlements, so that clients and partners can build their own digital experiences using the same underlying functionality that powers Expian’s vanilla site. A vanillawebsite is a base implementation of the booking journey, a fully functional template that demonstrates best practice use of the API. It can be personalised for each client’s brand, products, and audience needs, providing a reliable starting point for bespoke website experiences.

In short: if you can do it on Expian’s vanilla booking site, you can do it through the API.

Examples include:

  • Creating and managing bookings for journeys, attractions, or events.
  • Applying vouchers or promos at checkout.
  • Validating tickets and vouchers.
  • Integrating Expian data with external CRMs, campaign management and marketing tools, analytics tools, ticketing systems and more.

This guide explains what the Expian API is, what it does, and how it supports the wider Expian ecosystem. It’s written for non-technical users, such as project managers, content teams, and client partners, who need to understand how Expian’s API connects systems and enables smooth booking, membership, and entitlement experiences..

Note: This guide complements the Expian Technical API Documentation, which contains endpoint details, request/response schemas, and field-level definitions. Refer to the technical document for exact API specifications.

Key Features & Benefits

The Expian API offers a consistent, scalable, and secure foundation for connecting booking and membership systems across travel and attractions. It is designed to simplify integration and enable flexible digital experiences.

Key Features

  • Unified Access: Connects booking, membership, and entitlement data through one platform.
  • RESTful Design: Uses standard HTTP methods and JSON, making it easy to integrate with modern systems.
  • RESTful Design definition:
    'RESTful' means the API follows REST (Representational State Transfer) principles, a simple, standard way for systems to communicate over the web. RESTful APIs are predictable and easy to use because they rely on familiar web operations.
  • HTTP Methods definition:
    These are the standard 'action' used in web communication to tell the API what you want to do with data:
  • GET: Retrieve information (e.g., list of bookings).
  • POST: Create something new (e.g., make a booking).
  • PUT / PATCH: Update existing information (e.g., change a booking date).
  • DELETE: Remove something (e.g., cancel a booking).
  • JSON (JavaScript Object Notation) definition:
    JSON is the lightweight data format that APIs use to send and receive information. It’s easy for both users and computers to read.
  • Modular Endpoints: Supports products, bookings, memberships, payments, and reporting as discrete, connectable services.
  • Endpoint definition:
    An endpoint is the specific web address (URL) where the API performs a function or provides information. Each endpoint handles one type of task, for example, retrieving products, creating a booking, or processing a payment. You can think of endpoints as individual doors into the Expian system, each dedicated to a particular service or data set.
  • Real-Time Data: Provides up-to-date information on pricing, availability, and customer entitlements.
  • Secure Authentication: Ensures data integrity and privacy through token-based access control.
  • Expian Sandbox Environment: Enables partners to safely test and validate integrations before going live.

Benefits

  • Faster Integrations: Reduce development time with standardised, well-documented endpoints.
  • Consistent Experiences: Ensure that custom sites and third-party tools behave exactly like Expian’s vanilla booking site.
  • Scalable Architecture: Handle high transaction volumes without performance loss.
  • Data Reliability: Maintain accurate, real-time access to bookings, entitlements, and membership data.
  • Future-Proofing: Semantic versioning supports smooth upgrades and backward compatibility.

Why It Matters

The Expian API underpins all client and partner digital experiences, from online bookings to on-site membership validation. By using the same API that powers Expian’s vanilla site, partners gain access to a stable, proven foundation for their own systems.

Why This Matters to You

  • Operational Consistency: Everyone, internal teams, partners, and clients, interacts with the same trusted data.
  • Reduced Complexity: Simplifies data exchange between systems, avoiding manual workarounds or duplicate integrations.
  • Improved Reliability: Ensures consistent uptime and response times through tested, scalable architecture.
  • Business Agility: Enables faster delivery of new digital services and customer experiences.
  • Governance & Compliance: Built with GDPR, security, and data stewardship in mind.

The Expian Platform

Expian provides a unified platform for managing bookings, memberships, entitlements, and customer experiences. The API sits at the heart of this platform, connecting front-end experiences (websites, apps, POS systems) to the operational data layer.

The API serves:

  • Vanilla Website: Expian’s default booking site uses the public API endpoints available to partners. It’s a working reference for typical user journeys.
  • Client Implementations: Many clients build their own branded booking experiences on top of the Expian API.
  • Integration Partners: External systems connect to Expian for inventory synchronisation, membership verification, and entitlements.

Getting Started

Some further technical terms that you may have heard of but were too embarrassed to ask....

Token

A short-lived credential proving your app is allowed to call the API. You include it in each request’s Authorization header.

Example header:Authorization: Bearer <access_token>

Wherever we have pagination, it includes the following parameters:

.

Pagination

A way the API splits large result sets into smaller pages so responses stay fast and lightweight. Where we have pagination, you request page-by-page using parameters; currentPage, perPage, from, to, total, lastPage, and the API returns a pointer to the next page.

Example:GET /api/v1/products?limit=50&cursor=abc123 → response includes nextCursor you use on the next call.

API Key

A unique identifier used to authenticate and authorise a system or application to access the API. It’s like a password for your integration, issued by Expian for your organisation. API keys should always be stored securely and never exposed in public code or client-side applications.

Example:x-api-key: abcd1234efgh5678

OAuth Credential

A secure authorisation method that uses tokens instead of passwords. OAuth allows systems to access the API on behalf of a user or service without sharing credentials directly. It’s commonly used when multiple systems or users need controlled, time-limited access.

Example flow: Your app requests an access token → Expian issues a short-lived token → your app includes it in each API request.

Webhook

A webhook is a way for the API to send information automatically to another system when something happens, for example, when a booking is confirmed or a payment succeeds. Instead of your system asking for updates, Expian 'pushes' the information to a URL you provide, so data stays up to date in real time.

Polling

Polling is when your system repeatedly asks the API if something has changed (for example, 'Has this booking been updated yet?'). It’s less efficient than using webhooks because it sends many requests, even when there’s no new data.

Access and Authentication

To use the Expian API, partners must request credentials from the Expian Integration Team. Each partner receives unique API keys or OAuth credentials, depending on configuration.

  • Sandbox Environment: For testing and development.
  • Production Environment: For live integrations.

Always use the sandbox to validate workflows before connecting to production.

Making Your First Call

All API requests use standard REST conventions and JSON format. A typical call retrieves available products, creates a booking, or validates a membership.

Example (simplified):

GET /api/v1/products

Authorization: Bearer {token}

The response will contain available products, pricing, and metadata. For full endpoint specifications, see the Technical API Documentation.

API Versioning

Expian currently ensures that all API changes have backward compatibility. The /api/v1/ path is a namespace rather than a version. Expian does not currently use API versioning; the platform remains backwards compatible, and v1 is maintained for structural consistency

Vanilla Booking Flow Overview

The vanilla site demonstrates a standard booking flow powered entirely by Expian’s API:

  • Search & Select: Retrieve product lists and availability.
  • Configure & Price: Apply dates, options, and entitlements.
  • Customer & Payment Details: Capture required booking information.
  • Checkout & Confirmation: Complete the transaction and generate confirmation tokens.
  • Post-Booking Actions: Retrieve, modify, or cancel bookings as needed.

Integration partners can reuse or extend any of these steps. For example, a partner may add:

  • A custom front-end experience for the search and booking journey.
  • An internal system integration to manage cancellations or membership benefits.
  • Automated reporting using the API’s booking and transaction endpoints.

Practical Use Cases

Building a Custom Booking Site

Use the API’s product, pricing, and booking endpoints to design a branded booking journey that mirrors Expian’s vanilla flow. This is ideal for partners who want to control their own look and feel while using Expian’s secure backend.

Membership & Entitlement Validation

Integrate Expian’s membership endpoints to check customer status, apply benefits, or validate access at POS or entry gates. For example, HRP uses this to ensure that members receive correct entry privileges and discounts.

Integrating with CRM or Analytics

Partners can feed Expian data into CRMs or BI platforms to track conversion, membership engagement, or campaign performance. Use the reporting endpoints or webhooks for real-time updates.

Ticket Validation & Check-In

Use Expian’s validation endpoints to scan tickets or vouchers, confirming their validity and updating attendance records automatically.

Inventory Synchronisation

For travel or event partners, synchronise products and availability with Expian in near real-time using the product and booking APIs.

Integration Best Practices

Security & Authentication

  • Always use HTTPS.
  • Store tokens securely and refresh them as required.
  • Never expose API keys in client-side code.

Error Handling

  • Implement retry logic for transient errors (HTTP 429 or 5xx).
  • Log and monitor API responses for auditing.
  • Refer to technical documentation for response codes and error messages.

Data Efficiency

  • Use pagination and filtering to limit response size.
  • Cache static data such as product lists where appropriate.
  • Avoid polling, use available webhooks or status endpoints.

Version Control & Compatibility

  • Always reference the latest stable API version.
  • Test integrations in sandbox before deployment.

Compliance & Governance

  • Adhere to GDPR and data protection laws.
  • Do not store unnecessary personal data.
  • Implement clear data retention and deletion policies.
  • Follow Expian’s Data Security and Privacy guidelines.

Implementation Playbook (Discovery → Live)

Discovery & Scope

  • Capture use-cases, systems, and data domains (Bookings, Memberships, Entitlements, Payments, Reporting).
  • Define success metrics (latency, reconciliation, CLV coverage, segmentation readiness).
  • Artifacts: RACI, data flow diagrams, field mapping matrix, error-handling policy.

Technical Mapping

  • Agree External IDs and consistent naming for products, tickets, membership types.
  • Select integration pattern: webhooks (push) over polling (pull) where possible.
  • Security: OAuth/API keys, token refresh, least-privilege scopes.

Build & Configure

  • Set up a test (sandbox) connection to Expian’s API, use the correct API version (/api/v1/), and if you’re tracking analytics, make sure GA4 (Google Analytics) and GTM (Google Tag Manager) event tracking are configured as part of the integration
  • Implement retries/backoff for 429/5xx and idempotency where relevant.

Test & Validate

  • UAT scripts that mirror real journeys (search, price, add-ons, checkout, refunds, membership validation).
  • Data QA: pagination boundaries, time zone handling, and rounding rules in finance exports.

Launch & Operate

  • Phased go-live with monitoring dashboards (API error rates, webhook delivery, job queues).
  • Create a release/compatibility plan using semantic versioning.

Troubleshooting & Support

Common Issues

Getting Help

  • Check the Technical API Documentation for endpoint details and examples.
  • Contact the Expian Integration Support Team via your partner portal or support email.
  • Include timestamps, endpoint URLs, and error messages when reporting issues.

Appendix

Key API Areas

*For detailed request/response schemas, parameters, and error codes, see the Expian Technical API Documentation.

Glossary

Summary

The Expian API offers a flexible, secure, and proven foundation for creating booking and membership experiences across travel, attractions, and events. Whether you are embedding Expian functionality in your own site or integrating it with existing systems, following the guidance in this document will help ensure reliable, compliant, and scalable implementations.

For full endpoint details, field definitions, and examples, please refer to the Expian Technical API Documentation.

Authentication failure

/api/v1/transactions

Expian’s default booking website using standard API calls.

Manage benefits, discounts, and access rights

Resolution

Payments

Reporting

Regenerate token and retry

Membership

Products

Booking

Entitlements

A third-party system connected to Expian via API.

Create, modify, or cancel bookings

Vanilla Site

Purpose

Possible Cause

Issue

Validate against Technical API Documentation

Bookings

Process payments or initiate checkout

Retrieve available inventory, pricing, and metadata

Entitlement

Unoptimised queries or high volume

Definition

Incorrect payload or endpoint

Memberships

A benefit or right (e.g., membership discount or access pass).

Retrieve sales, transaction, or operational data

Use filters, pagination, and caching

Validate membership, retrieve member details, apply benefits

Unexpected error codes

/api/v1/entitlements/validate

Integration Partner

Term

/api/v1/products

A confirmed purchase of a product, journey, or event.

Expired or invalid token

/api/v1/bookings

Category

/api/v1/memberships

Slow response times

Example Endpoints*

/api/v1/checkout

A time-based or benefit-based account granting entitlements.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article