API access · REST · GraphQL · Webhooks · MCP

Your data is yours — take it wherever you actually need it

Most platforms let you put data in and make getting it out difficult. We assume the opposite: bookings, lock logs, sensor readings, rates and availability are all one query away, events reach your system through a webhook within seconds, and the whole interface is documented. If you build your own tooling, integrate with your accounting, or want the entire thing under your own brand, that is a normal scenario here rather than an exception.

REST, GraphQL and webhooksAn MCP interface for AI agentsWhite label under your own brand
API access · REST · GraphQL · Webhooks · MCP

Four ways EZYsmart fits the rest of your stack

Webhooks: the event arrives in seconds

A new booking, a cancellation, a door opening, a sensor alarm or a payment — every event is posted to the address you nominate the moment it happens, signed and with retries. You are not polling on a one-minute timer or wondering whether two systems have drifted apart, because information moves on the event rather than on a clock.

REST and GraphQL over the same data

Simple things — checking availability, asking for a rate, creating a booking — take a couple of lines over REST. When you need the booking, the property, the rates and the log together, GraphQL fetches them in one request with exactly the fields you asked for. Both speak to the same data, so the choice is about taste rather than capability.

An MCP interface, so an AI agent can do real work

The same data is reachable over MCP, which means an AI assistant can pull occupancy, assemble a report or prepare a rate change without anyone writing a glue layer. The permissions are the same as everywhere else: the agent sees exactly what its key allows, and every action lands in the log.

Keys, scopes and a log that survives an audit

Every integration gets its own key, its own scopes and its own rate limits, so the accounting connector cannot open doors and a partner’s key can be revoked in one click. All requests are logged by timestamp and key. When a partnership ends, so does the access — in a second, not at the start of next month.

API access

Two systems nobody has to copy between any more

A small management company kept bookings in EZYsmart but invoices and client records in its accounting software. At the start of every month somebody spent two days moving numbers from one to the other: how many nights, at what rate, on which property, and what went missing along the way. The errors always surfaced at the worst possible moment, and always in front of clients. The integration took one developer a couple of days. Now a webhook posts every confirmed booking straight into accounting, a cancellation voids the draft invoice line too, and the monthly report is a single GraphQL query returning properties, nights and totals at once. At the same time the company’s website runs a white label booking form that looks like theirs rather than ours, backed by the same API. Two working days a month turned back into working days, and the month-end arguments disappeared, because both systems now read the same row.

API access

Related solutions

API and integrations — answers

Is the API a paid extra?

Access belongs to the platform rather than to a separate tier — we do not think getting your own data out should be a negotiation. Normal usage limits are set so that a regular integration never touches them: syncing bookings, reports, a website form, device events. If you have exceptionally high volume or you are building your own product on top of us, we agree separate limits and a support level, because at that point it is a partnership rather than ordinary use. White label and a branded interface are a separate agreement, since they include design, domain and support. Either way we quote the numbers upfront, not once the integration is finished and you are locked in.

How much development does a typical integration take?

The most common case — bookings from one system to another, a webhook in and a query out — is usually a couple of days for an experienced developer, because the hard part is not our interface but the other side’s data model. A simple availability or rate lookup is an hour. A bigger project, where a whole customer journey gets built under your brand, is measured in weeks. The documentation is public, examples exist, and the test environment lets you play the whole flow through without creating real bookings. If your team gets stuck, we answer technical questions directly rather than through a general support queue — which saves more time than any chapter of documentation.

What does white label mean in practice?

That your customer sees your brand and your domain, not ours. The booking form, the guest emails, the digital key page and the reports carry your logo, colours and name, and the address sits under your own website. Technically the same platform, the same API and the same support run behind it, but your customer never needs to know who built it. It is typically used by management companies, developers and partners who resell the solution under their own name. The agreement covers more than the visuals: who answers customer questions and who holds the data are part of it too, and those are things worth settling upfront, because changing them later is awkward.

Who owns the data, and can I take it out?

The data is yours. You can read all of it out over the API at any time and export it in a standard machine-readable format — bookings, customers, logs, measurements. Our role is to hold and process it so the service works, not to accumulate it for ourselves. The same applies if you leave: if you decide to move on, you take your data with you, not screenshots of it. On personal data we are the processor and you are the controller, which means the contract states what we may do and how long data is kept. Deletion and access requests can be fulfilled programmatically too, so you are not working through them by hand.

Does the MCP interface mean an AI gets access to my building?

Only as much as you allow. MCP is simply a structured way for an AI assistant to work over your data — pulling occupancy, assembling a monthly report, preparing a proposed rate change. The agent uses an ordinary key with precisely bounded scopes, so you can give it read-only access and leave door opening and payments entirely out. Every action is logged the same way a human’s would be. In practice it is used most for reporting and analysis, because that is where the value is clearest and the risk smallest. If you have no use for MCP, there is no need to switch it on at all.

Tell us what this has to talk to

Accounting, your own website, a partner’s system, or a real product built on top of us — describe what you are building and we will tell you honestly whether the API covers it or whether it is worth having us write it.