Environments

Two independent, physically separated environments. Data does not cross between them, credentials don't work across, and outbound webhook fanout is scoped to the environment that emitted the event.

Environment Base URL Docs Purpose
Production https://api.quendoo.com/v1/qc https://api.quendoo.com/v1/qc/docs Real hotelier data. Real bookings. Real money moving.
Staging https://staging-api.quendoo.com/v1/qc https://staging-api.quendoo.com/v1/qc/docs Sandbox. Ask us for test credentials. Feature parity with prod within one release.

Which one to use when

Getting staging credentials

Ask us. We mint a client_id / client_secret scoped to one or more staging properties we set aside for you. Turnaround: same business day.

What's in staging

What's NOT in staging

Environment differences that will bite

Resetting a staging property

For automated test suites: POST /v1/qc/staging/properties/{ext}/reset wipes every bookable calendar row, every booking, every custom policy back to the seed state. Configurations you pushed via QC (extras, promotions) are preserved unless you pass ?full=1. Not available in production.

Isolation

Domains + CORS

The public booking widget's domain is per-environment too: booking.quendoo.com (prod) vs staging-booking.quendoo.com (staging). Both are served from https:// only; HTTP 80 redirects to HTTPS 443.

CORS is set to allow every origin for GET/OPTIONS under /v1/qc/*, and to reflect Authorization; per-origin allow-lists are per-client_id and configured with us. Set them tight in prod.