Connect BaliStay Loyalty to Cloudbeds

Cloudbeds is the most common PMS for independent properties in Bali. BaliStay Loyalty receives reservation events from your Cloudbeds property, normalises them into guest and stay records, and awards loyalty points on checkout.

Official Cloudbeds developer documentation: developers.cloudbeds.com/

What syncs from Cloudbeds

  • Guest identity — name, email, phone and nationality — on each reservation event.
  • Stay dates, room type and the total amount of the stay.
  • Booking source, so direct bookings can be separated from OTA bookings.
  • Stay status transitions, including checkout, which is what triggers point accrual.

What you need to connect

  • Your Cloudbeds API key and the property ID the connection should map to.
  • An inbound webhook in your Cloudbeds property pointed at the BaliStay webhook endpoint.
  • A webhook secret shared between the two systems; every inbound request is verified against it.
  • Points are credited on the first transition of a stay into checked-out, so a retried webhook cannot double-credit a member.

Credentials the connection form asks for

  • apiKey — API key (required). Cloudbeds API key for the property.
  • propertyId — Property ID (required). The Cloudbeds property this hotel maps to.

Secrets are sealed with AES-256-GCM before storage and are never echoed back by the API.

What is not wired yet

Stated plainly because it affects how you plan the rollout.

  • Outbound reservation pull. BaliStay does not yet poll the Cloudbeds API to backfill stays, so only events arriving after the connection is created are captured.
  • OAuth 2.0 token exchange. Credentials are stored per hotel rather than obtained through an OAuth flow.

Cloudbeds integration questions

How long does the Cloudbeds integration take to set up?
The connection itself takes minutes once you have API access to your property. The longer part is the first data pull, which today depends on Cloudbeds sending events forward rather than BaliStay backfilling history, so historical stays may need importing separately.
Does BaliStay write anything back to Cloudbeds?
No. The Cloudbeds connection is inbound only in the current build. Loyalty data — points, tiers, member status — lives in BaliStay and does not sync back to the PMS.
What happens if Cloudbeds sends the same event twice?
Nothing is double-credited. Reservations are keyed on hotel plus external reservation ID, so a repeated event resolves to the same stay. Points are awarded only on the first transition into checked-out.
How is the webhook secured?
Each connection has its own webhook secret, and inbound requests must carry an HMAC-SHA256 signature over the raw request body that matches it. There is no global fallback secret, so a connection without a configured secret rejects all inbound events rather than accepting unsigned traffic.

Need a different PMS?

Cloudbeds and Mews are the two supported connections today. If you run something else, the inbound webhook contract is documented and we will scope a custom adapter during onboarding.