Track API
Track (TRACK Hospitality Software) exposes a REST API at https://{your-domain}.trackhs.com/api covering units, reservations, quotes, contacts, folios, messages and unit blocks, authenticated with an API key and secret signed with HMAC; it has no webhooks.
Written from running this integration in production. Last checked against the Track API on 3 October 2026.
What the Track API is
Track (TRACK Hospitality Software) is a PMS for vacation rental managers. Each company has its own Track domain, such as acme.trackhs.com, and its API lives at https://acme.trackhs.com/api. It covers units and the property (node) hierarchy they sit in, reservations, quotes, contacts, folios and payments, guest messages, unit blocks and nightly pricing.
Requests are signed with an API key and secret, using HMAC by default (Basic authentication is also accepted). There are two kinds of key: a Server Key reaches the whole API, while a Channel Key reaches only what a booking channel needs.
Track has no webhooks. Repull polls it about every minute for changed reservations, and guest conversations and messages are polled every minute too, so a change made in Track reaches you within a minute or two rather than instantly. Messages you send through Repull go out to the guest from Track.
Through Repull: each Track unit is a listing, reservations carry Track’s status and the full money breakdown (rent, fees, per-tax lines, amount paid and balance), and bookings are created, changed, quoted and cancelled with POST /v1/reservations/quote, POST /v1/reservations, PATCH /v1/reservations/{id} and POST /v1/reservations/{id}/cancel, made in Track first.
How to get Track API access
- 1.In Track, go to Configuration → Company Setup → API Keys and create a Server Key. It has full read and write access, and is the one we recommend.
- 2.Copy the API key and the API secret. Note your Track domain, the address you sign in at (for example
acme.trackhs.com). - 3.Send the domain, key and secret to
POST /v1/connect/track/credentials, or paste them into Repull Connect.keyTypedefaults toserverandauthModetohmac; leaveauthModealone unless Track support tells you otherwise. - 4.Repull checks the key against Track before saving anything, then starts the first import of units and reservations.
A Channel Key, created under Configuration → PMS Setup → Distribution Channels, can only quote, create, confirm and cancel bookings. Send keyType: "channel" with it. Changing bookings, guest messages, payments and calendar changes need a Server Key. Optional settings in credentials: moveReasonId (the Track move reason used when a booking moves to another unit — without it, a unit change is refused), paymentTypeId (the Track payment type that payments taken elsewhere are recorded under), and, only if Track support asks, hmacRealm (default Acquia) and secretIsBase64 (default true).
What will bite you
From running this integration in production, not from their documentation.
Moving a booking to another unit needs a move reason
Track requires a move reason when a booking changes unit. Set moveReasonId on the connection to the id of a move reason in Track; without it, a unit change is refused. Date and guest changes do not need it.
No webhooks
Track does not push changes. Everything is found by polling: reservations by their last update time, guest messages by their last event. Repull polls about every minute; built directly, you own that loop and its rate budget (10,000 requests per 5 minutes per IP).
Hold or Confirmed is Track’s decision
A new booking becomes a Hold or a Confirmed reservation depending on the property’s channel settings and guarantee policy. Without a payment it is usually a Hold, which Track can let expire. Repull asks Track to confirm it when you ask for a confirmed booking; if Track refuses, the booking stays a Hold and the response says so.
Custom prices need a setting on Channel Keys
Booking at your own price rather than Track’s quote needs "Allow Custom Pricing" turned on for the distribution channel when you use a Channel Key. Without it, Track refuses the booking and Repull tells you how to turn it on.
Channel bookings are locked
Bookings that came from Airbnb, Vrbo or Booking.com are locked to that channel in Track. They cannot be changed or cancelled through the API: Track’s own unlock would break the channel’s sync, so Repull never does it. Change them on the channel.
No refunds and no inbound messages
Track has no refund API, so refunds are made in Track. You can send guest messages, but there is no way to record a message the guest sent elsewhere into Track’s thread.
What it costs to keep working
The API is broad, but every customer is on their own domain, and nothing tells you when data changes.
- •A polling loop per customer, with a cursor for reservations past Track’s 10,000-result paging limit.
- •HMAC request signing per customer, with the key type deciding which calls are allowed at all.
- •Holds that expire, and bookings that come back a Hold when you asked for Confirmed.
- •Channel-locked bookings, which must be left alone.
The same job, both ways
Track directly
# Every request is HMAC-signed with your key and secret
curl -s 'https://acme.trackhs.com/api/v2/pms/reservations?updatedSince=2026-10-01T00:00:00Z' \
-H 'Authorization: acquia-http-hmac id="...",nonce="...",realm="Acquia",signature="...",version="2.0"' \
-H 'X-Authorization-Timestamp: ...'
# Then poll again every minute, and page past the 10,000-result limit.Through Repull
curl -s 'https://api.repull.dev/v1/reservations?limit=100' \
-H 'Authorization: Bearer sk_live_YOUR_KEY'
# Track bookings, kept current by Repull's polling, in the same shape as every other PMS.Why use Repull for Track
Your next customer may not be on Track
If you only ever need one Track customer, use its API directly — you would be adding a layer you do not need. The cost arrives with the second customer and the second system.
Polling handled
Track has no webhooks. Repull runs the polling for you, so Track bookings and messages stay current without a loop of your own.
One booking API
Quote, create, change and cancel through the same endpoints as the other PMSes, with what Track cannot do refused in plain words rather than failing silently.
Channels next to the PMS
The same Repull key reaches Airbnb, Booking.com and Vrbo directly, alongside Track.
Connect Track through Repull
Create a key, connect a Track account with its Client ID and Secret, and read reservations in the same shape as every other system you support.
Frequently asked questions
Does Track have a public API?
Yes. TRACK Hospitality Software documents its API at developer.trackhs.com. It covers units, reservations, quotes, contacts, folios, guest messages and unit blocks, on your own Track domain.
Which Track key should I use, a Server Key or a Channel Key?
A Server Key, created under Configuration → Company Setup → API Keys. It has full access. A Channel Key, under Configuration → PMS Setup → Distribution Channels, can only quote, create, confirm and cancel bookings.
Does Track have webhooks?
No. Repull polls Track about every minute, so a change made in Track shows up through Repull within a minute or two.
Can I message guests in Track through Repull?
Yes, with a Server Key. Guest conversations are polled every minute, and messages you send through Repull are sent to the guest from Track. A message the guest sent somewhere else cannot be written into Track’s conversation.
Why did my new booking come back as a Hold?
Track decides between Hold and Confirmed from the property’s channel settings and guarantee policy; with no payment it is usually a Hold. Repull asks Track to confirm it when you ask for a confirmed booking, and tells you when Track refuses.
Can I change an Airbnb or Vrbo booking in Track through Repull?
No. Track locks bookings from Airbnb, Vrbo and Booking.com to their channel, and unlocking them would break the channel’s sync. Change them on the channel.
Has this been tested against a live Track account?
Repull’s Track connector is built and verified against Track’s API documentation. Tell us at hello@repull.dev if anything you see in Track differs.
The other systems Repull connects
Reference
Auth Type
API key + secret (HMAC)
Required Fields
domainapiKeyapiSecretkeyTypeauthModeSupported Operations
Connection Guide
In Track, go to Configuration → Company Setup → API Keys and create a Server Key (full access, recommended). Paste your Track domain, the API key and the API secret into Repull Connect. A Channel Key, under Configuration → PMS Setup → Distribution Channels, only allows booking.
Notes
- • Each Track unit is a listing
- • No webhooks: Repull polls Track about every minute, for reservations and for guest messages
- • Outbound guest messages are sent through Track; a message the guest sent elsewhere cannot be written into Track
- • A Server Key has full access; a Channel Key can only quote, create, confirm and cancel bookings
- • Hold or Confirmed is decided by the property’s policies in Track
- • Bookings locked to a channel (Airbnb, Vrbo, Booking.com) cannot be changed or cancelled through the API
- • No refund API