Advisory guide · updated 29 July 2026

SiteMinder API keys — hygiene, scope and rotation for boutique hotels

Most boutique hotels we scope for Hotelminder inherit one all-powerful SiteMinder API key from the previous consultant. This guide walks through the tidy replacement — one key per module, one property per key, rotated on staff turnover.

Hotelminder does not need much from your SiteMinder subscription — most modules on our shortlist read three or four endpoints and write to one. That means your API keys can be small, purposeful, and boring, which is exactly how boutique operations teams like their credentials. What follows is the housekeeping we do on every scoping call, whether the hotel is new to Hotelminder or has been running for a year.

Why the default one-key-fits-all pattern hurts you

SiteMinder does not enforce a scope model on API keys; you can create a single omnipotent key and paste it into every partner integration that ever asks. Most consultants do exactly that because it is faster on day one. The cost lands later: when the revenue manager who set up that key leaves, no-one wants to rotate it because five partners will break; when a partner integration is compromised, every partner integration is now compromised; when your fiscal auditor asks who wrote to your rate plans on the night of the New Year's Eve overbooking, there is no answer beyond "someone with the key".

The Hotelminder pattern is the opposite. One key per module per property, named after both, rotated on a fixed cadence, revoked immediately on staff turnover. It sounds heavy — in practice it takes about forty seconds per key to create, and pays back the first time you need to answer an auditor.

How to name a key so future-you doesn't hate you

Give every key three parts in its name: the partner, the module, and the property short code. Our convention is hotelminder-rate-reasoner-vienna-01 or hotelminder-fiscal-composer-milan-02. The trailing number is the rotation index — bumped by one every time the key is regenerated. It reads a little verbose in the SiteMinder key list, but every column tells you something you will want in eight months.

Scoping to a single property (not to the parent group)

On SiteMinder Multi-Property, the key generation dialogue defaults to full group access if you are logged in as a group admin. Do not accept the default. Click Change scope, tick only the property the key is for, and confirm. Even for the Portfolio Sync Fabric module, which pushes rates across the group, we ask you to generate one key per property and let the Fabric orchestrate — a single group-scoped key is a single point of failure that a boutique group cannot absorb without pausing every property.

Rotation cadence

Two rules. First, rotate every ninety days by default, calendared into your operations lead's task list. Second, rotate immediately — same day, before the exit interview if possible — when a staff member with access to the SiteMinder admin panel leaves. The rotation itself is: generate a new key with the next index number, paste it into Hotelminder, wait for the green handshake, then delete the old key from SiteMinder. Hotelminder holds both keys warm for up to twelve hours so there is no gap in module availability. The old key does not have to be deleted immediately, but it should be gone before the next revenue meeting.

Revoke without breaking a live module

The instinctive move when you suspect a leaked key is to delete it in SiteMinder. Do not do that first. Instead, log into Hotelminder, open the affected property, and pause the module. Pausing severs the module's scope without deleting the connection — the module holds its state, the guest data stays where it is, and the property page turns yellow rather than red. Then delete the SiteMinder key. Regenerate it. Paste the new one into Hotelminder. Un-pause the module. The whole sequence is under ten minutes for a single module, and it leaves your dashboard in a state you can defend at the next audit.

Do not paste an API key into email. Your Hotelminder advisor will never ask for a key over email. If a key needs to move between two people at your property, use your shared password manager or a one-time secret share tool with an expiry under twenty-four hours. Keys pasted into email survive in mailbox archives for years and are the single most common leak vector we see on boutique properties.

Reading the Hotelminder key audit log

Every SiteMinder API key registered with Hotelminder appears in the audit log at app.mindermod.org/keys. The log shows the key's name, its rotation index, its scope, the modules that consume it, the last successful read, the last write, the IP address the last write came from, and the SiteMinder response code. If any row is red for more than five minutes we page an advisor; you will get a note before you notice.