Embedding Owner Import

Each listing group can have an owner-import link. A property owner opens it, connects their own VRBO, Booking.com, Houfy or Airbnb account, and picks which listings to import into the group. They don't need a Host Tools login. You can send owners the link, or put the page inside your own app with an <iframe>. This page is about the iframe.

Before you start

  1. Ask us to allowlist your domain. Email [email protected] with the domain your app runs on. Until we add it, browsers refuse to show the page in your iframe, and Chrome shows app.hosttools.com refused to connect. An entry covers the domain and its subdomains, over HTTPS only. The same list controls which redirect URLs the page accepts.
  2. Get the link. Generate or Rotate Owner Import Link returns ownerImportLink, and List Listing Groups and Get Listing Group return the current link.

Each new link invalidates the group's previous one. Generate it once and store it, rather than calling generateOwnerImportToken every time you render the iframe.

Build the iframe URL

Start from ownerImportLink and add any of these query parameters:

ParameterValuesWhat it does
channelsComma-separated: airbnb, vrbo, booking, houfy. homeaway and booking.com also work. Case doesn't matter.Shows only these channels on the channel picker. If it's missing, empty, or has no recognized channel, all four show.
embed1 or trueHides the Host Tools footer, the support chat widget and Host Tools' analytics scripts. The Host Tools logo and the page heading stay.
redirectAn HTTPS URL on your allowlisted domain, URL-encodedOnce the owner has imported listings, the whole browser tab goes to this URL, not only the iframe. The page ignores a URL that isn't allowlisted.
<iframe
  src="https://app.hosttools.com/owner-import?ownerImportToken=<token>&channels=vrbo,booking,houfy&embed=1&redirect=https%3A%2F%2Fapp.example.com%2Fowners%2Fdone"
  width="100%"
  height="800"
  style="border: 0"
></iframe>

Connect Airbnb outside the iframe

Airbnb won't let its sign-in and consent pages load inside an iframe, and the owner-import page opens Airbnb in the same frame. If an owner picks Airbnb in your iframe, the frame goes blank or shows www.airbnb.com refused to connect.

Leave airbnb out of channels and connect Airbnb with Headless Airbnb Auto-Connect instead. Send the owner's whole browser tab to:

https://app.hosttools.com/api/owner-import/auto-connect/airbnb?ownerImportToken=<token>&redirect=<url-encoded redirect>

The owner goes straight to Airbnb. After they approve, Host Tools adds every listing from that Airbnb account to the group, skipping any that are already in Host Tools. It then sends the owner to your redirect with the result in the query string, for example ?owner-import-status=success&imported=3&accountID=.... If your button sits inside an iframe of your own, give the link target="_top".

channels only filters the first channel picker. Once an owner has imported listings, the + button on a listing opens a channel list that always shows all four channels, Airbnb included.

When the owner finishes

If you passed redirect, Host Tools sends the whole browser tab there, unchanged, when the owner finishes importing listings from the channel picker. It doesn't add result parameters the way Headless Airbnb Auto-Connect does. If the browser blocks the navigation, the owner sees "Redirecting you back…" and a Continue button, and after 3 seconds, their import dashboard. Connecting another channel to a listing that's already imported doesn't trigger the redirect.

Without redirect, the owner stays in the iframe on a dashboard of the group's listings, where they can connect more channels or import more listings.

The iframe doesn't send postMessage events to your page. To find out what was imported, use either of these:

  • The listingGroup.changed webhook. Host Tools sends it when listings join the group, with the group's full listingIDs, so you can compare it with your copy.
  • GET /api/getListingGroup/{listingGroupID}, called when the owner lands on your redirect URL.

Sandboxed iframes

You don't need sandbox. If you use it, include these tokens:

sandbox="allow-scripts allow-same-origin allow-forms allow-popups allow-popups-to-escape-sandbox allow-top-navigation"
  • allow-scripts and allow-same-origin: the page is a JavaScript app that calls the Host Tools API.
  • allow-popups and allow-popups-to-escape-sandbox: some steps open the Booking.com extranet, Houfy settings or VRBO help in a new tab.
  • allow-top-navigation: needed for redirect. allow-top-navigation-by-user-activation isn't reliable here, because the redirect fires when the import finishes, not when the owner clicks.

Size and cookies

The page doesn't report its height to your app, so give the iframe a height of at least 800px or let it fill the viewport. The connect and import steps open as dialogs inside the frame, and a short frame squeezes them.

The page signs in with the token in its URL rather than a cookie, so it works in browsers that block third-party cookies.

Keep the link private

Anyone with the link can import listings into the group and connect or disconnect channels on its listings, so only show it to the owner it's for. If it leaks, call generateOwnerImportToken again. The old link stops working straight away.

Troubleshooting

What you seeWhyFix
The iframe is blank, or says app.hosttools.com refused to connectYour domain isn't on the allowlistEmail [email protected]
www.airbnb.com refused to connect after the owner picks AirbnbAirbnb can't load in an iframeLeave out airbnb and use Headless Airbnb Auto-Connect
The page says the link is invalidThe link was regenerated, or the URL was changedGet the current ownerImportLink from the API
The owner stays on the dashboard instead of going to redirectredirect isn't HTTPS or isn't allowlisted, or the sandbox is missing allow-top-navigationCheck the URL and the sandbox tokens