Each listing group can have an owner-import link. A property owner opens it, connects their own VRBO, Booking.com, Houfy or Airbnb account, and picks which listings to import into the group. They don't need a Host Tools login. You can send owners the link, or put the page inside your own app with an <iframe>. This page is about the iframe.
Before you start
- Ask us to allowlist your domain. Email [email protected] with the domain your app runs on. Until we add it, browsers refuse to show the page in your iframe, and Chrome shows
app.hosttools.com refused to connect. An entry covers the domain and its subdomains, over HTTPS only. The same list controls whichredirectURLs the page accepts. - Get the link. Generate or Rotate Owner Import Link returns
ownerImportLink, and List Listing Groups and Get Listing Group return the current link.
Each new link invalidates the group's previous one. Generate it once and store it, rather than calling generateOwnerImportToken every time you render the iframe.
Build the iframe URL
Start from ownerImportLink and add any of these query parameters:
| Parameter | Values | What it does |
|---|---|---|
channels | Comma-separated: airbnb, vrbo, booking, houfy. homeaway and booking.com also work. Case doesn't matter. | Shows only these channels on the channel picker. If it's missing, empty, or has no recognized channel, all four show. |
embed | 1 or true | Hides the Host Tools footer, the support chat widget and Host Tools' analytics scripts. The Host Tools logo and the page heading stay. |
redirect | An HTTPS URL on your allowlisted domain, URL-encoded | Once the owner has imported listings, the whole browser tab goes to this URL, not only the iframe. The page ignores a URL that isn't allowlisted. |
<iframe
src="https://app.hosttools.com/owner-import?ownerImportToken=<token>&channels=vrbo,booking,houfy&embed=1&redirect=https%3A%2F%2Fapp.example.com%2Fowners%2Fdone"
width="100%"
height="800"
style="border: 0"
></iframe>Connect Airbnb outside the iframe
Airbnb won't let its sign-in and consent pages load inside an iframe, and the owner-import page opens Airbnb in the same frame. If an owner picks Airbnb in your iframe, the frame goes blank or shows www.airbnb.com refused to connect.
Leave airbnb out of channels and connect Airbnb with Headless Airbnb Auto-Connect instead. Send the owner's whole browser tab to:
https://app.hosttools.com/api/owner-import/auto-connect/airbnb?ownerImportToken=<token>&redirect=<url-encoded redirect>
The owner goes straight to Airbnb. After they approve, Host Tools adds every listing from that Airbnb account to the group, skipping any that are already in Host Tools. It then sends the owner to your redirect with the result in the query string, for example ?owner-import-status=success&imported=3&accountID=.... If your button sits inside an iframe of your own, give the link target="_top".
channels only filters the first channel picker. Once an owner has imported listings, the + button on a listing opens a channel list that always shows all four channels, Airbnb included.
When the owner finishes
If you passed redirect, Host Tools sends the whole browser tab there, unchanged, when the owner finishes importing listings from the channel picker. It doesn't add result parameters the way Headless Airbnb Auto-Connect does. If the browser blocks the navigation, the owner sees "Redirecting you back…" and a Continue button, and after 3 seconds, their import dashboard. Connecting another channel to a listing that's already imported doesn't trigger the redirect.
Without redirect, the owner stays in the iframe on a dashboard of the group's listings, where they can connect more channels or import more listings.
The iframe doesn't send postMessage events to your page. To find out what was imported, use either of these:
- The
listingGroup.changedwebhook. Host Tools sends it when listings join the group, with the group's fulllistingIDs, so you can compare it with your copy. GET /api/getListingGroup/{listingGroupID}, called when the owner lands on yourredirectURL.
Sandboxed iframes
You don't need sandbox. If you use it, include these tokens:
sandbox="allow-scripts allow-same-origin allow-forms allow-popups allow-popups-to-escape-sandbox allow-top-navigation"allow-scriptsandallow-same-origin: the page is a JavaScript app that calls the Host Tools API.allow-popupsandallow-popups-to-escape-sandbox: some steps open the Booking.com extranet, Houfy settings or VRBO help in a new tab.allow-top-navigation: needed forredirect.allow-top-navigation-by-user-activationisn't reliable here, because the redirect fires when the import finishes, not when the owner clicks.
Size and cookies
The page doesn't report its height to your app, so give the iframe a height of at least 800px or let it fill the viewport. The connect and import steps open as dialogs inside the frame, and a short frame squeezes them.
The page signs in with the token in its URL rather than a cookie, so it works in browsers that block third-party cookies.
Keep the link private
Anyone with the link can import listings into the group and connect or disconnect channels on its listings, so only show it to the owner it's for. If it leaks, call generateOwnerImportToken again. The old link stops working straight away.
Troubleshooting
| What you see | Why | Fix |
|---|---|---|
The iframe is blank, or says app.hosttools.com refused to connect | Your domain isn't on the allowlist | Email [email protected] |
www.airbnb.com refused to connect after the owner picks Airbnb | Airbnb can't load in an iframe | Leave out airbnb and use Headless Airbnb Auto-Connect |
| The page says the link is invalid | The link was regenerated, or the URL was changed | Get the current ownerImportLink from the API |
The owner stays on the dashboard instead of going to redirect | redirect isn't HTTPS or isn't allowlisted, or the sandbox is missing allow-top-navigation | Check the URL and the sandbox tokens |