Creating a permission group for API affiliates
Last updated: May 5, 2025
Always check with the Channel Support team before adding/removing permissions for an API affiliate.
When adding an affiliate who is connected to FareHarbor using an API—Channel or External—we must give that affiliate a special permission group that allows them to enable their full API functionality. Specifically, Channel API affiliates must be able to:
- Cancel a booking: All API affiliates require the ability to cancel a booking they make.
- Set invoice prices: TripAdvisor Experiences/Viator pushes through invoice prices into FareHarbor.
Creating the permission group for Channel APIs
Here are the steps to take to create it:
- Navigate to Settings > Users & Permissions > Permission Groups tab.
- Go to “Affiliate – Cannot see prices” and click Edit.
- Scroll down and click Duplicate.
- Name the new permission group “Affiliate – API”.
All the checkboxes can remain the same except for two additions:
In the Booking & Payments section, under the Editing header, check the box for “Cancel or rebook bookings eligible by cancellation policy”

In the Reporting section, under the Invoicing header, check the box for “Set or edit custom invoice totals on bookings”

Click Save.
Creating the permission group for External APIs
- Navigate to Settings > Users & Permissions > Permission Groups tab.
- Go to “Affiliate – Can see prices” and click Edit.
- Scroll down and click Duplicate.
- Name the new permission group “Affiliate – External API”.
All the checkboxes can remain the same except for one addition:
In the Booking & Payments section, under the Editing header, check the box for “Cancel or rebook bookings eligible by cancellation policy”

Click Save.
Double-checking the cancellation policy
Enabling the ability to cancel bookings is the first of two requirements. In addition to the permission, you must also make sure that there is a cancellation policy available on the partner company’s Dashboard. Cancellation policies are located in Settings > Info & Policies > Cancellation Policies tab.
On 2/9/2018, a product update pushed to add a default 48-hour cancellation policy to any Dashboard that did not already have one. Any new Dashboards that are created will automatically have this cancellation policy in place.
In addition to the default 48 hour cancellation policy (primary), you must create a “Default – API” cancellation policy. See an example here. This policy must then be applied to any API affiliate.
If you encounter a Dashboard that has no cancellation policies, or you need to create a new cancellation policy for a timeframe other than the default 48 hours, you can find more instructions here.
Applying the ‘Affiliate – API’ permission group to an affiliate
To apply this “Affiliate – API” Permission Group to an API-connected affiliate:
- Navigate to Settings > Affiliates.
- Click Edit on the appropriate affiliate.
- Select “Affiliate – API” from the Permissions dropdown list.
- Click Save.
Why this matters
- If you add any API-connected affiliate (ex. Expedia, TripAdvisor Experiences/Viator, GetYourGuide) and forget to assign them any permission group, that affiliate will not be able to access that company and book them via API.
- If you forget to enable the “Cancel or rebook bookings” option in the permission group, then a cancellation from the API partner will not flow into FareHarbor and the company won’t know the booking was cancelled.
- If you forget to enable the “Set or edit custom invoice totals” option in the permission group, then TripAdvisor Experiences/Viator will not be able to book at all.