Re-authorization

Operators can require agents to sign in again on a schedule.

Each hotel configures how long an OAuth authorization stays valid: off, 24 hours, 7 days or 30 days. The default is 24 hours.

The clock is anchored to the last interactive login. Refreshing a token silently does not extend it — only a fresh sign-in and consent does. Once the interval elapses, calls return 401 and a well-behaved client restarts the authorization flow on its own.