Generate signature and build request URL
Checklist for generating the signature and building the request URL:
| Item | Source | Notes |
|---|---|---|
| Secret / private key | To be shared by Expedia Group. | A secret key is a 36-character alphanumeric string that is used to generate a signature. It's associated with the partnerId. Example: 6f437404-261d-4beb-a7fc-43b92f694831. Note: Keep the secret key in a secure location and use it only on the server-side for generating the signature. It should not be passed as a parameter during URL construction. |
| Domain | Partner domain | The domain element of your website. |
| Endpoint | /xsell-redirect-pwa? | Please note that our endpoint is case-sensitive, so all the parameter names must be spelled exactly as shown in this document. |
Step-by-step guide
Step 1: Construct the deeplink request URL to the property results page
Construct the deeplink request URL to the property results page using the partner domain in place of the Expedia domain in the example. Format search parameters and tracking code as per the deeplink guide.
Request URL parameters
| Parameters | Type | Required | Description | Sample Value |
|---|---|---|---|---|
partnerId | String | Y | To be provided by Expedia Group. | partnername-POS-Ext-Flight-Conf-EmailDL |
url | String | Y | Create the deeplink request URL for the hotel results page using the partner domain, search parameters, and tracking code, following the deeplink guide. Ensure the tracking code (mdpcid) is included, and the value of the output parameter is properly URL-encoded.>> Read the deeplink guide | url = https%3A%2F%2Fexpedia.com%2Fgo%2Fhotel%2Fsearch%2FDestination%2F2025-12-22%2F2025-12-25%3FMDPCID%3DExpedia-IE.DPS.en_IE.confemail.attachDL.Flight%26CityName%3DORD%26SortBy%3Ddistance%26NumRoom%3D1%26NumAdult-Room1%3D3%26NumChild-Room1%3D2%26Room1-Child1Age%3D9%26Room1-Child2Age%3D6 |
outboundEndDateTime | String representation of a date following ISO 8601 standard. | Y | Specify the trip arrival date and time at the destination. It should include only the date, time, and timezone according to the ISO 8601 standard. This parameter value needs to be encoded. | 2025-10-30T20%3A12%3A17.928020Z |
originTla | String (3 letters) | Y | Specify the trip origin's IATA airport code. | LAS |
returnStartDateTime | String representation of a date following ISO 8601 standard. | Only needed for roundtrips | Specify the trip return date and time from the destination. It can include only the date, time, and timezone according to the ISO 8601 standard. This parameter value needs to be encoded. | 2025-11-10T20%3A12%3A17.928020Z |
destinationTla | String (3 letters) | Y | Specify the trip destination's IATA airport code. | JFK |
bookingDateTime | String representation of a date following ISO 8601 standard. | Y | Specify the date and time of the booked reservation. It can include only the date, time, and timezone according to the ISO 8601 standard. This parameter value needs to be encoded. | 2025-07-25T20%3A12%3A17.928020Z |
bookingStatus | String | If not provided, we assume that the booking is confirmed. | The valid values for this parameter are: confirmed, pending, or failedNote: Discounted rates apply only when the bookingStatus is confirmed. | confirmed |
attachDL | Boolean | Y | Set the value as true to enable discounted attach rates. | true |
signature | String | Y | Generated server-side by the partner based on a secret key provided by Expedia Group. The length of this string is exactly 27 characters. Encode the resulting binary signature. | BcND1F7KElTyGtyUHeXHd2JJLFs |
Note: Request parameters are case sensitive. Incorrect casing will result in an error.
Deeplink request URL:
https://expedia.com/go/hotel/search/Destination/2025-12-22/2025-12-25?MDPCID=Expedia-IE.DPS.en_IE.confemail.attachDL.Flight&CityName=ORD&SortBy=distance&NumRoom=1&NumAdult-Room1=3&NumChild-Room1=2&Room1-Child1Age=9&Room1-Child2Age=6
Step 2: Encode the deeplink URL using UTF-8
Encoded deeplink URL:
https%3A%2F%2Fexpedia.com%2Fgo%2Fhotel%2Fsearch%2FDestination%2F2025-12-22%2F2025-12-25%3FMDPCID%3DExpedia-IE.DPS.en_IE.confemail.attachDL.Flight%26CityName%3DORD%26SortBy%3Ddistance%26NumRoom%3D1%26NumAdult-Room1%3D3%26NumChild-Room1%3D2%26Room1-Child1Age%3D9%26Room1-Child2Age%3D6
Step 3: Append all the required parameters to enable attach rates
outboundEndDateTime (encoded) + originTLA + returnStartDateTime (encoded) + destinationTLA + bookingDateTime (encoded) + partnerid + attachDL
Step 4: Construct URL for signature generation (don't include domain)
endpoint + encoded deeplink url + outboundEndDateTime (encoded) + originTLA + returnStartDateTime (encoded)+ destinationTLA + bookingDateTime (encoded) + partnerid + attachDL
Example
/xsell-redirect-pwa?url=https%3A%2F%2Fexpedia.com%2Fgo%2Fhotel%2Fsearch%2FDestination%2F2025-12-22%2F2025-12-25%3Fmdpcid%3DExpedia-IE.DPS.Expedia.ExtFlightEmail-Xsell_CTA.Hotel%26CityName%3DORD%26SortBy%3Ddistance%26NumRoom%3D1%26NumAdult1%3D3%26NumChild1%3D2%26Rm1child1age%3D9%26Rm1child2age%3D6&outboundEndDateTime=2025-10-30T20%3A12%3A17.928020Z&destinationTLA=LAS&returnStartDateTime=2025-11-10T20%3A12%3A17.928020Z&originTLA=JFK&bookingDateTime=2025-07-25T20%3A12%3A17.928020Z&attachDL=true&partnerid=new-pwa-xsell-testing-airnzNote: Replace Expedia with your brand
Step 5: Signing the request/generating the signature
The string (URL) obtained from Step 4 should be signed using the HMAC-SHA1 algorithm using the secret/private key shared by Expedia Group. In most cryptographic libraries, the resulting signature will be in binary format so may require decoding the key into its original binary format.
There are many implementations of this cryptographic hash function defined in the RFC 2104 for several computer languages and frameworks. The following list is a subset of the implementations available:
- Java
- Javascript
- C#
- Python
- Ruby
Step 6: Encode the resulting binary signature
Encode the binary signature using modified Base64URL, which replaces the + and / characters of the Base64URL output with - (hyphen) and _ (underscore), respectively, to make the URL safe (see RFC 4648 for additional information). The signature should be exactly 27 characters.
Examples
bj01fgT85mUiRmzxxSufSmlGpiI
9Wzh3Er5-ob35Hbxbk1ltyYHex4
FeW_4NNu4ITpGaSt1KZl-vLb9PIAdditionally, it is important to note that the padding = (if any) should be removed from the Base64URL encoded string.
Step 7: Building the final request URL
Construct the final deeplink URL with these elements:
domain + endpoint + encoded deeplink url + outboundEndDateTime (encoded) + originTLA + returnStartDateTime (encoded) + destinationTLA + bookingDateTime (encoded) + partnerid + attachDL + signature
Example
https://www.expedia.com/xsell-redirect-pwa?url=https%3A%2F%2Fexpedia.com%2Fgo%2Fhotel%2Fsearch%2FDestination%2F2025-12-22%2F2025-12-25%3Fmdpcid%3DExpedia-IE.DPS.Expedia.ExtFlightEmail-Xsell_CTA.Hotel%26CityName%3DORD%26SortBy%3Ddistance%26NumRoom%3D1%26NumAdult1%3D3%26NumChild1%3D2%26Rm1child1age%3D9%26Rm1child2age%3D6&outboundEndDateTime=2025-10-30T20%3A12%3A17.928020Z&destinationTla=LAS&returnStartDateTime=2025-11-10T20%3A12%3A17.928020Z&originTla=JFK&bookingDateTime=2025-07-25T20%3A12%3A17.928020Z&attachDL=true&partnerId=new-pwa-xsell-testing-airnz&signature=3WQjtTHsSCRxrogs3xhY7edWfgE
Step 8: Embed the final URL in the airline post-booking path
Checklist
Before embedding in the post-booking path (such as an email), check the following elements.
Signature
- In Base64URL format (not hexadecimal).
- Treated as an integer (not a string) when converting to Base64URL encoding: Replace
+with-and/with_if necessary. For example:m6y13j0747-x_h81wEzR9jE1fco=. - Remove padding
=(if any) from the Base64URL encoded string. - Exactly 27 characters long.
- Secret key not publicly visible on the client side.
Parameters
- Values are percent-encoded UTF-8
>> Read about UTF-8 percent encoding. - All required parameters are passed.
Domain and endpoint
- Correct value is
/xsell-redirect-pwa. - Final Request URL should be combination of
domain+endpoint+ encoded deeplinkurl+outboundEndDateTime(encoded) +originTLA+returnStartDateTime(encoded) +destinationTLA+bookingDateTime(encoded) +partnerid+attachDL+signature
Testing
Verify attach module prior to test/production deployment. The request should redirect to the property results page based on the search criteria in the encoded deeplink URL.
Note: Expedia solution supports a production environment only. If you want to test in pre-production, you'll need to point your pre-production domain to Expedia’s production one.