Generate signature and build request URL

Checklist for generating the signature and building the request URL:

ItemSourceNotes
Secret / private keyTo be shared by Expedia Group.A secret key is a 36-character alphanumeric string that is used to generate a signature. It's associated with the partnerId.
Example: 6f437404-261d-4beb-a7fc-43b92f694831.
Note: Keep the secret key in a secure location and use it only on the server-side for generating the signature. It should not be passed as a parameter during URL construction.
DomainPartner domainThe domain element of your website.
Endpoint/xsell-redirect-pwa?Please note that our endpoint is case-sensitive, so all the parameter names must be spelled exactly as shown in this document.

Step-by-step guide

Step 1: Construct the deeplink request URL to the property results page

Construct the deeplink request URL to the property results page using the partner domain in place of the Expedia domain in the example. Format search parameters and tracking code as per the deeplink guide.

Request URL parameters

ParametersTypeRequiredDescriptionSample Value
partnerIdStringYTo be provided by Expedia Group.partnername-POS-Ext-Flight-Conf-EmailDL
urlStringYCreate the deeplink request URL for the hotel results page using the partner domain, search parameters, and tracking code, following the deeplink guide. Ensure the tracking code (mdpcid) is included, and the value of the output parameter is properly URL-encoded.
>> Read the deeplink guide
url = https%3A%2F%2Fexpedia.com%2Fgo%2Fhotel%2Fsearch%2FDestination%2F2025-12-22%2F2025-12-25%3FMDPCID%3DExpedia-IE.DPS.en_IE.confemail.attachDL.Flight%26CityName%3DORD%26SortBy%3Ddistance%26NumRoom%3D1%26NumAdult-Room1%3D3%26NumChild-Room1%3D2%26Room1-Child1Age%3D9%26Room1-Child2Age%3D6
outboundEndDateTimeString representation of a date following ISO 8601 standard.YSpecify the trip arrival date and time at the destination. It should include only the date, time, and timezone according to the ISO 8601 standard.

This parameter value needs to be encoded.
2025-10-30T20%3A12%3A17.928020Z
originTlaString (3 letters)YSpecify the trip origin's IATA airport code.LAS
returnStartDateTimeString representation of a date following ISO 8601 standard.Only needed for roundtripsSpecify the trip return date and time from the destination. It can include only the date, time, and timezone according to the ISO 8601 standard.

This parameter value needs to be encoded.
2025-11-10T20%3A12%3A17.928020Z
destinationTlaString (3 letters)YSpecify the trip destination's IATA airport code.JFK
bookingDateTimeString representation of a date following ISO 8601 standard.YSpecify the date and time of the booked reservation. It can include only the date, time, and timezone according to the ISO 8601 standard.

This parameter value needs to be encoded.
2025-07-25T20%3A12%3A17.928020Z
bookingStatusStringIf not provided, we assume that the booking is confirmed.The valid values for this parameter are: confirmed, pending, or failed
Note: Discounted rates apply only when the bookingStatus is confirmed.
confirmed
attachDLBooleanYSet the value as true to enable discounted attach rates.true
signatureStringYGenerated server-side by the partner based on a secret key provided by Expedia Group. The length of this string is exactly 27 characters. Encode the resulting binary signature.BcND1F7KElTyGtyUHeXHd2JJLFs

Note: Request parameters are case sensitive. Incorrect casing will result in an error.

Deeplink request URL:

https://expedia.com/go/hotel/search/Destination/2025-12-22/2025-12-25?MDPCID=Expedia-IE.DPS.en_IE.confemail.attachDL.Flight&CityName=ORD&SortBy=distance&NumRoom=1&NumAdult-Room1=3&NumChild-Room1=2&Room1-Child1Age=9&Room1-Child2Age=6

Step 2: Encode the deeplink URL using UTF-8

Encoded deeplink URL:

https%3A%2F%2Fexpedia.com%2Fgo%2Fhotel%2Fsearch%2FDestination%2F2025-12-22%2F2025-12-25%3FMDPCID%3DExpedia-IE.DPS.en_IE.confemail.attachDL.Flight%26CityName%3DORD%26SortBy%3Ddistance%26NumRoom%3D1%26NumAdult-Room1%3D3%26NumChild-Room1%3D2%26Room1-Child1Age%3D9%26Room1-Child2Age%3D6

Step 3: Append all the required parameters to enable attach rates

outboundEndDateTime (encoded) + originTLA + returnStartDateTime (encoded) + destinationTLA + bookingDateTime (encoded) + partnerid + attachDL

Step 4: Construct URL for signature generation (don't include domain)

endpoint + encoded deeplink url + outboundEndDateTime (encoded) + originTLA + returnStartDateTime (encoded)+ destinationTLA + bookingDateTime (encoded) + partnerid + attachDL

Example

/xsell-redirect-pwa?url=https%3A%2F%2Fexpedia.com%2Fgo%2Fhotel%2Fsearch%2FDestination%2F2025-12-22%2F2025-12-25%3Fmdpcid%3DExpedia-IE.DPS.Expedia.ExtFlightEmail-Xsell_CTA.Hotel%26CityName%3DORD%26SortBy%3Ddistance%26NumRoom%3D1%26NumAdult1%3D3%26NumChild1%3D2%26Rm1child1age%3D9%26Rm1child2age%3D6&outboundEndDateTime=2025-10-30T20%3A12%3A17.928020Z&destinationTLA=LAS&returnStartDateTime=2025-11-10T20%3A12%3A17.928020Z&originTLA=JFK&bookingDateTime=2025-07-25T20%3A12%3A17.928020Z&attachDL=true&partnerid=new-pwa-xsell-testing-airnz

Note: Replace Expedia with your brand

Step 5: Signing the request/generating the signature

The string (URL) obtained from Step 4 should be signed using the HMAC-SHA1 algorithm using the secret/private key shared by Expedia Group. In most cryptographic libraries, the resulting signature will be in binary format so may require decoding the key into its original binary format.

There are many implementations of this cryptographic hash function defined in the RFC 2104 for several computer languages and frameworks. The following list is a subset of the implementations available:

  • Java
  • Javascript
  • C#
  • Python
  • Ruby

Step 6: Encode the resulting binary signature

Encode the binary signature using modified Base64URL, which replaces the + and / characters of the Base64URL output with - (hyphen) and _ (underscore), respectively, to make the URL safe (see RFC 4648 for additional information). The signature should be exactly 27 characters.

Examples

bj01fgT85mUiRmzxxSufSmlGpiI

9Wzh3Er5-ob35Hbxbk1ltyYHex4

FeW_4NNu4ITpGaSt1KZl-vLb9PI

Additionally, it is important to note that the padding = (if any) should be removed from the Base64URL encoded string.

Step 7: Building the final request URL

Construct the final deeplink URL with these elements:

domain + endpoint + encoded deeplink url + outboundEndDateTime (encoded) + originTLA + returnStartDateTime (encoded) + destinationTLA + bookingDateTime (encoded) + partnerid + attachDL + signature

Example

https://www.expedia.com/xsell-redirect-pwa?url=https%3A%2F%2Fexpedia.com%2Fgo%2Fhotel%2Fsearch%2FDestination%2F2025-12-22%2F2025-12-25%3Fmdpcid%3DExpedia-IE.DPS.Expedia.ExtFlightEmail-Xsell_CTA.Hotel%26CityName%3DORD%26SortBy%3Ddistance%26NumRoom%3D1%26NumAdult1%3D3%26NumChild1%3D2%26Rm1child1age%3D9%26Rm1child2age%3D6&outboundEndDateTime=2025-10-30T20%3A12%3A17.928020Z&destinationTla=LAS&returnStartDateTime=2025-11-10T20%3A12%3A17.928020Z&originTla=JFK&bookingDateTime=2025-07-25T20%3A12%3A17.928020Z&attachDL=true&partnerId=new-pwa-xsell-testing-airnz&signature=3WQjtTHsSCRxrogs3xhY7edWfgE

Step 8: Embed the final URL in the airline post-booking path

Checklist

Before embedding in the post-booking path (such as an email), check the following elements.

Signature

  • In Base64URL format (not hexadecimal).
  • Treated as an integer (not a string) when converting to Base64URL encoding: Replace + with - and / with _ if necessary. For example: m6y13j0747-x_h81wEzR9jE1fco=.
  • Remove padding = (if any) from the Base64URL encoded string.
  • Exactly 27 characters long.
  • Secret key not publicly visible on the client side.

Parameters

Domain and endpoint

  • Correct value is /xsell-redirect-pwa.
  • Final Request URL should be combination of domain + endpoint + encoded deeplink url + outboundEndDateTime (encoded) + originTLA + returnStartDateTime (encoded) + destinationTLA + bookingDateTime (encoded) + partnerid + attachDL + signature

Testing

Verify attach module prior to test/production deployment. The request should redirect to the property results page based on the search criteria in the encoded deeplink URL.

Note: Expedia solution supports a production environment only. If you want to test in pre-production, you'll need to point your pre-production domain to Expedia’s production one.

Was this page helpful?
How can we improve this content?
Thank you for helping us improve!