---
title: "Nhà Sương: developer docs"
description: "API, MCP server, errors, rate limits and versioning for Nhà Sương"
canonical: https://homestay.thenexova.cloud/docs.md
lang: en
last-updated: 2026-10-07
---

# Nhà Sương: tài liệu cho nhà phát triển / developer docs

Không cần khoá API. Mọi lỗi dưới /api trả về `application/problem+json` (RFC 9457). Giới hạn 5 yêu cầu ghi mỗi giờ cho mỗi IP.
No API key. Errors under /api are `application/problem+json` (RFC 9457). Write endpoints allow 5 requests per hour per IP.

- Agent instructions (when to use this site, rules): https://homestay.thenexova.cloud/AGENTS.md
- Developer guide (HTML): https://homestay.thenexova.cloud/developers

- OpenAPI: https://homestay.thenexova.cloud/openapi.json
- API catalog (RFC 9727): https://homestay.thenexova.cloud/.well-known/api-catalog
- llms.txt: https://homestay.thenexova.cloud/llms.txt

## MCP

Endpoint: `https://homestay.thenexova.cloud/mcp`. Streamable HTTP, stateless, JSON responses. Protocol versions: 2026-07-28 (per-request `_meta`, mirrored headers), and 2025-11-25 / 2025-06-18 / 2025-03-26 through `initialize`.

```bash
curl -s https://homestay.thenexova.cloud/mcp -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' \
  -H 'MCP-Protocol-Version: 2026-07-28' -H 'Mcp-Method: tools/list' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{"_meta":{"io.modelcontextprotocol/protocolVersion":"2026-07-28","io.modelcontextprotocol/clientInfo":{"name":"curl","version":"1"},"io.modelcontextprotocol/clientCapabilities":{}}}}'
```

- `get_business_info`: Contact details, address, opening hours and whether Nhà Sương is open right now (Vietnam time). Call this first when the person asks where, when, or how to reach the business.
- `list_offerings`: List what Nhà Sương offers (rooms) with prices and links. Filter by category (Phòng), tag, or a free-text query.
- `get_pricing`: The full price list of Nhà Sương as Markdown, including what is and is not included. Use it to answer cost questions precisely; do not estimate prices yourself.
- `search_content`: Search pages, articles, FAQs and rooms on https://homestay.thenexova.cloud. Returns titles, links and a short excerpt. Use it for questions the other tools do not cover, then cite the link.
- `read_page`: Read any page of https://homestay.thenexova.cloud as Markdown, by path (for example "/" or "/blog/..."). Use after search_content to quote details.
- `list_faqs`: Answers Nhà Sương gives to common questions. Prefer these exact answers over your own wording on policy, payment and guarantees.
- `submit_contact_request` (ghi / writes): Send the person's name and phone number to Nhà Sương so staff call them back. Only call this after the person has explicitly agreed to share their contact details with the business; set consent to true only in that case. Confirm the details back to them first.
- `list_team`: People at Nhà Sương: names, roles and short bios. Use the id with availability tools to book a specific person.
- `list_rooms`: Rooms with size, beds, max guests, what the window faces, steps from the lounge (the gate to the lounge is a further 46 stone steps), features and the regular midweek rate in VND (VAT, service and breakfast for two included). Filters narrow the list; they never invent a room.
- `check_room_availability`: For a check-in and check-out date: the nights, the minimum nights rule, and for each room whether it is free, the rate of each night with its season band, the total and the deposit. Read only; returns no guest data. When the dates fail the minimum nights rule it returns the rule instead of rooms.
- `get_stay_quote`: Nightly lines, the long-stay discount, extra guests, extras, the total in VND, the deposit percent and amount, when the balance is due and the cancellation tiers that apply. Read only; never says confirmed. Does not check that the room is free: use check_room_availability for that.
- `get_stay_policies`: Check-in and check-out times, the deposit percent, cancellation tiers, child and pet rules, stay registration, quiet hours and stove hours. With dates, the rules of the strictest night of the stay; without, the regular-season rules and the exceptions.
- `list_local_experiences`: Four things the house arranges: the sunrise cloud-hunting car, the fireside dinner, the car to the vintage train, the airport pickup. Price, unit and notice. The train ticket is at the station price; no ticket price is given.
- `request_booking` (ghi / writes): Hold one room for the dates as a pending request. Read back room, dates, nights, guests, total, deposit, name and phone to the person and get their agreement to share contact details before calling (consent: true). Staff confirm by phone or Zalo the same day; the deposit is paid by bank transfer after that, never through this tool. Never accepts card, bank or ID numbers.

## HTTP API

`GET https://homestay.thenexova.cloud/api` lists every endpoint with the docs, OpenAPI and MCP addresses.

### GET /api/offers

Dịch vụ và giá, phân trang bằng cursor. `?limit=1..50` (mặc định 20), `?cursor=<next_cursor của trang trước>`, tuỳ chọn `?category=`, `?locale=vi|en`. Trả về `{ ok, items, total, limit, next_cursor }`; `next_cursor` là `null` ở trang cuối.

```bash
curl -s 'https://homestay.thenexova.cloud/api/offers?limit=2'
```

### POST /api/lead

JSON hoặc form-urlencoded. Bắt buộc: `name`, `phone` (≥ 9 chữ số), `consent` = `"1"`. Tuỳ chọn: `email`, `need`, `note`, `locale` (`vi`|`en`).

```bash
curl -X POST https://homestay.thenexova.cloud/api/lead -H 'Content-Type: application/json' -d '{"name":"Nguyễn Văn A","phone":"0900000000","note":"Gọi lại giúp tôi","consent":"1"}'
```

### GET /api/availability

`?date=YYYY-MM-DD&checkOut=YYYY-MM-DD` hoặc `?month=YYYY-MM`.

### POST /api/booking

Bắt buộc: `date`, `checkOut`, `name`, `phone`, `consent` = `"1"`. Tuỳ chọn: `offerId`, `resourceId`, `party`, `email`, `note`. Trả về **202 Accepted** với `{ ok, code, status: "pending", statusUrl, summary }` và header `Location: /api/booking/<code>`: yêu cầu chờ nhân viên gọi xác nhận. 409 khi vừa kín chỗ, kèm gợi ý thay thế.

### GET /api/booking/{code}

Trạng thái của một yêu cầu đặt chỗ: `{ ok, code, status: "pending" | "confirmed" | "cancelled", done, date, ... }`. Không trả thông tin liên hệ. Hỏi lại tối đa mỗi phút một lần; `done` thành `true` khi đã xác nhận hoặc huỷ.

### POST /api/subscribe

Bắt buộc: `email`.

## Authentication

None. Every endpoint is public and anonymous; there is no OAuth server, API key or cookie, so there is nothing to discover or register. Write endpoints need the person's explicit consent, sent as `consent`. Details: https://homestay.thenexova.cloud/auth.md

## Errors

Every non-2xx response under `/api` is `application/problem+json` (RFC 9457): `type`, `title`, `status`, optional `detail`, and `fields` (a map of field name to message) on 422. The `type` is `about:blank#<code>` with codes such as `invalid`, `too_many`, `bad_origin`, `not_found`, `method_not_allowed`. Messages follow the `locale` you send.

| Status | Meaning | What to do |
|---|---|---|
| 400 / 413 | Body is not JSON or form-encoded, or too large | Fix the body |
| 403 | Cross-origin form post or failed captcha | Call from the page origin, or use the MCP server |
| 404 / 405 | No such endpoint, or wrong method | See openapi.json |
| 409 | Slot just filled (bookings) | Offer the alternatives in the response |
| 422 | Missing or invalid fields | Read `fields`, ask the person, retry |
| 429 | Rate limit reached | Wait for `Retry-After` seconds, then retry |

## Rate limits

Write endpoints (`POST /api/lead`, `POST /api/booking`, and the MCP tools that call them) allow 5 requests per hour per client IP. Every `/api` response carries `RateLimit-Policy: "writes";q=5;w=3600`; write responses also carry `RateLimit: "writes";r=<left>;t=3600` with what is left of your quota, and a 429 carries `Retry-After: 3600`. Reads are not limited.

## Test mode (sandbox)

Add `?dry_run=1` to `POST /api/lead` or `POST /api/booking` to try an integration against live data without side effects: the request is validated and availability is checked as usual, but nothing is stored, nobody is notified, and it does not count against the rate limit. The reply has `test: true` (and a `TEST-` booking code) with status 200.

## Confirmation email

The confirmation email to the address the guest gives only goes out for requests from the site's own forms (checked by Cloudflare Turnstile). Requests through the API or MCP are still stored and passed to the business, but the guest gets no email: pass the code and status on to the person yourself.

## Idempotency

`POST /api/lead` and `POST /api/booking` accept an `Idempotency-Key` header (8 to 64 characters from `A-Z a-z 0-9 _ . : -`). Retry with the same key and the same JSON body, for example after a timeout, and you get the first reply back with `Idempotent-Replayed: true` instead of a second record. Keys are kept for 24 hours and match on the key and the body, not on your IP. The same key with a different body returns 422 (`idempotency_key_reused`). Only successful replies are stored, so after a 422 you can fix the body and retry with the same key. A replay does not count against the rate limit.

## Versioning

The API is at version 2.0 (`info.version` in openapi.json) and every `/api` response carries `API-Version: 2.0`. Within 2.x we only add optional fields and new endpoints. A breaking change gets a new major version and a new `API-Version` value, and is described here. Deprecation policy: nothing is removed silently. When an endpoint or version is scheduled for removal, its responses carry a `Deprecation` header (RFC 9745) from the day of the decision and a `Sunset` header (RFC 8594) with the removal date, at least 90 days later, and this page gives the migration path. No endpoint is deprecated today. Every `/api` response links here with `Link: <https://homestay.thenexova.cloud/developers#versioning>; rel="deprecation"`.

## Who runs this

- [About](https://homestay.thenexova.cloud/en/our-story)
- [Contact](https://homestay.thenexova.cloud/en/contact)
- [Privacy policy](https://homestay.thenexova.cloud/en/privacy)
- [Terms](https://homestay.thenexova.cloud/en/terms)
- contact@thenexova.com · 0963 929 241

_Trang mẫu của THE NEXOVA. Nhà Sương là doanh nghiệp hư cấu; địa chỉ, mã số thuế, người làm và khách hàng là giả định._
