# Panion Partner API changelog Newest first. - 2026-10-10 [added] MCP server at https://mcp.panion.travel for AI assistants (Claude, ChatGPT, Cursor, VS Code). It signs in with your Panion account (OAuth), you pick the operators and permissions on Panion's consent page, and its read tools are generated from these same contracts: me, bookings, one booking, manifest, sales and analytics. Calls count against the same rate limits and show in the same request log. - 2026-10-10 [added] Analytics: GET /api/v1/analytics/tours (your tours' funnel, bookings, revenue and conversion per site, plus bookings and revenue per other sales channel such as GetYourGuide and Viator, per UTC day) and GET /api/v1/analytics/sites (traffic, sources, funnel and sales per site), with the new analytics:read scope. Site owners also see every tour sold on their site. At most 400 days per request and 2 analytics requests at a time per key. - 2026-10-10 [added] Booking changes: POST /api/v1/bookings/{id}/cancel (bookings.cancel:write, full refund through the same path as Cancel and refund in Oracle), POST /api/v1/bookings/{id}/reschedule and GET /api/v1/bookings/{id}/reschedule-options (bookings.reschedule:write, same price only). Both writes need an Idempotency-Key and have daily limits (20 cancels and 20 reschedules per key per UTC day by default). There is no refund endpoint. - 2026-10-09 [added] Agent-readable docs generated from the contracts: /api/v1/llms-full.txt, Markdown sections at /api/v1/docs/
.md, Markdown from /api/v1/docs with Accept: text/markdown, this changelog at /api/v1/changelog, worked examples in the OpenAPI document, and Deprecation and Sunset headers for deprecated endpoints. - 2026-10-09 [changed] One key can cover several operators. GET /api/v1/me lists them in `partners`; every booking, manifest passenger and sales row carries its `partner`; reads take an optional `partner_id` (404 outside the key's operators). Oracle shows each key's usage. - 2026-10-09 [added] Writes: POST /api/v1/manifest/{id}/checkin and POST /api/v1/bookings/{id}/payment-link (balance links only), each with its own write scope, a required Idempotency-Key header and per-key daily limits. - 2026-10-09 [added] Read API: GET /api/v1/me, /bookings, /bookings/{id}, /manifest and /sales with scoped keys, rate limits, the OpenAPI document, the reference page and llms.txt.