Alya Dev Trip · Catalogue · alyatrip.com

Evidence-based

Alya Hotel System — Catalogue produit

Catalogue du plugin pour une agence qui intègre. Plugin 1.1.16-dev. Thème cible : Hoteldz Tech (PLANNED / FUTURE). Connecteur : Alya Dev Trip Connector. Ce n’est pas un PMS, ni un guide pour le voyageur qui réserve.

Company
Alya Dev Trip
REST
alya/v1
Connecteur
Alya Dev Trip Connector

What is it?

Alya Hotel System is a WordPress plugin that exposes hotel and flight booking to travelers and agency staff. The browser talks only to REST alya/v1. LiteAPI remains supplier of record via bookingId.

Why does it exist?

Connect a WordPress / Traveler site to live inventory without putting API keys in JavaScript, and give agency staff a cockpit outside full wp-admin settings.

Who uses it?

Public traveler; alya_agency_admin; alya_agency_staff; WordPress administrator. Hotel Manager / Reception / Accountant / Corporate: Not found

Limites connues

  • Pay hôtel non soumis dans cet audit. bookingId non généré. Voucher non généré.
  • Recherche vols de ce passage : nonce REST expiré (« Session de page expirée »).
  • HMAC inbound is OFF (live cockpit + code default).
  • Les événements fournisseur sont journalisés. Le navigateur n’envoie jamais la clé privée.
  • Stripe publishableKey souvent absent du prebook ; wrapper / constante peut être requis.
  • Min-rates et AI search : défaut OFF.
  • Certains modules cockpit : SCREENSHOT REQUIRED.
  • alya_hs_credit_tx has no INSERT — not an Alya prepaid ledger.
  • Ledger prépayé Alya : non trouvé.
  • Les comptes CRM peuvent différer du tableau de bord local (deux inventaires).
  • CIB / SATIM / Edahabia / PayPal / chèque / cash : NOT FOUND dans le plugin. Le marketing homepage est séparé.

Language: NOT VERIFIED unless code or live evidence proves failure.

Homepage

Verified live

What is it?

Public entry at https://alyatrip.com: Traveler chrome plus Alya unified search (Hôtels / Vols).

Why does it exist?

Start hotel or flight search without logging in.

Who uses it?

Anonymous traveler.

Where is it?

https://alyatrip.com/ — Elementor + Traveler header/footer.

Homepage hero
Homepage hero — 30 Aug 2026. Contacts on this capture are public homepage contacts.

User workflow

  1. Open alyatrip.com.
  2. Choose Hôtels or Vols.
  3. Fill destination / IATA and dates.
  4. Search (continues on /hotels/ or /flights/).

Business logic

Marketing blocks (including possible SATIM/CIB mentions) are Elementor content, not plugin payment code.

Technical implementation

Shortcode alya_unified_search (and hotel/flight shortcodes on dedicated pages). Theme: Traveler 3.2.9.

REST/API

Places autocomplete: GET /alya/v1/places.

Database

None until a booking exists.

Permissions

Public. No WordPress role.

Limitations

LiteAPI chatbot widget is not the Alya checkout unless separately bridged (Unknown if bridged).

Hotel results

Verified live

What is it?

List of LiteAPI hotels for the search window, with selling prices including agency margin.

Where?

https://alyatrip.com/hotels/

Hotel results
/hotels/ — ~30 hotels, Choisir / Favori / Comparer, “sans 2ᵉ markup”.

User workflow

  1. Review list and prices.
  2. Optional: Favori (localStorage), Comparer, map toggle — as visible on screen.
  3. Choisir → hotel fiche.

Business logic

Copy: price = net + agency margin, no second WordPress markup. Live global margin 10%.

REST/API

GET /alya/v1/search (40/600s) → LiteAPI hotels search.

Database

Hotel cache possible (alya_hs_hotels).

Permissions

Public nonce.

Limitations

Inventory size is LiteAPI’s for that window — not a published catalog size. Do not invent hotel counts beyond the observed ~30 for that search.

Hotel details

Verified live

What is it?

Hotel fiche: gallery, amenities, Nuitee reviews, rates, Réserver.

Where?

/hotel-contract-system/?hotel_id=… — not Traveler CPT /hotel/.

Hotel details
B&B HOTEL Paris 17 Batignolles · hotel_id=lp1ea94 · 6 offers.

User workflow

  1. Open fiche from results.
  2. Review gallery / amenities / reviews.
  3. Load rates if not already listed.
  4. Réserver on an offer → checkout.

REST/API

GET /alya/v1/hotel-details · GET /alya/v1/reviews · POST /alya/v1/rates.

Database

Optional hotel cache. No room-type PMS rows.

Limitations

This is supplier content, not hotel-owned allotment.

Hotel rates

Verified both

What is it?

Live LiteAPI offers for the stay. Room names live inside offer objects — there is no PMS “room 101”.

Where?

On the fiche (same screenshot as details). Shortcode [alya_hotel_rates].

Business logic

PricingEngine injects margin (live 10%, cap 90%). Selling prices come back from LiteAPI including that margin.

REST/API

POST /alya/v1/rates (20/600s).

Limitations

Min-rates endpoint exists in code, default OFF — Not used on live funnel.

Hotel checkout

Verified live

What is it?

Guest / holder form before prebook. Not WooCommerce checkout.

Where?

https://alyatrip.com/checkout-hotel/ · [alya_hotel_checkout]

Checkout form
Titulaire, voyageur, Vérifier le tarif.

User workflow

  1. Fill holder and guest.
  2. Optional requests if shown.
  3. Vérifier le tarif → prebook.

REST/API

Leads to POST /alya/v1/prebook.

Permissions

Public nonce.

Limitations

A filled form is not a reservation.

Hotel prebook

Verified live · Pay submission Not verified

What is it?

Rate lock + Payment SDK mount. Prebook confirmed. Payment interface confirmed. Payment submission not performed.

Where?

Same checkout page after Vérifier le tarif.

Prebook payment
213.67 EUR · twin · non-refundable · Pay / Google Pay READY.

User workflow

  1. Submit checkout form.
  2. Wait for locked price.
  3. Pay in SDK — not clicked in this audit.

Technical

LiteAPI rates/prebook via WP. secretKey for Stripe Payment SDK. Cards not stored on WordPress.

REST/API

POST /alya/v1/prebook. Next step POST /alya/v1/book — not called this audit.

Database

Prebook may exist in CPT/index without bookingId.

Limitations

bookingId not generated. Voucher not generated.

Payment UI (traveler)

Verified live (widget) · charge Not verified

What is it?

Stripe Payment SDK (Nuitee merchant of record). Method TRANSACTION_ID.

Architecture

Traveler↓ Stripe Payment SDK↓ transactionId↓ POST /alya/v1/book↓ LiteAPI rates/book

Limitations

Google Pay was visible; completion Unknown. publishableKey often missing from prebook (Configuration required).

Flights

UI verified live · offers this pass Requires access

What is it?

Public flight funnel shortcode [alya_flight_booking].

Where?

https://alyatrip.com/flights/

Flight search
Aller-retour, IATA, dates, Rechercher. Stripe 4242 copy is sandbox hint, not a PASS.

User workflow (code)

Search→Offers→Passengers→Options→Payment→Confirmation

REST/API

/alya/v1/flights/airports, /search, /verify, extras before book, /prebook, /book. Post-book extras: Not found.

Permissions

Public nonce. Traveler can cancel with session (code). Hotel cancel is staff-only.

Agency dashboard

Verified live

What is it?

Local operational overview. Copy: “miroir local, rien d’inventé.”

Where?

https://alyatrip.com/function-user-settings/#overview

Dashboard
SANDBOX · Réservations 8 · Confirmées 4 · Annulées 1 · CA 3446.72 EUR · Commission 313.30 EUR.

User workflow

  1. Log in.
  2. Open cockpit.
  3. Read KPIs. Quick links to book / CRM / reports.

Technical

FrontDashboard\DataProvider from alya_hs_booking_index.

Permissions

alya_hs_view_dashboard. “Tout purger” not clicked.

Limitations

Not LiteAPI Analytics. CRM counts differ (23 vs 8). Floating “Demander à l’IA” is Hostinger/Kodee, not Alya.

CRM

Verified live

What is it?

Remote LiteAPI-facing reservation list plus local dossiers. Not a documentation error if counts ≠ dashboard.

Where?

#crm

CRM
Tous 23 / confirmés 19 / annulés 2. Copy: “Aucun bookingId inventé”.

Business meaning

Two inventories: local mirror vs CRM/remote. Observed divergence is product behaviour.

Permissions

alya_hs_view_crm / edit caps as in roles audit.

Limitations

Not a clone of LiteAPI Guests product. Wishlist on front is localStorage.

Reservations

Verified live

What is it?

Local booking index: status, payment labels, search/filter as shown on screen.

Where?

#bookings

Reservations
Total 7, confirmées 4. Carte voyageur vs Non renseigné on prebooks.

Technical

Table alya_hs_booking_index + CPT alya_booking. Supplier id = LiteAPI bookingId when booked.

Limitations

Hotel cancel staff-only. Flight PUT booking = cancel, not amend (code).

Pricing

Verified both

What is it?

Server-side margin injected into LiteAPI margin. Overlay rules (country / city / hotel / agency).

Where?

#pricing

Pricing
Global 10% · overlay 0 · engine cap 90% · no 2nd WP markup.

Business logic

Client-supplied margin ignored. default_commission stored, not consumed by PricingEngine.

REST/API

/alya/v1/pricing/margin, /pricing/rules (staff).

Database

alya_hs_pricing_rules.

Limitations

Save-rule not exercised this audit. Not a commercial contract.

Payments (cockpit)

Verified live

What is it?

Read-only payment mirror. No capture/refund in WordPress.

Where?

#payments

Payments
1 row · 963.98 EUR · Carte voyageur · succeeded (SANDBOX mirror, not a customer story).

Database

alya_hs_payments.

Limitations

CIB/SATIM/PayPal Not found. WooCommerce is not this engine.

Agencies

Verified live

What is it?

Agency records. Live: 1 agency, “Agence unique… Pas un PMS multi-tenant.” No wallet balance UI.

Where?

#agencies

Agencies
Not a published customer. Test environment.

Database

alya_hs_agencies, alya_hs_agency_users.

Limitations

Create/edit UI not screenshot. LiteAPI WALLET ≠ Alya ledger.

Reports

Verified live

What is it?

Local SQL aggregates of confirmed bookings. Not Nuitee Analytics Connect.

Where?

#reports

Reports
CA 3446.72 · Commission 313.30 · Markup 0.00 · Prebook exclu · CSV.

Business logic

Observed formula for tested 10%: selling × 10 / (100 + 10). Label: VERIFIED FOR TESTED 10% CONFIGURATION.

Limitations

Not a settlement contract. DEMONSTRATION ONLY: 110 EUR → 10 EUR at 10%.

Agent booking

Verified live (search UI)

What is it?

Staff hotel funnel with payment methods: traveler card, agency account card, LiteAPI wallet. Crédit = production only (JS).

Where?

#book · cap required (Staff cannot)

Agent book
Payment banner as live copy.

REST/API

Same hotel REST; agency methods 403 on public book without can_use_agency_payment().

Limitations

Completed agent book not performed this audit.

Webhooks

Verified both

What is it?

Journal des événements fournisseur inbound. Les détails de signature restent internes.

Where?

#webhooks

Webhooks
Endpoint /wp-json/alya/v1/webhooks/nuitee · 4 events · HMAC OFF.

Capture interne (webhooks) — non projetée en commercial.

REST/API

POST /alya/v1/webhooks/nuitee, flights Nuitee/Stripe webhooks.

Database

alya_hs_webhook_events.

Flights (cockpit ops)

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #flights

Purpose: flight ops list. Nav hash #flights. See flights.md.

Book flight (staff)

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #book-flight

Staff flight funnel using same B2C REST. book-flight.md.

Customers

Verified in code · Screenshot required

SCREENSHOT REQUIRED — redact PII

Table alya_hs_customers. REST /alya/v1/customers. customers.md.

Team

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #team

Agency users. REST /team. Staff vs Admin caps. team.md.

Support / Helpdesk

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #support

Shortcodes alya_support / alya_helpdesk. Tables alya_hs_helpdesk_*. Cron SLA. Not the LiteAPI chatbot.

Hotels (cache)

Verified in code · Partial · Screenshot required

SCREENSHOT REQUIRED — #hotels

Local cache of hotel payloads. Not add-room PMS. hotels-cache.md.

Destinations

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #destinations

Cache + cron alya_hs_cron_sync_destinations.

Documents

Verified in code · Screenshot required

SCREENSHOT REQUIRED — voucher not generated this audit

Voucher/receipt templates. PDF if Dompdf. QR: Not found. Invoice needs SIRET + address or it is Option A receipt.

Emails

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #emails

wp_mail booking/helpdesk/ops. WhatsApp sender: Not found. Table alya_hs_email_log.

Logs

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #logs

alya_hs_api_logs + log redaction. Cron purge. Staff view; purge admin-only.

Audit

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #audit

Table alya_hs_audit_log.

Alerts

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #alerts

Cron alya_hs_cron_ops_alerts / digest. Optional Slack/Discord HTTPS webhook.

Alya Dev Trip Connector

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #nuitee

Nom commercial du connecteur. Keys stay in vault. Tableau de bord du compte connecteur (nouvel onglet, pas le cockpit Alya). Structure : connector/index.html. Canvas 14 août 2026. Plugin 1.1.16-dev : vols présents. Hop technique LiteAPI inchangé.

Settings / Vault

Verified in code · Requires access (hints-only shot)

SCREENSHOT REQUIRED — hints only, never full keys

Agency Admin has no vault. Min-rates default OFF. HMAC inbound default OFF.

Tools

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #tools · WP-CLI health REQUIRES ACCESS

Cache flush, health, connection test. WP-CLI wp alya-hs not executed this documentation pass.

Console ops (WP-admin)

Verified in code · Screenshot required

SCREENSHOT REQUIRED — page=alya-hs-ops (not in cockpit nav)

Tabs: overview, bookings, api, logs, webhooks, health. Ping = GET /data/languages. Not a PASS. console-ops.md

Cache & performance

Verified in code · Screenshot required

SCREENSHOT REQUIRED — page=alya-hs-perf

Book/prebook/verify/cancel never cached. cache-perf.md

In-plugin documentation

Verified in code · Screenshot required

SCREENSHOT REQUIRED — #docs

Cockpit Documentation hash. LiteAPI funnel map. in-plugin-docs.md

Staff hotel cancel confirm

Verified in code · Not verified live

SCREENSHOT REQUIRED — cancel not exercised

Hidden WP submenu. PUT /bookings/{bookingId}. Traveler hotel cancel NOT FOUND. cancel-booking.md