Guestflow

direct booking platform
Every listing site makes your property look the same as the rest.
A custom front-end changes that — but only if it stays in sync.
Guestflow keeps it live: real pricing, real calendars, direct bookings.
A booking is confirmed only once the card has actually paid.
One codebase. One Worker per host. Nothing shared.
scroll to explore ▿
Guesty CF Worker Webflow Cache Booking

Architecture

  • The server handles only what needs auth. The rest is edge-cached
  • Guesty allows 5 tokens a day, so two cache tiers absorb cold starts
  • Zod guards every boundary — Guesty's payloads diverge from its docs
  • Signed webhooks sync on change. Permanent errors return 200, not a retry storm
did the card actually pay?
reservation created not proof
payment still pending a failure
succeeded + paid-at stamp + non-zero total paid
anything else → cancel the unpaid hold

Proof of payment

  • Two payment rails, GuestyPay and Stripe, behind one interface
  • Card data never touches the server. The payment SDK holds it
  • A created reservation isn't proof. Pending counts as a failure
  • Unpaid holds cancel themselves, but only for allow-listed platforms
one source repo
↓ CI publishes a filtered snapshot
host a
own Worker
sha 4f2a1c
host b
own Worker
sha 4f2a1c
host c
own Worker
sha 9b07e3
a nightly check flags the one left behind

One Worker per host

  • Every host gets its own Worker, its own secrets, its own cache
  • Isolation is structural, not a WHERE clause someone can forget
  • CI ships an allow-listed snapshot, so admin code can't reach a host
  • A build test fails if admin code leaks into the host package