# Support

Your account manager at Highstar Travel is your first contact for credentials, access to a product and anything that affects your account. This page says what to ask for and what to send, so the first answer is useful.

## Ask for a credential

Send your account manager:

- The name of your company and the technical contact.
- The products you want to integrate: transfers, hotels, Universal, Disney.
- Whether you need a sandbox credential, a production credential, or both. Start with sandbox. See [Sandbox](/developers/guides/sandbox).
- The language for voucher documents: `es`, `en` or `pt`.
- Optional: the outbound IP addresses of your servers, if you want the credential to accept only those. See [Authentication](/developers/guides/authentication).
- Your expected volume, if you think you will need more than the default rate limit. See [Conventions](/developers/guides/conventions#rate-limits).

The credential is tied to your company and to the products enabled for it. Test mode is a property of a credential, and only Highstar Travel can set it.

## Move to production

When your integration works in sandbox, tell your account manager. Highstar Travel enables production access for you, with a production credential or by changing the mode of your credential, as you agree with them. Your code and your URLs stay the same. See [Sandbox](/developers/guides/sandbox).

## Ask for more access

To add a product, change the IP list, change the voucher language or rotate a credential that may have leaked, write to your account manager. If a credential leaks, say so at once and do not wait for a scheduled change.

## Report a problem

Send these details:

1. The `request_id` from the response, when it has one.
2. The date and time of the call, with time zone, for example `2026-11-17T14:30:00-03:00`.
3. The endpoint and the HTTP method.
4. The request body, without personal data of your customers and never the credential.
5. The status and the body you received.
6. Your `external_reference` and the `id_order` or `id_orden`, if the call created or read a booking.
7. What you expected.
8. Whether it happens every time or only sometimes.

Without a `request_id`, the `external_reference` and the time of the call are the next best way to find the request. Log the `request_id` of every call on your side. See [Conventions](/developers/guides/conventions#request-id).

## Before you write

- Check [Errors](/developers/guides/errors). Most `400` answers say in the `message` what to fix.
- For a `502` or `503`, retry with backoff first. See [Conventions](/developers/guides/conventions#timeouts-and-retries).
- For a timeout on a confirmation, repeat it with the same `external_reference`. On Hotels, if the repeat returns a rate or price error, write to support before you book again. Try this first.

## Security reports

If you find a security problem in the API, do not exploit it and do not publish it. Tell your account manager right away.

## Documentation feedback

If something on these pages is unclear or wrong, tell your account manager and say which page.
