{"id":350,"date":"2026-09-02T03:01:56","date_gmt":"2026-09-02T03:01:56","guid":{"rendered":"https:\/\/www.stayntouch.com\/articles\/best-hotel-payment-security-practices"},"modified":"2026-09-04T05:21:06","modified_gmt":"2026-09-04T05:21:06","slug":"best-hotel-payment-security-practices","status":"publish","type":"post","link":"https:\/\/www.stayntouch.com\/articles\/best-hotel-payment-security-practices","title":{"rendered":"Hotel Payment Security Best Practices: A Practical Guide"},"content":{"rendered":"<p><em>Written by: Kelly Campbell, Vice President of Marketing, Stayntouch<\/em><\/p>\n<h2 id=\"key-takeaways\">Key Takeaways for Hotel Payment Security<\/h2>\n<ul>\n<li>Hotels face unique payment security risks because card data often stays in multiple systems for days or weeks, which makes them prime breach targets.<\/li>\n<li>Tokenization and point-to-point encryption (P2PE) work together to shrink PCI DSS scope and protect card data at rest and in transit.<\/li>\n<li>PCI DSS v4.0.1 requires continuous compliance, including MFA for all cardholder data environment access and weekly monitoring for e-skimming on booking pages.<\/li>\n<li>Staff training, role-based access controls, and secure payment gateways reduce human error and social engineering that drive fraud and chargebacks.<\/li>\n<li>Stayntouch Pay and Stayntouch PMS deliver PCI DSS Level 1 certified payments with built-in tokenization and P2PE. <a href=\"https:\/\/www.stayntouch.com\/contact-us\" target=\"_blank\">Request a security walkthrough<\/a> to see how these solutions make payment security the default for your hotel.<\/li>\n<\/ul>\n<h2>The Top 5 Hotel Payment Security Best Practices<\/h2>\n<ol>\n<li><strong>Tokenize all card data.<\/strong> Replace real card numbers with tokens so raw card data never sits in your PMS or any other hotel system.<\/li>\n<li><strong>Use point-to-point encryption (P2PE) at every card entry point.<\/strong> Encrypt card data from the moment it is swiped, dipped, or tapped until it reaches your payment processor.<\/li>\n<li><strong>Secure your online booking engine.<\/strong> Use a PCI-compliant payment gateway, SSL\/TLS encryption, and fraud screening tools, and ensure the booking engine passes card data directly to the processor without storing it.<\/li>\n<li><strong>Train staff and enforce role-based access controls.<\/strong> Train staff on PCI DSS requirements and phishing awareness, and restrict system access to only what each role requires.<\/li>\n<li><strong>Reduce PCI scope through technology choices.<\/strong> Minimize the cardholder data your hotel stores, processes, or transmits by choosing a cloud-native PMS with integrated, PCI DSS Level 1 certified payments.<\/li>\n<\/ol>\n<h2>PCI DSS Requirements for Modern Hotels<\/h2>\n<p>PCI DSS, the Payment Card Industry Data Security Standard, is a set of security requirements that any business handling cardholder data must follow. Enforced by payment processors and acquiring banks, it functions as a condition of accepting card payments rather than a government regulation. PCI DSS v4.0.1 became the sole active standard on December 31, 2024, when v3.2.1 was retired, and all 51 previously future-dated requirements became mandatory on March 31, 2025.<\/p>\n<p>For hotels, PCI DSS compliance is typically more demanding than for many other businesses. Hospitality groups operating multiple venues may have transaction volumes aggregated across the portfolio, which can elevate them to Level 1 or Level 2 and trigger more rigorous assessments. The 12 core requirements are grouped into six control objectives:<\/p>\n<ul>\n<li>Build and maintain a secure network<\/li>\n<li>Protect cardholder data<\/li>\n<li>Maintain a vulnerability management program<\/li>\n<li>Implement strong access control measures<\/li>\n<li>Regularly monitor and test networks<\/li>\n<li>Maintain an information security policy<\/li>\n<\/ul>\n<p>PCI DSS v4.0.1 introduces several changes that directly affect hotels. Requirement 8.4.2 now mandates multi-factor authentication (MFA) for all access to the cardholder data environment (CDE), not just remote or administrative access. This shift reflects the reality that any CDE access point can become a breach vector. Password requirements have also strengthened, with a minimum of 12 characters including both numeric and alphabetic characters. Two new requirements, 6.4.3 and 11.6.1, specifically target e-skimming attacks on payment pages, requiring hotels to inventory and authorize every script running on their booking pages and monitor those pages for tampering at least weekly.<\/p>\n<p>The key shift in v4.0.1 is from point-in-time validation to continuous compliance. As of March 31, 2025, the standard emphasizes continuous monitoring rather than one annual check. Hotels must treat PCI DSS as an ongoing operational practice instead of a once-a-year project.<\/p>\n<h2>Tokenization and P2PE: How They Work Together for Hotels<\/h2>\n<p>Tokenization and P2PE handle different stages of the payment lifecycle, and hotels gain the strongest protection when they use both. Each control focuses on a specific risk and together they close major gaps.<\/p>\n<p><strong>Tokenization<\/strong> replaces a real card number with a meaningless substitute, or token, that has no mathematical relationship to the original. The mapping between token and card number lives in a secure vault operated by your payment provider. Tokenization is a storage control that keeps downstream systems away from the original card number. If a hacker breaches your PMS and steals tokens, they gain nothing usable.<\/p>\n<p><strong>Point-to-point encryption (P2PE)<\/strong> encrypts card data from the moment it is entered at a terminal until it reaches the payment processor. <a href=\"https:\/\/itpracticeexams.com\/kb\/security-plus\/pci-dss-scope-reduction\" target=\"_blank\" rel=\"noindex nofollow\">The merchant never possesses the encryption keys, so intermediate hotel systems only see ciphertext they cannot decrypt.<\/a> P2PE acts as a transport control that protects data while it moves between systems.<\/p>\n<p>P2PE protects card data while it is in transit, while tokenization protects it once it is stored. Almost every merchant that has pursued serious PCI scope reduction has implemented both controls.<\/p>\n<p>Hotels have a unique problem that makes both controls essential: they often need to charge cards after the guest has left. The incidental hold, the no-show fee, and the damage charge all require the ability to charge a card that is not physically present. For hotel environments, tokenization is especially useful for card-on-file, recurring charges, deposits, pre-authorizations, refunds, and post-stay charges because those flows can use the token instead of the real card number. P2PE then ensures that when a card is present at the front desk or kiosk, the data never enters your systems in readable form.<\/p>\n<p>The compliance benefit is significant. <a href=\"https:\/\/itpracticeexams.com\/kb\/security-plus\/pci-dss-scope-reduction\" target=\"_blank\" rel=\"noindex nofollow\">Systems that store only tokens hold no cardholder data and can drop out of PCI scope entirely.<\/a> Scope reduction lowers audit cost and breach exposure while keeping strong security for what remains in scope.<\/p>\n<p>Stayntouch Pay uses both tokenization and P2PE so card data never enters the PMS in readable form. The platform is PCI DSS Level 1 certified and runs on AWS Private VPC infrastructure with SOC 2 Type 1, GDPR, and ISO 27001\/27018 certifications.<\/p>\n<h2>Securing Online Bookings and Payment Gateways<\/h2>\n<p>Your online booking engine is the most exposed payment channel you operate. It is public-facing and accessible from anywhere in the world. This makes it a prime target for e-skimming attacks, where criminals inject malicious JavaScript into your payment page to steal card numbers as guests type them. A single Trustwave scan in April 2025 found 95,040 vulnerabilities across hospitality companies, including 14,318 critical-severity issues.<\/p>\n<p>To reduce the risk of e-skimming and card data exposure, apply these controls to your online booking flow:<\/p>\n<ul>\n<li>Use a PCI-compliant payment gateway that handles card data directly so it never touches your servers.<\/li>\n<li>Ensure your booking engine integrates securely with your PMS. The connection should be encrypted and card data should pass directly to the processor rather than being stored by the booking engine.<\/li>\n<li>Implement SSL\/TLS encryption on all booking pages.<\/li>\n<li>Enable fraud screening tools including Address Verification Service (AVS), Card Verification Value (CVV) checks, and 3D Secure 2.2, a strong customer authentication protocol that can shift chargeback liability to the card issuer for authenticated transactions.<\/li>\n<li>Monitor your payment pages for tampering. PCI DSS v4.0.1 Requirement 11.6.1 requires this at least weekly.<\/li>\n<li>Enable bot detection to prevent card-testing attacks, where attackers use your booking flow to validate stolen card numbers.<\/li>\n<\/ul>\n<p>Stayntouch\u2019s booking engine integrates with Stayntouch Pay, which uses tokenization and P2PE to ensure card data never enters the hotel\u2019s systems. Card data passes directly to the processor, and only a token returns to the PMS.<\/p>\n<h2>Front Desk and Point-of-Sale Security Controls<\/h2>\n<p>The front desk handles most card-present transactions, and human error and physical security gaps often appear here. In a typical hotel, between 15 and 30 personnel access sensitive card data daily, and every one of those access points requires MFA implementation under PCI DSS v4.0.1.<\/p>\n<p>To address human error and physical security gaps at the front desk and POS, implement these controls:<\/p>\n<ul>\n<li>Use EMV chip readers because chip cards are significantly harder to counterfeit than magnetic stripe cards.<\/li>\n<li>Never write down or store card numbers on paper, in spreadsheets, or in email.<\/li>\n<li>Ensure terminals are tamper-resistant and train staff to inspect them daily for skimming devices.<\/li>\n<li>Restrict access to payment systems using unique logins for every staff member, and avoid shared credentials. Shared logins destroy audit trails and make fraud almost impossible to attribute.<\/li>\n<li>Support contactless payments because digital wallets like Apple Pay and Google Pay reduce physical card skimming risk.<\/li>\n<li>Set automatic session timeouts on front desk terminals to prevent unauthorized access when screens are left unattended.<\/li>\n<\/ul>\n<p>Stayntouch Pay provides PCI-certified terminals with P2PE, so card data is encrypted at the moment of capture and never enters the PMS in readable form. Digital Registration Cards capture signed terms and conditions at check-in, creating documented evidence that reduces disputes and chargebacks by supporting the guest\u2019s folio with a clear authorization record.<\/p>\n<h2>Staff Training and Access Controls<\/h2>\n<p>Human error drives many payment data breaches, and hospitality\u2019s high turnover and seasonal staffing amplify this risk. Seventy percent of hotel staff access sensitive systems without regular cybersecurity training, according to the Verizon 2025 Data Breach Investigations Report. Nearly three out of four new employees clicked a phishing email within their first 90 days and were 44% more likely to fall for social engineering than experienced staff.<\/p>\n<p>Use these practices to strengthen staff behavior and access controls:<\/p>\n<ul>\n<li>Train staff on PCI DSS requirements, including what they can and cannot do with card data, upon hire and at least annually.<\/li>\n<li>Teach phishing awareness so staff can spot suspicious emails impersonating guests, travel agents, or OTA support representatives.<\/li>\n<li>Implement role-based access controls so staff see only the data they need for their specific role. For example, a housekeeper does not need payment folio access.<\/li>\n<li>Use MFA for all system access that touches the CDE, as PCI DSS v4.0.1 now requires.<\/li>\n<li>Establish clear escalation procedures. Staff should pause, avoid irreversible actions, escalate to a manager, and verify through official channels when a transaction feels wrong.<\/li>\n<\/ul>\n<p>Stayntouch Academy provides role-based, self-paced eLearning with certifications, test environments, and progress tracking so new hires can learn payment security before they touch a live system. Full platform training across all modules typically takes two days.<\/p>\n<p><a href=\"https:\/\/www.stayntouch.com\/contact-us\" target=\"_blank\">Talk to our team<\/a> to learn how Stayntouch\u2019s integrated security architecture and training tools reduce your compliance burden from day one.<\/p>\n<h2>Fraud Prevention and Chargeback Management<\/h2>\n<p>Even with well-trained staff, hotels must actively prevent fraud and manage chargebacks. This section focuses on the most common fraud patterns and the controls that reduce them.<\/p>\n<p>Hotels face two main types of payment fraud: card-not-present fraud on online bookings and card-present fraud using stolen cards at the front desk. Both lead to chargebacks, where a guest disputes a charge with their card issuer and the hotel loses the money by default unless it can prove the transaction was legitimate. Hotel chargeback rates typically run between 0.5% and 1.5% of transactions, significantly higher than the retail industry average of 0.3\u20130.5%.<\/p>\n<p>Social engineering is an additional and growing threat. Gen Threat Labs identified more than 350 compromised accommodations linked to reservation hijack scam flows across 50 countries, where criminals use stolen booking data to impersonate hotels and redirect guests to fraudulent payment pages.<\/p>\n<p>Use these practices to reduce fraud and improve chargeback outcomes:<\/p>\n<ul>\n<li>Use AVS and CVV checks for all online transactions.<\/li>\n<li>Implement velocity checks and flag multiple bookings from the same card or IP address in a short period.<\/li>\n<li>Verify identity at check-in so the card used matches the guest\u2019s identification and reservation.<\/li>\n<li>Maintain detailed records, including signed registration cards, check-in time logs, itemized folios, and authorization hold notes, to dispute chargebacks successfully.<\/li>\n<li>Never accept full card numbers via email and send a secure payment link instead.<\/li>\n<li>Treat inbound payment change requests as high risk until verified through official channels.<\/li>\n<\/ul>\n<p>Stayntouch Pay includes fraud detection and automated risk management for third-party bookings. Digital Registration Cards capture signed terms and conditions that serve as evidence in chargeback disputes. Funds settle two business days after transaction, which improves cash-flow certainty compared with slower settlement cycles.<\/p>\n<h2>Reducing PCI Scope Through Technology Choices<\/h2>\n<p>The most effective way to reduce your PCI DSS compliance burden is to minimize the amount of cardholder data your hotel stores, processes, or transmits. Every system that touches raw card data falls into PCI DSS scope, and every in-scope system must be assessed, monitored, and secured. Fines for PCI DSS non-compliance can exceed $100,000 per month.<\/p>\n<p>Tokenization and P2PE are the primary methods for scope reduction. Implementing a validated P2PE solution collapses PCI scope to roughly the physical device estate, procedures for handling devices, staff training on tamper evidence, and the reporting relationship with the P2PE Solution Provider. When card data is tokenized at the point of capture and encrypted in transit, your PMS, booking engine, and other systems never handle raw card data and can drop out of scope.<\/p>\n<p>Many hotels still store raw card data due to legacy systems built before tokenization was standard, inertia, and integration complexity. A cloud-native PMS with integrated payments eliminates this architectural debt. Stayntouch Pay exemplifies this approach by using tokenization and P2PE to ensure card data never enters the PMS. The platform runs on AWS Private VPC infrastructure with SOC 2 Type 1, GDPR, and ISO 27001\/27018 certifications and supports role-based access and MFA. Integration access is scoped so a door lock application can see a room number and checkout date but remains blocked from payment or address data.<\/p>\n<h2>Hotel Payment Security Checklist<\/h2>\n<p>Use this checklist to assess your current security posture and identify gaps:<\/p>\n<ul>\n<li>We use a PCI-compliant payment gateway for all online transactions.<\/li>\n<li>We tokenize all card data, with no raw card numbers stored in our PMS or any other system.<\/li>\n<li>We use P2PE at every card entry point, including front desk, kiosk, and POS.<\/li>\n<li>We use MFA for all access to payment systems.<\/li>\n<li>We restrict access to payment systems using role-based access controls with unique logins per staff member.<\/li>\n<li>We train staff on payment security upon hire and at least annually.<\/li>\n<li>We monitor our booking pages for e-skimming attacks at least weekly.<\/li>\n<li>We have a documented chargeback dispute process with supporting records.<\/li>\n<li>We never accept card numbers via email or phone.<\/li>\n<li>We regularly review our PCI DSS compliance status and maintain year-round evidence.<\/li>\n<\/ul>\n<h2>Common Pitfalls and How to Avoid Them<\/h2>\n<ul>\n<li><strong>Storing card data in the PMS.<\/strong> Some legacy systems store raw card numbers for future charges, which creates the single biggest PCI scope expander. Avoid this by using tokenization and storing tokens instead of card numbers.<\/li>\n<li><strong>Using outdated payment terminals.<\/strong> <a href=\"https:\/\/hotelfacilityguide.com\/security\/hotel-guest-privacy-data-security\" target=\"_blank\" rel=\"noindex nofollow\">Old terminals without EMV or contactless support are easier to skim and do not support P2PE.<\/a> Upgrade to PCI-certified terminals with P2PE.<\/li>\n<li><strong>Neglecting staff training.<\/strong> <a href=\"https:\/\/hotelbusiness.com\/hb-exclusive-what-hoteliers-can-do-to-combat-cybercrime\/\" target=\"_blank\">Thirty-two percent of cyberattacks in 2025 were caused by unpatched software and outdated systems<\/a>, and human error remains a parallel and equally serious vector. Make payment security training part of onboarding and require annual refreshers.<\/li>\n<li><strong>Ignoring PCI DSS v4.0.1 updates.<\/strong> Hotels that still operate under v3.2.1 assumptions fall out of compliance. The new requirements around MFA, password length, and e-skimming controls have been mandatory since March 31, 2025.<\/li>\n<li><strong>Failing to secure third-party integrations.<\/strong> Third-party involvement doubled from 15% to 30% of all breaches year-over-year, according to the 2025 Verizon Data Breach Investigations Report. Every integration that touches payment data represents a potential breach point, so ensure all integrations are PCI-compliant and use scoped access.<\/li>\n<\/ul>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What is PCI DSS and does it apply to my hotel?<\/h3>\n<p>PCI DSS, the Payment Card Industry Data Security Standard, applies to any business that stores, processes, or transmits cardholder data. If your hotel accepts card payments at any touchpoint, including front desk, online booking engine, kiosk, or point-of-sale, PCI DSS applies. It is enforced by payment processors and acquiring banks as a condition of accepting card payments rather than by a government body. Your compliance level, from Level 1 through Level 4, is determined by annual transaction volume. Most independent hotels fall into Level 4 and can comply by completing a Self-Assessment Questionnaire instead of undergoing a full external audit. Multi-property groups with high aggregate transaction volumes may qualify as Level 1 or Level 2 and require more rigorous assessment.<\/p>\n<h3>What is the difference between tokenization and point-to-point encryption?<\/h3>\n<p>Tokenization and P2PE protect card data at different stages of the payment lifecycle and work best together. Tokenization is a storage control that replaces a real card number with a meaningless token that has no mathematical relationship to the original. The mapping lives in a secure vault operated by your payment provider, so even if your PMS is breached, attackers get only tokens. P2PE is a transport control that encrypts card data from the moment it is entered at a terminal until it reaches the payment processor, using keys the merchant never possesses. Hotels need both because they process card-present transactions at the front desk, where P2PE protects data in transit, and store card credentials for future charges like no-show fees and post-stay charges, where tokenization protects stored data.<\/p>\n<h3>How do I reduce my hotel&#8217;s PCI scope?<\/h3>\n<p>PCI scope is determined by how many systems in your environment store, process, or transmit raw cardholder data. The most effective way to reduce scope is to architect card data out of your systems entirely. Tokenization ensures your PMS and downstream systems store only tokens instead of card numbers, which removes them from scope. P2PE ensures card data is encrypted at the terminal before it enters any hotel system, which removes the transmission path from scope. Network segmentation isolates the cardholder data environment from the rest of your network so systems that cannot reach the CDE are not subject to PCI assessment. Choosing a cloud-native PMS with integrated, PCI DSS Level 1 certified payments, rather than bolting security tools onto a legacy system, is the most efficient way to achieve this architecture. Stayntouch Pay follows this model so tokenization and P2PE function as defaults rather than add-ons.<\/p>\n<h3>What are the most common payment fraud schemes targeting hotels?<\/h3>\n<p>Hotels face several distinct fraud patterns. Card-not-present fraud occurs when stolen card details are used to make online bookings and the cardholder is not physically present to verify identity. Friendly fraud, also called chargeback fraud, occurs when a legitimate cardholder disputes a valid charge with their bank, often after a stay, claiming the transaction was unauthorized or services were not rendered. Social engineering scams target front desk staff directly, as callers impersonate guests, travel agents, or OTA support representatives and use urgency to request card details by phone or email or to redirect deposits to new cards. Reservation hijack scams use stolen booking data to impersonate hotels and redirect guests to fraudulent payment pages. E-skimming attacks inject malicious JavaScript into online booking pages to capture card numbers as guests type them. Each pattern requires a specific control, such as fraud screening and 3D Secure for card-not-present fraud, detailed records and signed authorization for friendly fraud, staff training and verification protocols for social engineering, and script monitoring for e-skimming.<\/p>\n<h3>How does a cloud-native PMS improve payment security compared to a legacy system?<\/h3>\n<p>Legacy property management systems were often built before tokenization and P2PE became standard practice, and many still store raw card numbers by default, which creates a permanent dataset that attackers can target. A cloud-native PMS with integrated payments can remove this architectural debt entirely. When tokenization and P2PE are built into the payment architecture rather than bolted on, card data never enters the PMS in readable form. The hotel&#8217;s systems store only tokens, which have no value to an attacker. Cloud-native infrastructure also removes on-premise servers, a common breach vector, and enables continuous patching and monitoring without scheduled downtime. Stayntouch Pay integrates directly with Stayntouch PMS on this architecture and follows the certifications and controls described earlier, including role-based access controls and MFA support across all system access.<\/p>\n<h2>Secure Payments, Protected Guests<\/h2>\n<p>Hotel payment security functions as both a compliance requirement and a guest-experience and revenue-protection issue. The stakes are clear: as mentioned earlier, the average cost of a hospitality data breach reached $4.03 million in 2025, and <a href=\"https:\/\/hotelbusiness.com\/hb-exclusive-what-hoteliers-can-do-to-combat-cybercrime\/\" target=\"_blank\">42% of hoteliers cite cybersecurity concerns as a primary reason for leaving a technology partnership<\/a>. The most effective approach to hotel payment security is to architect card data out of your systems through tokenization and P2PE, train your staff as a first line of defense, and choose technology partners who make security the default.<\/p>\n<p>Stayntouch Pay is PCI DSS Level 1 certified and uses tokenization and P2PE to ensure card data never enters your PMS. Combined with Stayntouch\u2019s cloud-native architecture on AWS, role-based access controls, MFA support, and Digital Registration Cards that document guest authorization, it provides a security foundation that lets your team focus on guests instead of compliance firefighting.<\/p>\n<p><a href=\"https:\/\/www.stayntouch.com\/contact-us\" target=\"_blank\">Schedule a demo<\/a> to see how Stayntouch Pay and Stayntouch PMS can reduce your PCI scope, protect guest payment data, and simplify compliance across every channel.<\/p>\n<section data-read-next=\"true\">\n<h2>Read Next<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.stayntouch.com\/articles\/hotel-payment-best-practices\" target=\"_blank\">Hotel Payment Best Practices for Independent Hotels<\/a><\/li>\n<li><a href=\"https:\/\/www.stayntouch.com\/articles\/pci-dss-level-1-hotel\" target=\"_blank\">PCI DSS Level 1 Hotel Software: Reduce Your PCI Scope<\/a><\/li>\n<li><a href=\"https:\/\/www.stayntouch.com\/articles\/hotel-payment-api-integrations\" target=\"_blank\">Hotel Payment API Integration Guide for PMS Platforms<\/a><\/li>\n<li><a href=\"https:\/\/www.stayntouch.com\/articles\/hotel-guest-payment-options\" target=\"_blank\">Hotel Guest Payment Options: A Complete Guide<\/a><\/li>\n<li><a href=\"https:\/\/www.stayntouch.com\/articles\/hotel-front-desk-payment-training\" target=\"_blank\">How to Train Hotel Front Desk Staff on Payment Processing<\/a><\/li>\n<\/ul>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Protect guests and reduce PCI scope with Stayntouch. Explore tokenization, P2PE, fraud prevention, and payment security best practices for hotels.<\/p>\n","protected":false},"author":117,"featured_media":349,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-350","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/posts\/350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/comments?post=350"}],"version-history":[{"count":1,"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/posts\/350\/revisions"}],"predecessor-version":[{"id":467,"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/posts\/350\/revisions\/467"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/media\/349"}],"wp:attachment":[{"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/media?parent=350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/categories?post=350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.stayntouch.com\/articles\/wp-json\/wp\/v2\/tags?post=350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}