Skip to content
Holidario Documentation

Integrations

Configure OpenRouter and AI conversation analysis

Create the OpenRouter account and key, configure ZDR, understand local Presidio anonymization, and govern automatic replies.

For
  • I own or administer an agency
Available on
  • Agency

Holidario can send a copy of a reservation conversation with detected personal information redacted to the AI model selected by your agency in OpenRouter to produce a summary and detect topics, dates, requests, and possible incidents. Before dispatch, the local Presidio instance replaces that information with non-reversible placeholders. The result is an operational aid: it does not replace reading the original conversation or a person's decision.

This guide first covers the shared OpenRouter setup and then focuses on conversation analysis. The Internal Support Agent is a separate optional feature: it uses private FAQs and public documentation and never uses conversations as a knowledge source. Every agent uses the tenant's shared OpenRouter key, but each keeps its own exact model and inference-provider pair.

The agency purchases and controls its OpenRouter account. Credentials, credits, usage, limits, and privacy settings belong to that account. Holidario adds no AI usage charge.

Two levels of access#

Configuration and daily use require different capabilities:

  • AI administration: read-ai-provider and update-ai-provider permissions, plus authorization for the team's configuration.
  • Work on a reservation: reservation read and update permissions, plus authorization for that reservation.

Belonging to a particular position does not by itself grant both capabilities. The default Manager and Front desk roles can review analysis already stored on an authorized reservation, but they do not include update-reservation: they cannot start analysis or an automatic response. Give them the focused review guide, never the API key.

Before configuration#

You need:

  • the Agency plan with AI messaging available;
  • your own OpenRouter account with credits and quota available;
  • an OpenRouter API key dedicated to the tenant;
  • an administrator of that account to review the OpenRouter privacy and ZDR settings;
  • a decision about the model and inference provider each agent will use;
  • an internal decision about which conversations may be sent to the provider;
  • a person responsible for reviewing results, costs, and automatic replies.

Do not use an employee's personal key. Use an organization credential that can be rotated when the team changes.

Create the OpenRouter account and key#

  1. Open OpenRouter and register the account controlled by your organization.
  2. Add funds under Credits. OpenRouter describes credits as deposits consumed by inference; they are not a Holidario subscription.
  3. Open API Keys and create a dedicated key, for example Holidario — tenant name.
  4. Set a spending limit for the key if your account requires that control.
  5. Copy the complete key when it is displayed. OpenRouter shows the secret value when it is created; it cannot be retrieved later from the list.
  6. Keep it in the agency's approved secrets manager until you enter it in Holidario. Never send it by email, chat, or to support.

The account, credits, and key are the tenant's responsibility. If the key is disabled, expires, runs out of credits, or reaches its limit, agents stop completing requests even if Holidario still shows a saved configuration.

Enable Zero Data Retention in OpenRouter#

Complete protection depends on the tenant maintaining its own OpenRouter account settings, not on Holidario alone. An administrator of that account must open Organization Privacy and keep the following states.

Under Data Policies > Zero Data Retention, turn on all five controls:

  1. Non-frontier: on.
  2. Anthropic: on.
  3. OpenAI: on.
  4. Google: on.
  5. xAI: on.

With these controls enabled, OpenRouter excludes non-ZDR endpoints in each group. In particular, first-party Anthropic endpoints give way to ZDR options such as Bedrock or Vertex; first-party OpenAI endpoints give way to Azure; and Google AI Studio gives way to Vertex when available for the model.

Under Data Training, turn off the following four controls:

  1. Allow paid endpoints that train on request data: off.
  2. Allow free endpoints that train on request data: off.
  3. Allow free endpoints that publish prompts: off.
  4. Allow 1% data discount in workspaces: off.

Also open Observability and keep Input & Output Logging off. This is an independent control: when enabled, OpenRouter stores prompt and response content for organization administrators to review. Recheck these settings after switching organizations or workspaces.

Holidario cannot change or certify settings in the external account. The tenant administrator must maintain them. OpenRouter documents the scope and exceptions in Zero Data Retention, Data Collection, and Provider Logging.

Presidio + ZDR#

Holidario runs Microsoft Presidio on its own server before these requests:

  • Internal Support: a detected value supported by an authorized read-only search is replaced in the provider copy with an encrypted, short-lived, session-bound private token. Other detected personal or sensitive data blocks the complete turn.
  • Conversation Analysis: Presidio analyzes the complete transcript locally in Spanish and English. It irreversibly replaces detected personal information and keeps no table that could reconstruct it. Dates and times remain because they are required to interpret the stay. Internal message identifiers are replaced with temporary numbers during the request and resolved again inside Holidario when an incident needs to cite messages.
  • SEO Content: Presidio anonymizes only uncontrolled text that may contain person-entered data, such as reviews and free-form descriptions. It retains intentional public listing fields —business name, location, geography, features, and structured facts— so the copy remains specific. A response that reproduces a privacy placeholder is not published.

If Presidio or its anonymizer is unavailable or returns an invalid response, Holidario blocks the request before contacting the provider. Automated detection reduces the personal information transmitted but can produce false positives or false negatives: use a controlled conversation to validate the team's usual languages and formats, and continue comparing the result with the original.

When an AI path sends a request, Holidario requires ZDR, pins the model and live-ZDR endpoint saved by the administrator, rejects data-collecting endpoints, and disables fallbacks. These are separate controls:

  • Presidio pseudonymizes authorized Internal Support searches and irreversibly anonymizes uncontrolled Conversation Analysis and SEO Content inputs.
  • ZDR requires OpenRouter and the selected final endpoint not to retain transmitted content; it does not anonymize that content.

ZDR applies only to inference-provider routing. It does not cover plugins or third-party tools someone chooses to enable in OpenRouter. Do not add external plugins or tools to a key used by Holidario without separately reviewing their processing and retention.

Configure the provider#

English desktop view of the fictional OpenRouter form, with a blank key, review links, and the mandatory declaration left unaccepted.
Visual example generated with fictional data; layout may vary by device.
  1. Switch to the correct team.
  2. Open Integrations > AI Provider.
  3. Open Edit.
  4. Enter the complete OpenRouter API key.
  5. From the same form, open the DPA, Organization Privacy, and Observability, and verify that they belong to the account that owns the key.
  6. Turn on the mandatory attestation. It confirms that the tenant controls the account and key, has accepted OpenRouter's current Terms and DPA, authorizes its administrators to choose an exact model/provider pair from OpenRouter's live ZDR registry, understands that providers and processing locations can change, authorizes redacted data to be sent through the selected routes, and will keep prompt logging, training, prompt publication, and data-use discounts disabled.
  7. Save and return to the integration.
  8. Check that it shows Configured with OpenRouter.

Holidario records the accepting administrator, time, and exact statement version. If the key was already stored before this control existed, leave the key field blank, accept the attestation, and save: the retained secret is not returned to the browser and does not need to be entered again. Replacing the key requires a fresh acceptance. A future statement version may require the administrator to accept it again.

The Configured status confirms that the key is stored; it does not guarantee credits, quota, limits, or independently prove the external account's privacy settings. The attestation documents the tenant's instruction and responsibility, but it does not let Holidario change or monitor OpenRouter. Each agent remains incomplete until you save its model and provider. The first real operation validates complete communication with OpenRouter and may incur usage.

Choose the model and inference provider#

Holidario loads the model catalogue available to the tenant key on the server. It then intersects that catalogue with the agent's required capabilities and OpenRouter's current ZDR registry. The key is never sent to the browser.

  1. Choose Model for this agent first.
  2. Under ZDR inference provider, compare the provider, quantization, context, maximum output, recent uptime, declared locations, and the input, output, and cache prices published by OpenRouter.
  3. Choose a selectable endpoint and use Save model and provider.

Every technically compatible endpoint in the live ZDR registry is selectable. Review the provider, declared locations, privacy policy, terms and price before saving it. Once saved, every request pins that exact pair with the order and only options; there is no automatic provider switching or fallback.

Amounts are the endpoint prices published by OpenRouter, normally in USD per million tokens. They are informational, may change after the catalogue refresh, and exclude credit-funding fees, taxes, and other account charges. Use the OpenRouter dashboard for definitive billing.

Enable Conversation Analysis#

  1. In AI Agents, find Conversation Analysis.
  2. Choose a compatible model and then a selectable ZDR inference provider.
  3. Use Save model and provider.
  4. Enable it for the team. The control remains unavailable while either value is missing, changes are unsaved, or the saved route is no longer eligible in the live catalogue.
  5. Initially leave every automatic-reply category without a template.
  6. Choose a controlled future reservation with a real OTA or WhatsApp conversation.
  7. Run the analysis and review the outcome before expanding use.

Changing this model/provider pair affects Conversation Analysis only. It does not change the routes for SEO Content, Auto Blog, or the Internal Support Agent.

Past reservations do not allow a new manual analysis. If the reservation has no compatible conversation, the action reports that it found no content to analyze.

Use analysis on a reservation#

  1. Open the authorized reservation from the calendar.
  2. Read the latest messages and confirm that they belong to the correct guest.
  3. Use Analyze Conversation.
  4. Wait for processing; the result might not appear immediately.
  5. Refresh the reservation and review the summary, categories, evidence, dates, actions, and concerns.
  6. Compare every important detail with the original text.

If new messages arrive during analysis, Holidario can mark the conversation for later review. Do not treat an earlier result as covering messages received afterwards.

Current behavior during an ongoing stay#

Holidario stores an ongoing-stay result as an incident analysis, but the visible card currently reads the general analysis. Last analyzed can therefore show a recent time while the new content is absent from the card.

Check that the reservation dates include today, that the OTA or WhatsApp conversation is linked, and that the last-analysis time is later than the message you intended to review. Work from the original conversation in the meantime. If those details match and the result remains absent, email [email protected] with the team, reservation, time zone, message time, and analysis time. Do not run analysis continuously in an attempt to make it appear.

Automatic replies: critical boundary#

In the agent configuration, you can associate templates with categories and enable sending. When Auto-send is enabled, a later analysis can generate a real guest message without a person selecting send again.

Before enabling it:

  1. review the category and its conditions across several representative conversations;
  2. check accept and decline templates in every language;
  3. verify property details, times, fees, and exceptions;
  4. confirm which channel will be used;
  5. test with a controlled reservation;
  6. assign someone to review the first executions.

If analysis cannot determine a clear response, automation may use a configured template as a fallback. Keep auto-send disabled for any category where an incorrect reply could commit price, availability, access, safety, or contractual terms.

Know when it is ready#

Analysis is ready for assisted use when:

  • the agent displays the expected exact model and provider;
  • all five ZDR controls are on, all four Data Training controls are off, and Input & Output Logging remains off in OpenRouter;
  • the agent is enabled;
  • the local Presidio service passes a controlled test and blocks dispatch when unavailable;
  • a controlled conversation completes without error;
  • the result matches the original text;
  • the team knows it must always verify the result;
  • automatic sending remains disabled or has passed specific acceptance.

Errors and recovery#

  • OpenRouter is not configured: save the tenant key.
  • OpenRouter rejects the API key: the saved key is invalid, expired, or revoked. Open Edit, replace it with an active OpenRouter API key, reaccept the attestation, and save. Holidario does not substitute the public catalogue because that would ignore the account's preferences and restrictions.
  • Agent route not configured: choose and save the model and provider inside Conversation Analysis, then enable the agent.
  • Current attestation pending: open Edit, review, and accept the current version before viewing or changing the dynamic catalogue.
  • Provider incompatible with the agent: the endpoint is ZDR but does not expose the parameters or modality this agent requires; choose another selectable endpoint.
  • Agent not enabled: enable Conversation Analysis.
  • No conversation: confirm that the reservation has linked OTA or WhatsApp messages.
  • Past reservation: use the information already recorded; do not force a new analysis.
  • Authentication, credit, or quota error: check the key, credits, limits, and model availability in OpenRouter.
  • The saved route is no longer available: Holidario does not switch providers. Check the account's ZDR settings and provider preferences, reload the catalogue, review the replacement provider, and save another compatible ZDR route.
  • Almost-empty card with the Automatic reply control: the attempt may have stored only an error. Do not select the control or treat the card as a valid analysis. Check the provider, model, quota, and billing, test with a controlled future reservation, and contact support if it repeats.
  • Ongoing stay with Last analyzed but no content: verify dates, linked conversation, and times. This is a current display limitation; work from the original thread and contact support when those checks are correct.
  • Incomplete or incorrect result: do not correct it by sending automatically; work from the original conversation and record the case.
  • Unexpected automatic message: disable auto-send for that category before continuing and review templates and association.

Do not repeat analysis continuously after a quota error: this can increase costs or worsen the provider limit.

Privacy, security, and quality#

  • Holidario applies Presidio to each new Internal Support user message, tokenizes detected values only for authorized read-only search fields, and blocks other detected personal or sensitive data.
  • Conversation Analysis replaces detected personal identifiers with non-reversible markers before constructing the OpenRouter request and fails closed when the local Presidio service is unavailable.
  • Holidario requires a pinned ZDR endpoint with no fallback, but retention within OpenRouter also depends on the tenant keeping Input & Output Logging and all four Data Training controls above disabled.
  • Review the contract, region, retention, training use, and processing terms for OpenRouter and the final endpoint.
  • Do not include passwords, access codes, or personal documents in conversations used only for testing.
  • The key is stored encrypted, but it must be rotated if an unauthorized person may have seen it.
  • Models can invent, omit, or misclassify information even when the text seems clear.
  • Review usage in OpenRouter; Holidario does not replace its limits or budget alerts.

What to send support#

Email [email protected] with the team, reservation, model, time and time zone, action performed, and visible error. For a missing ongoing-stay analysis, also include the stay dates and the last-message and last-analysis times. You can provide an anonymized excerpt that preserves the problem. Do not send the API key or the entire conversation unless essential.

Browse all documentation Press ⌘K or Ctrl+K from any page.

Preparing search…