Demo: Orbit Travel API
Download OpenAPI DocumentSearch destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.
Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.
Authentication
Create an access token
Exchanges your client id and secret for an access token (OAuth 2.0
client credentials grant). Send the token as Authorization: Bearer …
instead of an API key; it expires after an hour.
This endpoint takes no API key or token itself.
Bodyrequiredapplication/x-www-form-urlencoded
Always client_credentials.
Your OAuth client secret. The sample server accepts ocs_test_5e8d2a7c9b1f.
Your OAuth client id. The sample server accepts oc_test_orbit_demo.
Space-separated scopes. Omit for every scope the client may use.
Responses
200OK
Token type.
Send it as Authorization: Bearer <access_token>.
Seconds until the token expires. Request a new one before then.
Scopes granted, space-separated.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
400Malformed request, unsupported `grant_type` or unknown scope.
Machine-readable error code.
What went wrong, for people.
401Unknown client or wrong secret.
Machine-readable error code.
What went wrong, for people.
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
Seconds to wait before retrying.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
500Something failed on the server. Retry with backoff.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
curl http://localhost:3010/v1/oauth/token \
--request POST \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'client_secret=ocs_test_5e8d2a7c9b1f' \
--data-urlencode 'client_id=oc_test_orbit_demo' \
--data-urlencode 'scope=bookings:read bookings:write'{
"token_type": "Bearer",
"access_token": "oat_test_Q2xpZW50Q3JlZGVudGlhbHM",
"expires_in": 3600,
"scope": "bookings:read bookings:write"
}