Demo: Orbit Travel API
Download OpenAPI DocumentSearch destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.
Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.
Authentication
Create an access token
Destinations
List destinations
Get a destination
Flights
Search flights
Get a flight
Legacy flight searchDeprecated
Seats
Get a seat map
Hold seats
Create a booking
List bookings
Get a booking
Update a booking
Cancel a booking
Upload a travel documentbeta
List travel documents
Download a boarding pass
Create a passenger
List passengers
Get a passenger
Update a passenger
Delete a passenger
Pay for a booking
Get a payment
Refund a payment
Get the loyalty account
Returns the Orbit Miles account of the customer the key belongs to: balance, tier and how far the next tier is. Paid bookings earn one point per dollar.
Responses
200OK
Current tier, from lifetime points.
When the oldest points expire; null if none will.
When the account was opened.
Account id.
Orbit Miles member number, printed on boarding passes.
Points you can spend now.
Points from flights not yet flown; they become spendable after departure.
All points ever earned (sets the tier).
Distance to the next tier.
Show child attributes
Next tier up; null at Admiral.
Lifetime points still needed for the next tier; null at Admiral.
Progress from this tier to the next, 0–100.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
401Authentication is missing or invalid.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
403Authenticated, but not allowed to do this.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
Seconds to wait before retrying.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
500Something failed on the server. Retry with backoff.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
curl http://localhost:3010/v1/loyalty/account \
--header 'x-api-key: YOUR_API_KEY'{
"tier": "voyager",
"pointsExpireOn": "2028-10-31",
"memberSince": "2026-03-14",
"id": "loy_2Hk9Wd",
"memberNumber": "OT 4410 2291",
"pointsBalance": 48250,
"pointsPending": 12999,
"lifetimePoints": 53000,
"tierProgress": {
"nextTier": "pioneer",
"pointsToNextTier": 22000,
"percent": 56
}
}