Demo: Orbit Travel API
Download OpenAPI DocumentSearch destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.
Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.
Authentication
Create an access token
Destinations
List destinations
Get a destination
Flights
Search flights
Get a flight
Legacy flight searchDeprecated
Seats
Get a seat map
Hold seats
Holds seats for 15 minutes while your customer finishes checking out.
Assign them with Update a booking (holdId) before expiresAt, or they
are released.
Path Parameters
Flight id.
Bodyrequiredapplication/json
Seats to hold, all in one cabin. Up to nine.
Responses
201Created
Cabin of the held seats.
Active until it is used on a booking or expires.
When the seats are released if the hold is not used.
When the hold was created.
Hold id. Pass it as holdId to Update a booking.
Flight id.
Seats held.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
400The request is invalid: a parameter or body field failed validation.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
401Authentication is missing or invalid.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
403Authenticated, but not allowed to do this.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
404No flight with this id.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
409A seat is taken or already held.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
422A seat does not exist on this flight, or the seats span cabins.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
Seconds to wait before retrying.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
500Something failed on the server. Retry with backoff.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
curl http://localhost:3010/v1/flights/flt_2031_proxima/seat-holds \
--request POST \
--header 'x-api-key: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{
"seats": [
"24A",
"24B"
]
}'{
"cabin": "economy",
"status": "active",
"expiresAt": "2026-10-04T09:15:00Z",
"createdAt": "2026-10-04T09:00:00Z",
"id": "sh_Lq83Zt",
"flightId": "flt_2031_proxima",
"seats": [
"24A",
"24B"
]
}