OrbitDocs packages are coming to npm soon. Until then, run it from the GitHub repo →
v1.0.0OpenAPI 3.1.1

Demo: Orbit Travel API

Download OpenAPI Document

Search destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.

Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.

Server
Local
Authentication Required
Your API key. The sample server accepts `otk_test_4f9a2c1b8e7d6a5f`.
x-api-key:
Client Libraries
Shell

Authentication

Create an access token

List events

Auth Required

Lists events from the last 30 days, newest first: the same payloads webhooks deliver. Use it to catch up after downtime, or instead of webhooks if you cannot receive them.

Query Parameters

typestring

Only events of this type.

Enum values:booking.confirmedbooking.changedbooking.cancelledpayment.succeededpayment.failed
created[gte]string · date-time

Only events created at or after this time.

Example: 2026-10-01T00:00:00Z
created[lte]string · date-time

Only events created at or before this time.

Example: 2026-10-31T23:59:59Z
limitnumber

Items per page.

Default: 20Example: 20Min: 1Max: 100
cursorstring

Cursor from the previous page's nextCursor. Omit for the first page.

Example: eyJpZCI6ImJrXzEwIn0

Responses

200OK
application/json
dataEventDto[]required

Events on this page, newest first.

Show child attributes
typestringrequired

What happened.

Example: booking.confirmed
createdAtstring · date-timerequired

When the event happened.

Example: 2026-10-03T12:00:01Z
idstringrequired

Event id. Deliveries of the same event share it, so use it to skip duplicates.

Example: evt_N3wB9k
apiVersionstringrequired

API version the payload is shaped by.

Example: 2031-01-01
dataEventDataDtorequired

What changed.

Show child attributes
objectBookingDto | PaymentDtorequired

The object the event is about, as it was right after the change: a booking for booking.* events, a payment for payment.* events.

previousAttributesobject | nullrequired

For booking.changed: the changed fields with their previous values. null for other events.

Example: {"seats":[]}
pagePageInfoDtorequired

Pagination cursor.

Show child attributes
nextCursorstring | nullrequired

Cursor for the next page; null on the last page.

Example: eyJpZCI6ImJrXzIwIn0
hasMorebooleanrequired

Whether more items follow.

Example: true
Headers
X-RateLimit-Limitinteger

Requests allowed per minute for this credential.

Example: 60
X-RateLimit-Remaininginteger

Requests left in the current window.

Example: 59
X-RateLimit-Resetinteger

When the window resets, in Unix seconds.

Example: 1949398800
400The request is invalid: a parameter or body field failed validation.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
401Authentication is missing or invalid.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
403Authenticated, but not allowed to do this.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
Headers
Retry-Afterinteger

Seconds to wait before retrying.

Example: 42
X-RateLimit-Limitinteger

Requests allowed per minute for this credential.

Example: 60
X-RateLimit-Remaininginteger

Requests left in the current window.

Example: 59
X-RateLimit-Resetinteger

When the window resets, in Unix seconds.

Example: 1949398800
500Something failed on the server. Retry with backoff.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
GET/v1/events
curl 'http://localhost:3010/v1/events?created[gte]=2026-10-01T00:00:00Z&created[lte]=2026-10-31T23:59:59Z&limit=20&cursor=eyJpZCI6ImJrXzEwIn0' \
  --globoff \
  --header 'x-api-key: YOUR_API_KEY'
{
  "data": [
    {
      "type": "booking.confirmed",
      "createdAt": "2026-10-03T12:00:01Z",
      "id": "evt_N3wB9k",
      "apiVersion": "2031-01-01",
      "data": {
        "object": {},
        "previousAttributes": {
          "seats": []
        }
      }
    }
  ],
  "page": {
    "nextCursor": "eyJpZCI6ImJrXzIwIn0",
    "hasMore": true
  }
}

Get an event

Models

BankTransferInstructionsDto
BankTransferPaymentRequestDto
BoardingGroup Boarding group, called in order.
BoardingPassDto
BoardingPassFormat
BoardingPassPassengerDto
BookingDto
BookingListDto
BookingStatus Where the booking is in its life.
CabinClass Cabin.
CabinSeatMapDto
CancelBookingDto
CardBrand Card network.
CardDetailsDto
CardPaymentRequestDto
Climate
CreateBookingDto
CreatePassengerDto
CreateRedemptionDto
CreateRefundDto
CreateSeatHoldDto
CreateWebhookEndpointDto
DestinationDto
DestinationListDto
DocumentKind What the document is, detected from the scan.
DocumentStatus Review status. Boarding needs a verified passport.
EventDataDto
EventDto
EventListDto
FareDto
FlightDto
FlightListDto
GrantType Always `client_credentials`.
LegacyFlightSearchDto
LoyaltyAccountDto
LoyaltyTier Current tier, from lifetime points.
LoyaltyTransactionDto
LoyaltyTransactionListDto
LoyaltyTransactionType
MealPreference Meal served on board.
OAuthErrorCode Machine-readable error code.
OAuthErrorDto
PageInfoDto
PassengerDto
PassengerListDto
PassengerProfileDto
PassportDto
PaymentDto
PaymentMethodDetailsDto
PaymentMethodType How the payment was made. Exactly one of the objects below is set.
PaymentStatus Where the payment is in its life.
RedemptionDto
RedemptionStatus Redemptions complete immediately.
RefundDto
RefundReason Why the money went back.
RefundStatus Bank transfer refunds stay `pending` for a few days.
RewardType Reward to buy. Costs: `cabin_upgrade` 40,000, `booking_credit` 10,000 ($100 off), `extra_baggage` 8,000, `lounge_access` 5,000.
SeatDto
SeatFeature What makes this seat different.
SeatHoldDto
SeatHoldStatus Active until it is used on a booking or expires.
SeatMapDto
SeatPreference Preferred seat, used when seats are auto-assigned.
SeatPriceDto
SeatRowDto
SeatStatus Whether the seat can be held.
TestWebhookEndpointDto
TierProgressDto
TokenRequestDto
TokenResponseDto
TravelDocumentDto
TravelDocumentListDto
TravelPreferencesDto
UpdateBookingDto
UpdatePassengerDto
UpdateTravelPreferencesDto
UploadDocumentDto
WalletPaymentRequestDto
WalletType Wallet the token comes from.
WebhookDeliveryDto
WebhookDeliveryStatus `succeeded` when your endpoint answered with a 2xx status.
WebhookEndpointDto
WebhookEndpointListDto
WebhookEvent