Demo: Orbit Travel API
Download OpenAPI DocumentSearch destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.
Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.
Authentication
Create an access token
Destinations
List destinations
Get a destination
Flights
Search flights
Get a flight
Legacy flight searchDeprecated
Seats
Get a seat map
Hold seats
Create a booking
List bookings
Get a booking
Update a booking
Cancel a booking
Upload a travel documentbeta
List travel documents
Download a boarding pass
Create a passenger
List passengers
Lists saved passengers, newest first. Filter by email to find one.
Query Parameters
Items per page.
Cursor from the previous page's nextCursor. Omit for the first page.
Only the passenger with this email.
Responses
200OK
Passengers on this page, newest first.
Show child attributes
Date of birth.
Passport details; null when not on file yet.
Show child attributes
Expiry date. Must be valid six months after departure.
Passport number.
Issuing country, ISO 3166-1 alpha-2.
Orbit Miles member number, or null.
Up to 20 key-value pairs of your own. Values are strings; send an empty string to remove a key.
When the passenger was saved.
When the passenger last changed.
Passenger id.
Given name as on the passport.
Family name as on the passport.
Contact email.
Nationality, ISO 3166-1 alpha-2.
Seat and meal preferences.
Show child attributes
Preferred seat, used when seats are auto-assigned.
Meal served on board.
Prefers a cryosleep pod on journeys longer than a year.
Pagination cursor.
Show child attributes
Cursor for the next page; null on the last page.
Whether more items follow.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
400The request is invalid: a parameter or body field failed validation.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
401Authentication is missing or invalid.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
403Authenticated, but not allowed to do this.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
Seconds to wait before retrying.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
500Something failed on the server. Retry with backoff.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
curl 'http://localhost:3010/v1/passengers?limit=20&cursor=eyJpZCI6ImJrXzEwIn0&email=ada@example.com' \
--header 'x-api-key: YOUR_API_KEY'{
"data": [
{
"dateOfBirth": "1990-12-10",
"passport": {
"expiresOn": "2034-06-30",
"number": "X49201837",
"issuingCountry": "GB"
},
"loyaltyNumber": "OT 4410 2291",
"metadata": {
"crmId": "cus_10442",
"segment": "frequent-flyer"
},
"createdAt": "2026-10-03T12:00:00Z",
"updatedAt": "2026-10-04T08:15:00Z",
"id": "psg_8Fk2Lm",
"firstName": "Ada",
"lastName": "Lovelace",
"email": "ada@example.com",
"nationality": "GB",
"preferences": {
"seat": "window",
"meal": "vegetarian",
"cryosleep": true
}
}
],
"page": {
"nextCursor": "eyJpZCI6ImJrXzIwIn0",
"hasMore": true
}
}