Demo: Orbit Travel API
Download OpenAPI DocumentSearch destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.
Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.
Authentication
Create an access token
Destinations
List destinations
Get a destination
Flights
Search flights
Get a flight
Legacy flight searchDeprecated
Seats
Get a seat map
Hold seats
Create a booking
List bookings
Get a booking
Update a booking
Cancel a booking
Upload a travel documentbeta
List travel documents
Download a boarding pass
Create a passenger
List passengers
Get a passenger
Update a passenger
Delete a passenger
Pay for a booking
Pays for a booking by card, digital wallet or bank transfer; type
picks which. Cards and wallets are charged at once and the payment is
succeeded or failed (a payment.succeeded or payment.failed
webhook follows). Bank transfers stay pending until the money arrives;
method.bankTransfer says where to send it.
The Idempotency-Key header is required: retrying with the same key
returns the first payment (with Idempotent-Replayed: true) and never
charges twice.
Path Parameters
Booking id.
Headers
Unique key per payment attempt (a UUID works). Keys are kept for 24 hours.
Bodyrequiredapplication/json
One of three shapes, told apart by type.
Responses
201Created
Where the payment is in its life.
Machine-readable reason when status is failed, otherwise null.
Reason for people when status is failed, otherwise null.
Up to 20 key-value pairs of your own, returned on the payment and in its webhooks.
When the payment was created.
Payment id.
Booking paid for.
Amount charged, in cents (the booking total).
Amount refunded so far, in cents.
ISO 4217 currency code.
How the customer paid.
Show child attributes
How the payment was made. Exactly one of the objects below is set.
Card details when type is card, otherwise null.
Show child attributes
Card network.
Last four digits.
Expiry month (1–12).
Expiry year.
Wallet when type is wallet, otherwise null.
Where to send the money when type is bank_transfer, otherwise null.
Show child attributes
Pay by then, or the booking is cancelled.
Account to send the money to.
Bank identifier.
Put this in the transfer's reference so we can match it.
Refunds of this payment, oldest first.
Show child attributes
Why the money went back.
Bank transfer refunds stay pending for a few days.
When the refund was created.
Refund id.
Payment refunded.
Amount refunded, in cents.
ISO 4217 currency code.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
true when this is the stored response to an earlier request with the same key.
400The body is invalid, or the `Idempotency-Key` header is missing.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
401Authentication is missing or invalid.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
403Authenticated, but not allowed to do this.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
404No booking with this id.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
409The booking is cancelled or already paid.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
422This `Idempotency-Key` was already used with a different request.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
Seconds to wait before retrying.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
500Something failed on the server. Retry with backoff.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
curl http://localhost:3010/v1/bookings/bk_9Rz4Wt/payments \
--request POST \
--header 'x-api-key: YOUR_API_KEY' \
--header 'Idempotency-Key: 8e03978e-40d5-43e8-bc93-6894a57f9324' \
--header 'Content-Type: application/json' \
--data '{
"metadata": {
"orderId": "order-8812",
"channel": "web"
},
"type": "card",
"token": "tok_visa_4242",
"saveCard": true
}'{
"status": "succeeded",
"failureCode": "card_declined",
"failureMessage": "The card was declined.",
"metadata": {
"orderId": "order-8812",
"channel": "web"
},
"createdAt": "2026-10-03T12:01:00Z",
"id": "pay_3kTq9Z",
"bookingId": "bk_7Hq2xP",
"amount": 1299900,
"amountRefunded": 0,
"currency": "USD",
"method": {
"type": "card",
"card": {
"brand": "visa",
"last4": "4242",
"expMonth": 8,
"expYear": 2033
},
"wallet": null,
"bankTransfer": {
"dueAt": "2026-10-11T12:00:00Z",
"iban": "DE89370400440532013000",
"bic": "COBADEFFXXX",
"reference": "ORBIT-BK7HQ2XP"
}
},
"refunds": [
{
"reason": "requested_by_customer",
"status": "succeeded",
"createdAt": "2026-10-05T10:00:00Z",
"id": "re_c81Hq0",
"paymentId": "pay_3kTq9Z",
"amount": 1299900,
"currency": "USD"
}
]
}