OrbitDocs packages are coming to npm soon. Until then, run it from the GitHub repo →
v1.0.0OpenAPI 3.1.1

Demo: Orbit Travel API

Download OpenAPI Document

Search destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.

Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.

Server
Local
Authentication Required
Your API key. The sample server accepts `otk_test_4f9a2c1b8e7d6a5f`.
x-api-key:
Client Libraries
Shell

Authentication

Create an access token

Get the loyalty account

List loyalty transactions

Redeem points

Auth Required

Spends points on a reward. The points leave the balance at once and a redeem transaction is recorded.

Bodyrequiredapplication/json

rewardstringrequired

Reward to buy. Costs: cabin_upgrade 40,000, booking_credit 10,000 ($100 off), extra_baggage 8,000, lounge_access 5,000.

Example: lounge_access
bookingIdstring

Booking the reward applies to. Required for cabin_upgrade and extra_baggage.

Example: bk_7Hq2xP

Responses

201Created
application/json
rewardstringrequired

Reward bought.

Example: lounge_access
bookingIdstring | nullrequired

Booking the reward applies to, or null.

Example: bk_7Hq2xP
statusstringrequired

Redemptions complete immediately.

Example: completed
createdAtstring · date-timerequired

When the points were spent.

Example: 2026-10-04T09:30:00Z
idstringrequired

Redemption id.

Example: rdm_4TzQ1n
pointsnumberrequired

Points spent.

Example: 5000
transactionIdstringrequired

Loyalty transaction that took the points.

Example: ltx_5RbX0c
Headers
X-RateLimit-Limitinteger

Requests allowed per minute for this credential.

Example: 60
X-RateLimit-Remaininginteger

Requests left in the current window.

Example: 59
X-RateLimit-Resetinteger

When the window resets, in Unix seconds.

Example: 1949398800
400The request is invalid: a parameter or body field failed validation.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
401Authentication is missing or invalid.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
403Authenticated, but not allowed to do this.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
404No booking with this id.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
409Not enough points for this reward.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
422This reward needs a `bookingId`.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
Headers
Retry-Afterinteger

Seconds to wait before retrying.

Example: 42
X-RateLimit-Limitinteger

Requests allowed per minute for this credential.

Example: 60
X-RateLimit-Remaininginteger

Requests left in the current window.

Example: 59
X-RateLimit-Resetinteger

When the window resets, in Unix seconds.

Example: 1949398800
500Something failed on the server. Retry with backoff.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
POST/v1/loyalty/redemptions
curl http://localhost:3010/v1/loyalty/redemptions \
  --request POST \
  --header 'x-api-key: YOUR_API_KEY' \
  --header 'Content-Type: application/json' \
  --data '{
  "reward": "lounge_access",
  "bookingId": "bk_7Hq2xP"
}'
{
  "reward": "lounge_access",
  "bookingId": "bk_7Hq2xP",
  "status": "completed",
  "createdAt": "2026-10-04T09:30:00Z",
  "id": "rdm_4TzQ1n",
  "points": 5000,
  "transactionId": "ltx_5RbX0c"
}

Models

BankTransferInstructionsDto
BankTransferPaymentRequestDto
BoardingGroup Boarding group, called in order.
BoardingPassDto
BoardingPassFormat
BoardingPassPassengerDto
BookingDto
BookingListDto
BookingStatus Where the booking is in its life.
CabinClass Cabin.
CabinSeatMapDto
CancelBookingDto
CardBrand Card network.
CardDetailsDto
CardPaymentRequestDto
Climate
CreateBookingDto
CreatePassengerDto
CreateRedemptionDto
CreateRefundDto
CreateSeatHoldDto
CreateWebhookEndpointDto
DestinationDto
DestinationListDto
DocumentKind What the document is, detected from the scan.
DocumentStatus Review status. Boarding needs a verified passport.
EventDataDto
EventDto
EventListDto
FareDto
FlightDto
FlightListDto
GrantType Always `client_credentials`.
LegacyFlightSearchDto
LoyaltyAccountDto
LoyaltyTier Current tier, from lifetime points.
LoyaltyTransactionDto
LoyaltyTransactionListDto
LoyaltyTransactionType
MealPreference Meal served on board.
OAuthErrorCode Machine-readable error code.
OAuthErrorDto
PageInfoDto
PassengerDto
PassengerListDto
PassengerProfileDto
PassportDto
PaymentDto
PaymentMethodDetailsDto
PaymentMethodType How the payment was made. Exactly one of the objects below is set.
PaymentStatus Where the payment is in its life.
RedemptionDto
RedemptionStatus Redemptions complete immediately.
RefundDto
RefundReason Why the money went back.
RefundStatus Bank transfer refunds stay `pending` for a few days.
RewardType Reward to buy. Costs: `cabin_upgrade` 40,000, `booking_credit` 10,000 ($100 off), `extra_baggage` 8,000, `lounge_access` 5,000.
SeatDto
SeatFeature What makes this seat different.
SeatHoldDto
SeatHoldStatus Active until it is used on a booking or expires.
SeatMapDto
SeatPreference Preferred seat, used when seats are auto-assigned.
SeatPriceDto
SeatRowDto
SeatStatus Whether the seat can be held.
TestWebhookEndpointDto
TierProgressDto
TokenRequestDto
TokenResponseDto
TravelDocumentDto
TravelDocumentListDto
TravelPreferencesDto
UpdateBookingDto
UpdatePassengerDto
UpdateTravelPreferencesDto
UploadDocumentDto
WalletPaymentRequestDto
WalletType Wallet the token comes from.
WebhookDeliveryDto
WebhookDeliveryStatus `succeeded` when your endpoint answered with a 2xx status.
WebhookEndpointDto
WebhookEndpointListDto
WebhookEvent