Demo: Orbit Travel API
Download OpenAPI DocumentSearch destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.
Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.
Authentication
Create an access token
Destinations
List destinations
Get a destination
Flights
Search flights
Get a flight
Legacy flight searchDeprecated
Seats
Get a seat map
Hold seats
Create a booking
List bookings
Get a booking
Update a booking
Cancel a booking
Upload a travel documentbeta
List travel documents
Download a boarding pass
Create a passenger
List passengers
Get a passenger
Update a passenger
Delete a passenger
Pay for a booking
Get a payment
Refund a payment
Get the loyalty account
List loyalty transactions
Redeem points
Events
List events
Get an event
Create a webhook endpoint
List webhook endpoints
Delete a webhook endpoint
Send a test event
Sends a signed sample event to the endpoint right away and reports how your server answered, so you can check signature verification before real traffic arrives. The endpoint does not have to subscribe to the event type. Test events are not listed by List events.
Path Parameters
Endpoint id.
Bodyrequiredapplication/json
Event type to send, with sample data.
Responses
200OK
succeeded when your endpoint answered with a 2xx status.
HTTP status your endpoint answered with; null if it could not be reached.
Why the delivery failed; null when it succeeded.
When the delivery was attempted.
Delivery id.
Endpoint the event was sent to.
Round trip, in milliseconds.
Orbit-Signature header sent: hex HMAC-SHA256 of the body with the endpoint secret.
The event that was sent, exactly as your endpoint received it.
Show child attributes
What happened.
When the event happened.
Event id. Deliveries of the same event share it, so use it to skip duplicates.
API version the payload is shaped by.
What changed.
Show child attributes
The object the event is about, as it was right after the change: a booking for booking.* events, a payment for payment.* events.
For booking.changed: the changed fields with their previous values. null for other events.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
400The request is invalid: a parameter or body field failed validation.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
401Authentication is missing or invalid.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
403Authenticated, but not allowed to do this.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
404No webhook endpoint with this id.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
Seconds to wait before retrying.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
500Something failed on the server. Retry with backoff.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
curl http://localhost:3010/v1/webhook-endpoints/whe_91ka2/test \
--request POST \
--header 'x-api-key: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{
"type": "booking.confirmed"
}'{
"status": "succeeded",
"responseStatus": 200,
"error": "connect ECONNREFUSED",
"deliveredAt": "2026-10-04T09:00:00Z",
"id": "whd_s0Ue4M",
"endpointId": "whe_91ka2",
"durationMs": 182,
"signature": "5d41402abc4b2a76b9719d911017c592ae2f7c1d6a3e8f2b0c4d5e6f7a8b9c0d",
"event": {
"type": "booking.confirmed",
"createdAt": "2026-10-03T12:00:01Z",
"id": "evt_N3wB9k",
"apiVersion": "2031-01-01",
"data": {
"object": {},
"previousAttributes": {
"seats": []
}
}
}
}