OrbitDocs packages are coming to npm soon. Until then, run it from the GitHub repo →
v1.0.0OpenAPI 3.1.1

Demo: Orbit Travel API

Download OpenAPI Document

Search destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.

Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.

Server
Local
Authentication Required
Your API key. The sample server accepts `otk_test_4f9a2c1b8e7d6a5f`.
x-api-key:
Client Libraries
Shell

Authentication

Create an access token

Create a webhook endpoint

List webhook endpoints

Delete a webhook endpoint

Send a test event

Auth Required

Sends a signed sample event to the endpoint right away and reports how your server answered, so you can check signature verification before real traffic arrives. The endpoint does not have to subscribe to the event type. Test events are not listed by List events.

Path Parameters

idstringrequired

Endpoint id.

Example: whe_91ka2

Bodyrequiredapplication/json

typestring

Event type to send, with sample data.

Default: booking.confirmed

Responses

200OK
application/json
statusstringrequired

succeeded when your endpoint answered with a 2xx status.

Example: succeeded
responseStatusnumber | nullrequired

HTTP status your endpoint answered with; null if it could not be reached.

Example: 200
errorstring | nullrequired

Why the delivery failed; null when it succeeded.

Example: connect ECONNREFUSED
deliveredAtstring · date-timerequired

When the delivery was attempted.

Example: 2026-10-04T09:00:00Z
idstringrequired

Delivery id.

Example: whd_s0Ue4M
endpointIdstringrequired

Endpoint the event was sent to.

Example: whe_91ka2
durationMsnumberrequired

Round trip, in milliseconds.

Example: 182
signaturestringrequired

Orbit-Signature header sent: hex HMAC-SHA256 of the body with the endpoint secret.

Example: 5d41402abc4b2a76b9719d911017c592ae2f7c1d6a3e8f2b0c4d5e6f7a8b9c0d
eventEventDtorequired

The event that was sent, exactly as your endpoint received it.

Show child attributes
typestringrequired

What happened.

Example: booking.confirmed
createdAtstring · date-timerequired

When the event happened.

Example: 2026-10-03T12:00:01Z
idstringrequired

Event id. Deliveries of the same event share it, so use it to skip duplicates.

Example: evt_N3wB9k
apiVersionstringrequired

API version the payload is shaped by.

Example: 2031-01-01
dataEventDataDtorequired

What changed.

Show child attributes
objectBookingDto | PaymentDtorequired

The object the event is about, as it was right after the change: a booking for booking.* events, a payment for payment.* events.

previousAttributesobject | nullrequired

For booking.changed: the changed fields with their previous values. null for other events.

Example: {"seats":[]}
Headers
X-RateLimit-Limitinteger

Requests allowed per minute for this credential.

Example: 60
X-RateLimit-Remaininginteger

Requests left in the current window.

Example: 59
X-RateLimit-Resetinteger

When the window resets, in Unix seconds.

Example: 1949398800
400The request is invalid: a parameter or body field failed validation.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
401Authentication is missing or invalid.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
403Authenticated, but not allowed to do this.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
404No webhook endpoint with this id.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
Headers
Retry-Afterinteger

Seconds to wait before retrying.

Example: 42
X-RateLimit-Limitinteger

Requests allowed per minute for this credential.

Example: 60
X-RateLimit-Remaininginteger

Requests left in the current window.

Example: 59
X-RateLimit-Resetinteger

When the window resets, in Unix seconds.

Example: 1949398800
500Something failed on the server. Retry with backoff.
application/json
statusCodeintegerrequired

HTTP status code, repeated in the body.

Example: 404
messagestring | string[]required

What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.

Example: Booking not found
errorstring

Short name of the status.

Example: Not Found
POST/v1/webhook-endpoints/{id}/test
curl http://localhost:3010/v1/webhook-endpoints/whe_91ka2/test \
  --request POST \
  --header 'x-api-key: YOUR_API_KEY' \
  --header 'Content-Type: application/json' \
  --data '{
  "type": "booking.confirmed"
}'
{
  "status": "succeeded",
  "responseStatus": 200,
  "error": "connect ECONNREFUSED",
  "deliveredAt": "2026-10-04T09:00:00Z",
  "id": "whd_s0Ue4M",
  "endpointId": "whe_91ka2",
  "durationMs": 182,
  "signature": "5d41402abc4b2a76b9719d911017c592ae2f7c1d6a3e8f2b0c4d5e6f7a8b9c0d",
  "event": {
    "type": "booking.confirmed",
    "createdAt": "2026-10-03T12:00:01Z",
    "id": "evt_N3wB9k",
    "apiVersion": "2031-01-01",
    "data": {
      "object": {},
      "previousAttributes": {
        "seats": []
      }
    }
  }
}

Models

BankTransferInstructionsDto
BankTransferPaymentRequestDto
BoardingGroup Boarding group, called in order.
BoardingPassDto
BoardingPassFormat
BoardingPassPassengerDto
BookingDto
BookingListDto
BookingStatus Where the booking is in its life.
CabinClass Cabin.
CabinSeatMapDto
CancelBookingDto
CardBrand Card network.
CardDetailsDto
CardPaymentRequestDto
Climate
CreateBookingDto
CreatePassengerDto
CreateRedemptionDto
CreateRefundDto
CreateSeatHoldDto
CreateWebhookEndpointDto
DestinationDto
DestinationListDto
DocumentKind What the document is, detected from the scan.
DocumentStatus Review status. Boarding needs a verified passport.
EventDataDto
EventDto
EventListDto
FareDto
FlightDto
FlightListDto
GrantType Always `client_credentials`.
LegacyFlightSearchDto
LoyaltyAccountDto
LoyaltyTier Current tier, from lifetime points.
LoyaltyTransactionDto
LoyaltyTransactionListDto
LoyaltyTransactionType
MealPreference Meal served on board.
OAuthErrorCode Machine-readable error code.
OAuthErrorDto
PageInfoDto
PassengerDto
PassengerListDto
PassengerProfileDto
PassportDto
PaymentDto
PaymentMethodDetailsDto
PaymentMethodType How the payment was made. Exactly one of the objects below is set.
PaymentStatus Where the payment is in its life.
RedemptionDto
RedemptionStatus Redemptions complete immediately.
RefundDto
RefundReason Why the money went back.
RefundStatus Bank transfer refunds stay `pending` for a few days.
RewardType Reward to buy. Costs: `cabin_upgrade` 40,000, `booking_credit` 10,000 ($100 off), `extra_baggage` 8,000, `lounge_access` 5,000.
SeatDto
SeatFeature What makes this seat different.
SeatHoldDto
SeatHoldStatus Active until it is used on a booking or expires.
SeatMapDto
SeatPreference Preferred seat, used when seats are auto-assigned.
SeatPriceDto
SeatRowDto
SeatStatus Whether the seat can be held.
TestWebhookEndpointDto
TierProgressDto
TokenRequestDto
TokenResponseDto
TravelDocumentDto
TravelDocumentListDto
TravelPreferencesDto
UpdateBookingDto
UpdatePassengerDto
UpdateTravelPreferencesDto
UploadDocumentDto
WalletPaymentRequestDto
WalletType Wallet the token comes from.
WebhookDeliveryDto
WebhookDeliveryStatus `succeeded` when your endpoint answered with a 2xx status.
WebhookEndpointDto
WebhookEndpointListDto
WebhookEvent