Demo: Orbit Travel API
Download OpenAPI DocumentSearch destinations, flights and seat maps, book and pay, manage saved passengers and Orbit Miles, and receive booking and payment events by webhook or from the Events API.
Every request needs an API key in the x-api-key header, or an OAuth access token from Create an access token in Authorization: Bearer …. Each credential can make 60 requests a minute.
Authentication
Create an access token
Destinations
List destinations
Get a destination
Flights
Search flights
Get a flight
Legacy flight searchDeprecated
Seats
Get a seat map
Hold seats
Create a booking
List bookings
Get a booking
Update a booking
Changes a booking: correct passenger details, choose seats or change
your reference. Send only what changes. Seats come one per passenger, in
passenger order; assign held seats by sending the hold's holdId. A
booking.changed webhook follows, with the previous values.
Path Parameters
Booking id.
Bodyrequiredapplication/json
Your reference; null removes it.
Corrected passenger details, same number and order as on the booking. To add or remove passengers, cancel and book again.
Show child attributes
Full name as on the travel document.
Contact email for boarding updates.
Seat numbers, one per passenger in the same order. Each must be free,
held by holdId, or already on this booking.
Seat hold whose seats you are assigning; it is used up.
Responses
200OK
Where the booking is in its life.
Cabin booked.
When the booking was created.
Booking id.
Flight booked.
Everyone travelling.
Show child attributes
Full name as on the travel document.
Contact email for boarding updates.
Total charged, in cents.
ISO 4217 currency code.
Travel documents uploaded for this booking.
Seat numbers, one per passenger in the same order. Empty until seats are chosen with Update a booking.
Your reference, if you sent one.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
400The request is invalid: a parameter or body field failed validation.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
401Authentication is missing or invalid.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
403Authenticated, but not allowed to do this.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
404No booking with this id, or no active hold with `holdId`.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
409The booking is cancelled, or a seat is taken.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
422The number of passengers or seats does not match the booking, or a seat is in another cabin.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
429Too many requests: more than 60 a minute. Wait `Retry-After` seconds, then retry.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
Seconds to wait before retrying.
Requests allowed per minute for this credential.
Requests left in the current window.
When the window resets, in Unix seconds.
500Something failed on the server. Retry with backoff.
HTTP status code, repeated in the body.
What went wrong, for people. Validation failures list one entry per problem. Do not branch on this text.
Short name of the status.
curl http://localhost:3010/v1/bookings/bk_7Hq2xP \
--request PATCH \
--header 'x-api-key: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{
"reference": "order-8812-b",
"passengers": [
{
"name": "Ada Lovelace",
"email": "ada@example.com"
}
],
"seats": [
"24A",
"24B"
],
"holdId": "sh_Lq83Zt"
}'{
"status": "confirmed",
"cabin": "economy",
"createdAt": "2026-10-03T12:00:00Z",
"id": "bk_7Hq2xP",
"flightId": "flt_2031_proxima",
"passengers": [
{
"name": "Ada Lovelace",
"email": "ada@example.com"
}
],
"totalAmount": 2599800,
"currency": "USD",
"reference": "order-8812",
"documents": [
"passport-ada.pdf"
],
"seats": [
"24A",
"24B"
]
}