Flights API: requests open. How it works

Flights API reference

Flights API documentation

How authentication, search, booking, errors and rate limits work. The public API opens in a later phase; the sandbox key is unlocked once your API access is approved. Request shapes below are examples.

Overview

The IATA.co flights API lets approved accounts run the same live flight search and booking as the booking portal, over HTTPS with JSON requests and responses. You search a route, read the fares our suppliers return, re-price the one you want and book it, paying from your prepaid balance.

Base URL: https://iata.co/api/v1. Every request is sent over HTTPS and carries your API key. Send and expect application/json.

Authentication and API keys

Authenticate with a bearer token: your API key in the Authorization header. You get a key after your API access request is approved; it is shown once, so store it securely. Only a SHA-256 hash of the key is kept on our side.

GET /api/v1/ping
Authorization: Bearer YOUR_API_KEY

HTTP/1.1 200 OK
{ "ok": true }

IP whitelisting

A key only answers requests from the server IP addresses you register for your account. A request from any other address is refused with 403, so a leaked key cannot be used to spend your balance or your search quota from elsewhere. Add or change your whitelisted IPs from your dashboard.

Rate limits and quotas

Each plan has a monthly search quota and a per-minute request limit. Every response carries headers that tell you where you stand; when you exceed the per-minute limit you get HTTP 429 with a Retry-After header. Identical searches within a short window are answered from cache (X-Cache: HIT) and do not count against your quota.

X-RateLimit-Limit: 60
X-RateLimit-Remaining: 59
X-RateLimit-Reset: 42
X-Cache: MISS

Price check and booking

Before a booking, the chosen fare is re-priced with the supplier, because fares and seats change. If it still holds, the booking is created and the amount is debited from your prepaid balance in one step; a booking can never be charged twice. The response returns the booking id, status, PNR and the price charged.

POST /api/v1/bookings
Authorization: Bearer YOUR_API_KEY

{ "search_id": "srch_8f2a61c0", "flight_id": "flt_01",
  "passengers": [ { "type": "adult", "given_name": "…",
    "family_name": "…", "passport": "…" } ] }

HTTP/1.1 201 Created
{ "id": "bk_00123", "status": "confirmed",
  "pnr": "6XK2QF", "price": 148.20, "currency": "USD" }

Errors

Errors use standard HTTP status codes with a JSON body: 400 for a malformed request, 401 for a missing or invalid key, 402 when your balance cannot cover a booking, 403 for a non-whitelisted IP, 404 for an unknown resource, 429 when you are rate-limited, and 5xx for a problem on our side. The body carries a stable error code and a human-readable message.

HTTP/1.1 402 Payment Required
{ "error": "insufficient_balance",
  "message": "Top up your balance to book this fare." }

Free to join

Your first flight search is a minute away.

Open a free account, top up when you are ready, and request API access whenever you want to build.

  • Free account
  • Prepaid balance
  • Keys locked to your server
  • Plan-based limits
Join our WhatsApp group