Skip to main content

Xedos transport

Build with the transport network

Published schedules, current service updates, signed events and — for travel partners — seat booking.

Partner Booking API

For travel partners

For aggregators and travel agencies that sell this operator’s bus seats: search departures, show the seat map, block seats, confirm bookings with a PNR and cancel under the operator’s cancellation policy. Every seat comes from the same live inventory as the operator’s own website, so a seat is never sold twice.

Partners are onboarded after an agreement with the operator. Before that, the operator can issue sandbox keys that only reach a sandbox connection, so your team can build and test the integration. Live keys are issued only after certification and approval by a second person at the operator.

Each request carries your API key and an HMAC-SHA256 signature over the timestamp, a one-time nonce, the method, the path and the body. Sandbox and live keys never cross over.

Read the Partner API guideOpenAPI 3.1 description

Start with authentication

Register an application, accept the current terms and select the scopes you need. A sandbox application can issue a key for integration development. Production access requires approval by another authorised operator.

Send your key in Authorization: Bearer <key> and the operator’s organisation ID in X-Organisation-Id. Keys are shown once, expire on their recorded date, and can be revoked. IP restrictions and the application’s rate limit apply on each request. Public feeds need the organisation header but not a key.

Download synthetic data from /developers/sandbox/static.zip using a sandbox key. Keep keys in a server-side secret manager. A sandbox key cannot read a production feed.

Feed endpoints

ResourcePathFormat
Published timetable/gtfs/:feedCode/static.zipGTFS CSV archive
Trip predictions/gtfs-rt/:feedCode/trip-updates.pbGTFS Realtime protobuf
Vehicle positions/gtfs-rt/:feedCode/vehicle-positions.pbGTFS Realtime protobuf
Service alerts/gtfs-rt/:feedCode/alerts.pbGTFS Realtime protobuf

Use the static feed version with its realtime feed. Realtime data is a full dataset. Missing positions may be suppressed stale fixes; do not keep displaying an old location as current. Overnight stop times use hours beyond 24, for example 29:20:00.

Webhooks are delivered at least once

Deduplicate by X-Tms-Event-Id

Delivery is ordered per subscription and aggregate. Store each event ID before applying its effects. A successful HTTP response may be lost and the event may arrive again. Your sandbox must tolerate duplicates, including deliberately repeated events during integration exercises.

Your HTTPS endpoint must echo the challenge value from its verification request. Redirects are refused. HTTP 400–499 responses, except 429, are terminal. Transient failures retry up to eight times at 0 seconds, 15 seconds, 60 seconds, 5 minutes, 30 minutes, 2 hours, 6 hours and 24 hours, with jitter. Twenty consecutive failures disable the subscription.

X-Tms-Signature: t=<unix-seconds>,v1=<hex-signature>
X-Tms-Event-Id: <stable-event-id>
X-Tms-Event-Type: tms.gtfs-feed.published.v1
X-Tms-Delivery-Attempt: 1
X-Tms-Secret-Epoch: 2

signature = HMAC_SHA256(secret, timestamp + "." + raw_request_body)

{"eventId":"...","eventType":"tms.gtfs-feed.published.v1",
 "data":{"feedId":"...","feedVersion":"operator-42","archiveSha256":"..."}}

Verify against the exact request bytes with a constant-time comparison. Reject timestamps more than 300 seconds from your clock. Secret rotation overlaps for 24 hours; the current epoch is identified by X-Tms-Secret-Epoch, and the previous signature appears as v0 with X-Tms-Previous-Secret-Epoch.

Supported events and payload fields are available from /developers/catalogue. Your sandbox request log is available on the credentials page. Any approved partner key can read its own application log at /developers/requests using the same bearer key and organisation header. The log contains request paths and timestamps, never credentials.

GTFS Schedule reference · GTFS Realtime wire specification