For travel partners
Partner Booking API guide
Search, seat maps, seat blocks, confirmations and cancellations from the operator’s live inventory.
Before you start
Partners are onboarded after an agreement with the operator. Until then the operator can give you sandbox credentials that work only against a sandbox connection and test services. Live credentials are issued after a certification test and approval by a second person at the operator.
You receive, once and through a secure channel: the operator id (X-Organisation-Id), an API key, its key id and a base64 request-signing secret. Keep them in a server-side secret store.
Signing every request
Send Authorization: Bearer <key> and four signing headers. The signature is hex(HMAC-SHA256(secret, timestamp + "." + nonce + "." + METHOD + "." + path + "." + sha256hex(body))), where the secret is the base64-decoded signing secret, path starts at /transport/partner/v1 including the query string, and body is the exact bytes sent (empty for GET).
- Timestamps must be within 300 seconds of our clock.
- Every nonce is accepted once per key; a repeat is refused.
- Send
Idempotency-Keyon every POST so a retry never books twice.
import crypto from 'node:crypto';
// path starts with /transport/partner/v1 and includes the query string
function signedHeaders({ key, keyId, org, secretB64 }, method, path, rawBody = '') {
const timestamp = String(Math.floor(Date.now() / 1000));
const nonce = crypto.randomBytes(16).toString('hex');
const bodySha = crypto.createHash('sha256').update(rawBody).digest('hex');
const signature = crypto.createHmac('sha256', Buffer.from(secretB64, 'base64'))
.update(`${timestamp}.${nonce}.${method.toUpperCase()}.${path}.${bodySha}`).digest('hex');
return { Authorization: `Bearer ${key}`, 'X-Organisation-Id': org, 'X-Tms-Key-Id': keyId,
'X-Tms-Timestamp': timestamp, 'X-Tms-Nonce': nonce, 'X-Tms-Signature': signature };
}TS=$(date +%s); NONCE=$(openssl rand -hex 16) PATH_Q='/transport/partner/v1/availability?from=LOC_BLR&to=LOC_HYD&date=2026-10-01' KEY_HEX=$(printf '%s' "$SECRET_B64" | base64 -d | od -An -v -tx1 | tr -d ' \n') BODY_SHA=$(printf '' | openssl dgst -sha256 -hex | sed 's/^.* //') SIG=$(printf '%s' "$TS.$NONCE.GET.$PATH_Q.$BODY_SHA" | openssl dgst -sha256 -mac HMAC -macopt "hexkey:$KEY_HEX" -hex | sed 's/^.* //') curl -sS "$API$PATH_Q" -H "Authorization: Bearer $KEY" -H "X-Organisation-Id: $ORG" \ -H "X-Tms-Key-Id: $KEY_ID" -H "X-Tms-Timestamp: $TS" -H "X-Tms-Nonce: $NONCE" -H "X-Tms-Signature: $SIG"
Endpoints
Base URL: https://xedos.co.in/api/transport/partner/v1
| Request | Scope | Purpose |
|---|---|---|
GET /availability?from&to&date | inventory:read | Departures on sale through your channel, seats available and an indicative fare |
GET /services/{serviceId}/seat-layout | inventory:read | Seat map with deck, berth, seat type and ladies-only flags; only your sellable seats are available |
GET /services/{serviceId}/boarding-points | inventory:read | Boarding and dropping points with times |
GET /cancellation-policy | inventory:read | Refund slabs by hours before departure |
POST /quotes | booking:write | Binding price for exact seats (valid about 15 minutes) |
POST /holds | booking:write | Block the quoted seats for about 9 minutes; returns a block key |
POST /holds/{blockKey}/confirm | booking:write | Confirm after your customer pays; returns the PNR and ticket numbers |
POST /holds/{blockKey}/release | booking:write | Release a block you will not confirm |
GET /bookings/{ref} | booking:write | Booking status by your reference |
GET /bookings/{ref}/cancellation-preview | booking:write | Refund if cancelled now |
POST /bookings/{ref}/cancel | booking:write | Cancel under the active policy; returns the refund |
A booking is always block, then confirm. Money is integer paise as strings. Errors are {"error":{"code","message","retryable"}} with stable codes listed in the OpenAPI document.
Webhooks
The operator can send booking.confirmed, booking.cancelled, inventory.stop_sell, inventory.stop_sell_lifted and fare.changed to your HTTPS endpoint — only for your own channel, never with passenger personal data. Delivery is at least once; deduplicate on X-Tms-Event-Id and verify X-Tms-Signature as described on the developer overview.