Authentication
Two ways to authenticate, both bound to your key ID: signed requests (recommended) or OAuth 2 client-credentials bearer tokens.
Signed requests (HMAC-SHA256)
Send X-API-Key, X-Timestamp, X-Nonce and X-Signature on every call. The signature covers the method, the exact request target (path and query), the timestamp, the nonce and the body hash, so a replayed or altered request fails verification. Clock skew of up to five minutes is tolerated; reuse of a nonce within ten minutes is rejected with 401 api_nonce_reused.
Compute the signature over the raw bytes you put on the wire. Serialize your JSON once, hash those exact bytes, and send the same bytes as the body — re-serializing after signing is the most common cause of api_signature_invalid.
const payload = JSON.stringify(body);
const ts = Math.floor(Date.now() / 1000);
const nonce = randomBytes(16).toString("hex");
const bodyHash = createHash("sha256").update(payload).digest("hex");
const canonical = ["POST", "/v1/flights/search", ts, nonce, bodyHash].join("\n");
const signature = createHmac("sha256", SECRET).update(canonical).digest("hex");OAuth 2 client credentials
If signing every request does not fit your stack, exchange your key ID and secret for a short-lived bearer token at POST /v1/oauth/token (grant_type=client_credentials, form-encoded). Tokens live 30 minutes and carry your granted scopes; you may request a subset with the scope parameter.
Send the token as Authorization: Bearer together with X-API-Key on every call. The key ID is re-checked on each request, so revoking a key invalidates its tokens immediately.
curl -X POST "https://api.dubaitrip.com/v1/oauth/token" \
-d grant_type=client_credentials -d client_id=$KEY_ID -d client_secret=$SECRETKey IDs, secrets and rotation
Sandbox keys start with dt_sbx_, production keys with dt_live_. A key belongs to one environment and one partner. Secrets are shown once — at creation, at rotation and through the reveal link — and stored hashed on our side.
Rotate from the developer portal: a new key ID and secret are issued while the old key keeps working for the grace period you choose (up to seven days), so you can switch without downtime. Revocation is immediate.
IP allow-list
Optionally pin each environment to a set of IPv4/IPv6 addresses or CIDR ranges in the developer portal. Requests from any other address are refused with 403 api_ip_not_allowed even when correctly signed. Leave the list empty to accept any origin.