Skip to content

Quick start

From sign-up to a booked flight in the sandbox, in five steps.

  1. 1. Get sandbox credentials
  2. 2. Sign every request
  3. 3. Make your first call
  4. 4. Complete a booking flow
  5. 5. Request production

1. Get sandbox credentials

Register on the Travel APIs page. Once your email is verified, your partner account exists and a sandbox key ID is shown on screen; the secret is delivered by a one-time reveal link sent to the same address. Store it in your secrets manager — it is displayed exactly once.

You also receive a temporary password for the developer portal, where you can create and rotate keys, set an IP allow-list, watch usage and request production.

2. Sign every request

Each call carries four headers: X-API-Key (your key ID), X-Timestamp (unix seconds), X-Nonce (16–128 random characters) and X-Signature — the lowercase hex HMAC-SHA256 of a canonical string, keyed with your secret.

The canonical string is five lines joined by a newline: the HTTP method in upper case, the path plus query string exactly as sent, the timestamp, the nonce, and the lowercase hex SHA-256 of the raw body (an empty body hashes as the SHA-256 of zero bytes). Timestamps must be within 300 seconds of our clock; a nonce can be used once within 10 minutes.

Canonical string
POST
/v1/flights/search
1763200000
Qm9vdGxlZ0Zha2VOb25jZQ
3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

3. Make your first call

Search for a flight against the sandbox. The sandbox is wired to our suppliers’ test environments, so searches return test inventory and prices, and a booking placed there is a test booking — no real ticket, no charge. Every reference page has a complete sample in cURL, Node.js, Python and PHP — copy it, fill in your key ID and secret, run it.

cURL
curl -X POST "https://api.dubaitrip.com/v1/flights/search" \
  -H "X-API-Key: $KEY_ID" -H "X-Timestamp: $TS" -H "X-Nonce: $NONCE" -H "X-Signature: $SIG" \
  -H "Content-Type: application/json" \
  -d '{"slices":[{"origin":"DXB","destination":"LHR","departureDate":"2026-11-15"}],"passengers":{"adults":1},"wait":true}'

4. Complete a booking flow

Flights: search → price the chosen offer → create the order with passengers and contact → issue the ticket → (optionally) quote and request a refund. Hotels: search → read the rooms of a property → check the rate → create the booking → (optionally) quote and cancel.

Offer IDs and rate keys are opaque and short-lived. Always price or check right before you commit: if the price moved you receive 409 price_changed with the new amount, and you decide.

5. Request production

When your integration completes the flow end to end in the sandbox, open the developer portal and request production. We review the sandbox activity (searches, an order, a booking, a cancellation) and your integration details, then switch your account: a production key pair is emailed through the same one-time reveal link. Same base URL — requests signed with the dt_live_ key reach the live suppliers and settle against your deposit; your sandbox key keeps working for testing.