Guide

How to get flight API access: every path explained

Every flight startup hits the same wall: the product is designed, the developers are ready, and nobody will give you an API key. This guide walks through the four realistic access paths, the documents suppliers typically ask for, the journey from sandbox to production, and the reasons applications get rejected.

Short answer: there are four ways in. Hold your own IATA (or ARC) accreditation and sign directly with a GDS or airline; use a consolidator or host agency's credentials and ticket under their authority; sign up with an API aggregator that sells bookable content without requiring your accreditation; or start with affiliate and search-only feeds that pay commission on redirects. Which door opens for you depends on your company documents, financials and expected volumes, not on your code.

Advertisement

Why flight APIs are gated

Flight content is not open data. Ticketing moves money through settlement systems (IATA's BSP, or ARC in the US) that require accreditation and financial guarantees; airlines and GDSs police look-to-book ratios because search traffic costs them compute; and fraud in air ticketing is a constant. So every supplier asks the same underlying questions before issuing production keys: who are you legally, can you pay, will your traffic be sane, and who takes the loss if a booking goes wrong. Understand that, and the paperwork below stops feeling arbitrary.

The four access paths

Four paths to flight API access ordered by control and difficulty: own accreditation with direct deals, consolidator credentials, aggregator signup, and affiliate feeds 1. Own IATA/ARC + direct GDS or airline agreementsMost control, most requirements, longest setup 2. Consolidator / host agency credentialsTheir ticketing authority, your storefront; common in India and worldwide 3. Aggregator signup (API-first platforms)Fastest bookable access; usage-based fees; their carrier list 4. Affiliate and search-only programmesNo ticketing at all; commission on redirects; lowest barrier
Most new businesses enter at path 3 or 4 and move up as volumes and accreditation arrive.

Path 1: your own accreditation and supplier deals

The full-control route: your agency gains IATA accreditation (IATA now offers tiered models, GoLite, GoStandard and GoGlobal, with different financial requirements depending on whether you need cash ticketing), then signs subscriber agreements with a GDS such as Amadeus, Sabre or Travelport, or joins airline NDC programmes directly. You issue your own tickets and own the economics, but you also carry the financial guarantees and compliance load. Expect months, not weeks. We cover the accreditation process itself in our IATA accreditation guide and the technical side under GDS integration.

Path 2: consolidator or host agency credentials

A consolidator is an accredited wholesaler that resells air content, often with net fares, to sub-agents. Instead of your own accreditation you sign a sub-agent agreement, place a security deposit or maintain a prepaid balance, and receive API credentials that book and ticket under the consolidator's authority. In India this is the dominant model: platforms such as TBO and Tripjack expose exactly this kind of B2B API to registered agents; our TBO and Tripjack integration pages describe the technical shape. The trade-offs are dependence on the consolidator's terms and fares, and markups baked into some content.

Advertisement

Path 3: aggregator signup

API-first platforms aggregate airlines behind one modern API and, in managed models, let you sell without your own IATA or ARC accreditation because bookings run under the platform's supplier relationships (Duffel, for example, states this explicitly for its managed content). Onboarding is online: company details, activation checks, then production keys with usage-based fees. It is the fastest route to actually bookable content, bounded by the platform's carrier list and pricing. This path and the previous two can be combined; multi-source search is standard in the portals we build under flight API integration.

Path 4: affiliate and search-only programmes

If you only need to show fares and earn on referrals, affiliate programmes from metasearch players and OTAs provide search feeds or white-label widgets and pay commission on redirects or completed bookings, with no ticketing on your side. Barriers are low (a working website and an application form), which makes this the classic starting point for content and traffic businesses that may later upgrade to bookable APIs.

Documents suppliers typically ask for

Typical documentation requests across access paths
DocumentWho asks for itWhy
Company registration / incorporation certificateEveryoneProof you are a legal entity, matching the name on the agreement
Tax registrations (for example GST and PAN in India)GDSs, consolidators, aggregatorsInvoicing and local compliance
Business address proof and KYC of directorsGDSs, consolidatorsAnti-fraud and settlement risk checks
Bank details, and often a deposit or bank guaranteeConsolidators, BSP/IATASecuring ticketing exposure
Financial statements or proof of fundsIATA accreditation, some GDS dealsFinancial criteria for accreditation tiers
Website / product description and expected volumesEveryoneAssessing look-to-book, fraud surface and commercial fit
Travel trade licence where applicableMarket-dependentSome jurisdictions regulate selling travel

Not every supplier asks for everything; aggregators sit at the light end, IATA accreditation at the heavy end (IATA's own accreditation pages list the current criteria per model and market).

From sandbox to production

  • Sandbox first: build against test credentials with fake inventory; expect test fares and PNRs that behave slightly differently from production
  • Certification: GDSs and some consolidators review your booking flows (search, price, book, cancel, error handling) before granting live keys
  • Look-to-book limits: production keys come with search caps or ratios; caching and debounced search UIs keep you inside them
  • Commercial go-live: deposits funded, agreements countersigned, fraud rules configured, then live keys are issued
  • Controlled ramp: launch on a few routes, reconcile the first tickets against invoices, then scale traffic

Common rejection reasons

  1. No legal entity or mismatched names between the application, the website and the bank account.
  2. No working product or website: suppliers want evidence you are a real business, not a domain and a deck.
  3. Unrealistic volume claims, or a business model that is all search and no bookings.
  4. High-risk signals: markets or verticals with heavy fraud, unclear source of funds, or directors failing KYC.
  5. Insufficient financials for the accreditation tier or deposit requested.
  6. Policy conflicts, such as implying airline affiliation on your site, which also breaks advertising rules.

Most rejections are fixable: incorporate properly, launch a credible site, start on a lighter path and reapply with trading history. Sources: IATA travel agent accreditation pages (GoLite, GoStandard, GoGlobal); Duffel published access terms; supplier onboarding documentation from GDSs and Indian consolidator platforms. Requirements differ by market and change over time, so confirm current criteria with each supplier.

This article is general information about travel technology and online marketing. It is not legal, tax or financial advice, and advertising platform policies change often. Check the current policy documents and take professional advice for your own situation.

Advertisement

Frequently asked questions

Can I get a flight booking API with no company registered?

For bookable content, effectively no: every serious supplier contracts with a legal entity. Without a company you are limited to affiliate feeds, and even those programmes usually prefer registered businesses. Incorporate first; it is the cheapest unblocking step in the whole process.

How long does flight API access take?

It varies by path: aggregator onboarding can be days to weeks; consolidator agreements typically weeks including deposits and KYC; your own IATA accreditation plus a GDS agreement is usually a multi-month project. Build and certification time comes on top of access itself.

Do I need IATA accreditation to sell flights online?

No. Consolidator credentials and managed aggregator models let you sell under someone else's accreditation, and affiliate models avoid ticketing entirely. Accreditation becomes worthwhile when volumes are high enough that owning ticketing economics beats paying an intermediary.

What is a look-to-book ratio and why does it matter?

It is the number of searches per completed booking. Suppliers cap it because search costs them infrastructure. Exceeding your ratio can mean throttling, fees or losing access, so production systems cache results and avoid firing searches on every keystroke.

Which path is best for an Indian startup?

Most Indian startups begin with consolidator APIs for domestic content and net fares, sometimes adding a global aggregator for international NDC and low-cost coverage. Own accreditation tends to come later, once volumes and financials support it. Your mix depends on routes and margins.

WhatsApp us