Travelport TripServices APIs

by Travelport HTTP API in Travel & booking

Hosted

Travelport, LP · travelport.com since 2001 · who's behind it

Travelport TripServices is a set of REST JSON APIs on the Travelport global distribution system. It searches, prices, books, tickets, exchanges and cancels flights, books and cancels hotel stays, and authorises payment cards, for travel sellers under contract.

Good for A travel agency, travel management company or travel platform that will sign a GDS contract and wants GDS, NDC and low-cost air content with full servicing plus hotels.

Is this your product? Claim this listing or verify it

Assessment. Public OpenAPI 3.0 files, Markdown docs and an llms.txt cover search, pricing, booking, ticketing, exchanges and hotel stays, with dated release notes through August 2026. Production needs a sales contract and certification with 15 days' notice. No price, API rate limit, status page or SLA is published, and the terms bar automated tools without written permission.

Facts

Transport
HTTP
Endpoint
https://api.travelport.net
Auth
OAuth
Pricing
Paid · Paid
x402
No
Licence
Proprietary service under a Developer Contract and Travelport's API and SDK Terms of Use
llms.txt
published
Last release
APIs
Flights (OpenAPI 3.0, version 11.36.0, 101 operations), Stays (11.36.0, 22 operations, with a version 12 SearchComplete flow) and Pay (11.34.0, 2 operations)
Hosts
Production https://api.travelport.net/11/air/, /11/hotel/, /12/hotel/ and /11/payment/. Pre-production on https://api.pp.travelport.net. Tokens from https://auth.travelport.net/oauth/token
Content
Travelport says 400+ airlines across GDS, NDC and low-cost carriers, and hotels in 180 countries, including Expedia and Booking.com content where provisioned
Flights workflow
Search, price, add to a reservation workbench, commit, ticket, then exchange, refund or void. Seats, ancillaries and EMDs are covered
Stays workflow
Property search, availability, rules, book, retrieve, modify and cancel
Credentials
OAuth 2.0 password grant, 24-hour Bearer token, access group or PCC header on every call. Primary and managed identities in the Credential Access Manager
Rate limits
50 token requests a second per IP address. No limit for the Flights, Stays or Pay calls was found in the docs
Session times
Search results cached 12 minutes for GDS and 34 minutes for NDC content. A workbench lasts 30 minutes
Errors
Result/Error and Result/Warning with StatusCode, Message, SourceID, SourceCode and Category, and published code ranges by area. Stays has an older two-field form for some customers
Access
Trial credentials by form with no payment. Production by sales contract, then certification with at least 15 days' notice
Developer kits
Postman collections for NDC and GDS flights (v26.11.1), Stays (August 2026) and Pay. No SDK or MCP server found
Support
Cases and Developer Advisories through MyTravelport, which needs a customer login
Data retention
The GDS privacy notice says booking data is destroyed no more than 36 months after the last travel transaction in a reservation

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Public OpenAPI 3.0 files for Flights (101 operations), Stays (22) and Pay (2), with an llms.txt and a Markdown copy of every docs page
  • One API family covers search, price, book, ticket, exchange, refund and void for flights, plus hotel search, booking and cancellation
  • Trial credentials need no payment, and a separate pre-production host mirrors the production paths
  • Dated Flights release notes, with four releases between 16 July and 12 August 2026
  • Credential Access Manager rotates and disables identities, and managed identities give third parties their own credentials

Weaknesses

  • The API and SDK Terms of Use forbid any automated process or tool, such as a bot, without written authorisation from Travelport
  • No public price. Charges sit in a Developer Contract reached through sales, and production needs certification with 15 days' notice
  • No status page, SLA or API rate limit was found. The only published limit is 50 token requests a second per IP
  • Tokens come from the OAuth password grant with a username, password, client id and client secret, and no scopes were found
  • No idempotency key, no SDK and no MCP server. Some failures arrive as HTTP 200 with an error object in the body

Before you call it notes for agents

  1. Request one token and cache it for 24 hours. Travelport declines certification for refreshing more often than every 23 hours without a stated reason
  2. Send Accept-Encoding: gzip, deflate and XAUTH_TRAVELPORT_ACCESSGROUP (or TVP-PCC-CORE) on every call. Production traffic without compression is refused
  3. Send offersPerPage on a journey-based search, or later calls can't reference its results. Cached searches last 12 minutes for GDS content and 34 for NDC
  4. Commit a workbench within 30 minutes or it expires, and read Result/Error in the body even on HTTP 200
  5. Get written authorisation for agent access before production. The terms bar automated tools and speculative or duplicate bookings

Who's behind it provenance 57/100

  • Legal entity namedTravelport, LP20/20
  • Domain agetravelport.com, registered 2001-09-30 (25 years)15/15
  • Endpoint on the vendor's domainapi.travelport.net is not on travelport.com0/15
  • Terms of serviceread, states 3 of the 7 things a reader expects, and has 2 clauses that cost points2.6/10
  • Privacy policyread, states 7 of the 8 things a reader expects9.3/10
  • Status pagenot found0/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service gives no date, states 3 of 7, 3 to know

TL;DR Gives no date. States 3 of the 7 things a reader expects, and we didn't find the governing law, a liability limit or a service level. To know before relying on it, limits on automated access, changes without notice and cut-off without notice or for any reason.

Restricts automated accesscosts points
use any automated process or tool to access and/or use the Service (such as a BOT or a spider) without written authorization from Travelport;

A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.

Says the terms or the service can change without noticecosts points
7.2 We may automatically transmit updates or upgrades to the software to your computer to update, enhance, and further develop the Service without notice to you.

A customer may not hear about a change before it applies.

Says access can be ended without notice or for any reason
Our cancellation or suspension may be without cause.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts

Not found in the text.

Says where a dispute would be heard and under whose law.

States a limit on its liability

Not found in the text.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
In addition, we may, with or without notice, suspend or cancel your Service if you fail to pay the invoices for Charges in full and on time.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Gives 30 days of notice before a change
Unless otherwise provided in your Developer Contract, you may cancel a Service at any time, with or without cause, subject to giving Travelport not less than 30 days prior written notice and to payment of any Charges specified in your Developer Contract.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
1.2 In using the Service, you shall not and will not enable or encourage others to:

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

Developers may not use the service to run queries and then complete the bookings through a third party's system.
use the Service to perform queries, but then complete bookings via a third party's system;

Noted by a second reader on 2026-10-08.

Travelport may place advertising in results, interfaces and content served through the services, and developers must not omit or obscure it.
We reserve the right to include advertising in the results provided to you via the Services, in any user interface we provide for the Services, or in Content served through the Services.

Noted by a second reader on 2026-10-08.

Developers must give Travelport reasonable access, without charge, to applications that use the service so it can monitor compliance.
8.2 You will permit us reasonable access, without charge, to the applications that utilize the Service for purposes of monitoring your compliance with these Terms of Use.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 5,392 words

Privacy policy dated 2025-01-03, states 7 of 8

TL;DR Dated 2025-01-03. States 7 of the 8 things a reader expects, and we didn't find how long data is kept. The rules found no clause to flag.

Gives the date it was last updated Last updated 2025-01-03
Effective Date: This notice was last updated on 3rd January 2025.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
At Travelport, we want to give you an understanding about how we collect your information and the use we make of it in the course of our business.

The basic statement a privacy policy exists to make.

Says how long data is kept

Not found in the text.

Says when data sent to the service is deleted.

Says who else receives the data
We also disclose GDS Personal Data to vendors that perform functions on our behalf, including suppliers of software development services, business processing service providers, contact center service providers, and computer maintenance providers.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell GDS Personal Data for the purpose of allowing third parties to conduct direct marketing for their own products or services.

A plain statement either way.

Says what rights people have over their data
Individuals have the right to access their personal information.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@travelport.com
If you would like to limit the use and disclosure of your personal information, you can email privacy@travelport.com, at any time.

An address or officer to send a request to.

Says where data is transferred or stored Relies on the Data Privacy Framework
To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

The countries data goes to and the safeguard used.

The document · read 2026-10-08 · 2,610 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The API and SDK Terms of Use are incorporated into each Developer Contract, which names the contracting Travelport company and sets the charges. The contract itself is not public. Trial and pre-production access falls under the Terms of Service for Travelport test system access on the developer portal, governed by the law of Georgia, USA.

The privacy link is the Travelport Privacy Notice for the GDS, last updated 3 January 2025, which covers traveller data processed in the Apollo, Galileo and Worldspan systems. It names Travelport, LP for the Data Privacy Framework, with offices in Langley, Berkshire and Atlanta, Georgia.

The APIs answer on api.travelport.net and auth.travelport.net, a second domain named in Travelport's own docs. RDAP gives travelport.net a registration date of 2000-01-12 with Amazon Registrar, and travelport.com 2001-09-30 with CSC Corporate Domains.

No status page is linked from the developer portal or the support page. status.travelport.com did not answer our request.

www.travelport.com/.well-known/security.txt and the developer portal's both return 404. A Responsible Disclosure Policy dated June 2025 takes reports at responsibledisclosure@travelport.com and says there is no bug bounty.

The portal's /changelog page is empty. Dated release notes are kept per API, and the Flights page was last modified on 16 September 2026.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 21:12 UTC

Right nowUpHTTP 404 · 132 ms · under a minute ago
Uptime 24h100.0%21 probes
Uptime 30 days100.0%21 probes
p50 24h132 msget
p95 24h194 msopen endpoint

Probed every five minutes at https://api.travelport.net. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/travelport.json

Notable

  • The API and SDK Terms of Use say a developer shall not use any automated process or tool, such as a bot or a spider, to access or use the service without written authorisation from Travelport source
  • The same terms forbid speculative, duplicative or fictitious segments and using the service for queries while completing bookings through a third party's system source
  • The developer portal home says "Instant trial access" with no payment required, and the request form's confirmation text says credentials arrive by email within one business day source
  • Moving to production means a support case for certification with sample requests and responses, at least 15 days' notice, and a contract for each API source
  • A supplier that can't be reached returns StatusCode 200 with the message COMMUNICATION ERROR and SourceCode 2599 in Result/Error source
  • The Stays FAQ says tokens may not be standard JWTs and should be handled as opaque strings, and that Postman examples and the OpenAPI files disagree on some field names source
  • Travelport's GitHub organisation holds only tutorials and samples for the older uAPI, last pushed in July 2022. No TripServices SDK was found source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 3.8
Graded as a hosted API. No public status page found. None is linked from the developer portal or the support page, and status.travelport.com did not answer (0). No readable incident history, so 5 by the rubric (5). The only published limit is 50 token requests a second per IP address. No limit for the Flights, Stays or Pay calls was found (4 of 15). No 429, Retry-After or backoff guidance and no idempotency key for booking or ticketing was found in the docs or the three OpenAPI files, whose responses list 400, 401, 402, 403, 404, 500 and 503 only (0). No SLA published, and the test terms disclaim availability (0). Version 11 is in production and the docs say TripServices is ready today (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.7
Public OpenAPI 3.0 files download without login for Flights (version 11.36.0, 101 operations), Stays (22) and Pay (2) (25). llms.txt lists the docs, and every page has a Markdown copy at the same path with .md (10). Long guides explain search, pricing, booking, ticketing and exchanges and when each call applies, but 35 of the 101 Flights operations have no description in the spec (13 of 20). Typed schemas with required fields, patterns and length limits, 130 enums in Flights, and polymorphic @type objects. Travelport warns the files may hold unmapped roadmap objects, and the Stays FAQ says Postman and the spec disagree on some names (11 of 15). 2,237 examples in the Flights spec and published error lists with code ranges, though Pay has no error list (12 of 15). The version sits in the path with Accept-Version and Content-Version headers, and release notes are dated per API. The portal's changelog page is empty (13 of 15).
Agent ergonomics 13%16.2 8.3
offersPerPage, maxNumberOfUpsellsToReturn, detail-view flags and reference payloads (an identifier in place of the full fare) size a request, but responses are large nested documents with no field selection found (15 of 25). Stays paginates with a nextIdentifier, Flights caps results per page, and search filters cover carriers, cabins and content source (15 of 20). Errors carry StatusCode, Message, SourceID, SourceCode and Category with documented ranges. Some failures arrive as HTTP 200 with COMMUNICATION ERROR in the body, Stays has two error formats, and a wrong version returns only faultstring (13 of 20). No idempotency key or retry guidance was found. The workbench is a two-step build then commit, which keeps a booking uncommitted until the last call (5 of 20). Each call needs a token, an access group or PCC header, compression and often two version headers. There is no SDK, only Postman collections (3 of 15).
Security & auth 14%17.5 8.2
OAuth 2.0 password grant, with a username, password, client id and client secret exchanged for a 24-hour Bearer token. The Credential Access Manager creates, rotates and disables identities. No scopes were found, and the long-lived secret is a password (20 of 30). Access groups limit a credential to one point of sale and its content, managed identities give third parties their own credentials, and pre-production is a separate host. No read-only credential or approval step for ticketing was found (8 of 20). Responses are mostly structured supplier data, with free text in hotel descriptions, fare rules and remarks and no injection guidance (8 of 15). Every response has an E2ETrackingId and a transaction id, and callers can send a TraceId. No operator log or audit export is documented (5 of 15). A Responsible Disclosure Policy dated June 2025 with a 10 business day acknowledgement and no bug bounty. Both security.txt paths return 404, and no SOC 2, ISO 27001 or PCI attestation was found on the pages read (6 of 20).
Payments & pricing 10%12.5 2.5
No x402, MPP or L402 (0). No public price. The terms say charges are specified in each Developer Contract, and the docs send new customers to sales (0). A trial with no payment is advertised on the portal, with credentials sent by email after a form (20). A person fills in the form with a name, work email and company, and production needs a contract and certification (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 4.9
The newest dated Flights release is Air Offer 26.11.33W on 12 August 2026, updated 25 August, and the release notes page was last modified on 16 September 2026. That is within 90 days and outside 30 (20 of 30). Four dated Flights releases since 10 July 2026, on 16 July, 27 July, 5 August and 12 August (20). Public release notes, with support cases, the knowledge base and Developer Advisories behind a MyTravelport login and no public forum. The Stays page lists no 2026 release (8 of 15 for a closed service). No SDK. The Postman developer kits are current, at v26.11.1 for GDS flights and August 2026 for Stays (5 of 15). No package to judge. The OpenAPI files are at 11.36.0 with older versions kept alongside (3 of 10).
Transparency & trusteditorial 47, provenance 57 7%8.8 4.5
Closed service. The API and SDK Terms of Use and the test system terms are public, but the Developer Contract that sets charges, liability and the contracting entity is not (13 of 30). The GDS privacy notice, last updated 3 January 2025, lists the traveller data held, says it is destroyed no more than 36 months after the last travel transaction, and states Data Privacy Framework certification for Travelport, LP. No public DPA was found (20 of 30). The API reference marks seven Flights operations as deprecated with no dates, the terms promise reasonable advance notice of changes, and retirement dates go out in Developer Advisories behind a login (8 of 20). No subprocessor list was found. The terms say data may be stored in the United States or any country where Travelport or its agents have facilities, the FAQ says the platform runs on AWS, and a global operator list names the distributor in each country (6 of 20).
Negative events≤15None recorded0
Total45.9 · E

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 19 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Travelport TripServices APIs, or have the agent fetch /fixes/travelport.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Travelport TripServices APIs

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/travelport, the October 2026 research run, assessed 8 October 2026. Grade E, 45.9 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Travelport TripServices APIs: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Reliability, 19 out of 100, up to 16.2 more on the total

Why it scored 19: Graded as a hosted API. No public status page found. None is linked from the developer portal or the support page, and status.travelport.com did not answer (0). No readable incident history, so 5 by the rubric (5). The only published limit is 50 token requests a second per IP address. No limit for the Flights, Stays or Pay calls was found (4 of 15). No 429, Retry-After or backoff guidance and no idempotency key for booking or ticketing was found in the docs or the three OpenAPI files, whose responses list 400, 401, 402, 403, 404, 500 and 503 only (0). No SLA published, and the test terms disclaim availability (0). Version 11 is in production and the docs say TripServices is ready today (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 2. Payments & pricing, 20 out of 100, up to 10 more on the total

Why it scored 20: No x402, MPP or L402 (0). No public price. The terms say charges are specified in each Developer Contract, and the docs send new customers to sales (0). A trial with no payment is advertised on the portal, with credentials sent by email after a form (20). A person fills in the form with a name, work email and company, and production needs a contract and certification (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 3. Security & auth, 47 out of 100, up to 9.3 more on the total

Why it scored 47: OAuth 2.0 password grant, with a username, password, client id and client secret exchanged for a 24-hour Bearer token. The Credential Access Manager creates, rotates and disables identities. No scopes were found, and the long-lived secret is a password (20 of 30). Access groups limit a credential to one point of sale and its content, managed identities give third parties their own credentials, and pre-production is a separate host. No read-only credential or approval step for ticketing was found (8 of 20). Responses are mostly structured supplier data, with free text in hotel descriptions, fare rules and remarks and no injection guidance (8 of 15). Every response has an `E2ETrackingId` and a transaction id, and callers can send a `TraceId`. No operator log or audit export is documented (5 of 15). A Responsible Disclosure Policy dated June 2025 with a 10 business day acknowledgement and no bug bounty. Both security.txt paths return 404, and no SOC 2, ISO 27001 or PCI attestation was found on the pages read (6 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 4. Agent ergonomics, 51 out of 100, up to 8 more on the total

Why it scored 51: `offersPerPage`, `maxNumberOfUpsellsToReturn`, detail-view flags and reference payloads (an identifier in place of the full fare) size a request, but responses are large nested documents with no field selection found (15 of 25). Stays paginates with a `nextIdentifier`, Flights caps results per page, and search filters cover carriers, cabins and content source (15 of 20). Errors carry StatusCode, Message, SourceID, SourceCode and Category with documented ranges. Some failures arrive as HTTP 200 with COMMUNICATION ERROR in the body, Stays has two error formats, and a wrong version returns only `faultstring` (13 of 20). No idempotency key or retry guidance was found. The workbench is a two-step build then commit, which keeps a booking uncommitted until the last call (5 of 20). Each call needs a token, an access group or PCC header, compression and often two version headers. There is no SDK, only Postman collections (3 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 5. Transparency & trust, 52 out of 100, up to 4.2 more on the total

Made of editorial 47, provenance 57.

Why it scored 52: Closed service. The API and SDK Terms of Use and the test system terms are public, but the Developer Contract that sets charges, liability and the contracting entity is not (13 of 30). The GDS privacy notice, last updated 3 January 2025, lists the traveller data held, says it is destroyed no more than 36 months after the last travel transaction, and states Data Privacy Framework certification for Travelport, LP. No public DPA was found (20 of 30). The API reference marks seven Flights operations as deprecated with no dates, the terms promise reasonable advance notice of changes, and retirement dates go out in Developer Advisories behind a login (8 of 20). No subprocessor list was found. The terms say data may be stored in the United States or any country where Travelport or its agents have facilities, the FAQ says the platform runs on AWS, and a global operator list names the distributor in each country (6 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Endpoint on the vendor's domain: api.travelport.net is not on travelport.com (0 of 15)
- Terms of service: read, states 3 of the 7 things a reader expects, and has 2 clauses that cost points (2.6 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)
- Status page: not found (0 of 10)
- security.txt: not found (0 of 10)

## 6. Maintenance & community, 56 out of 100, up to 3.9 more on the total

Why it scored 56: The newest dated Flights release is Air Offer 26.11.33W on 12 August 2026, updated 25 August, and the release notes page was last modified on 16 September 2026. That is within 90 days and outside 30 (20 of 30). Four dated Flights releases since 10 July 2026, on 16 July, 27 July, 5 August and 12 August (20). Public release notes, with support cases, the knowledge base and Developer Advisories behind a MyTravelport login and no public forum. The Stays page lists no 2026 release (8 of 15 for a closed service). No SDK. The Postman developer kits are current, at v26.11.1 for GDS flights and August 2026 for Stays (5 of 15). No package to judge. The OpenAPI files are at 11.36.0 with older versions kept alongside (3 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Schema & documentation, 84 out of 100, up to 2.6 more on the total

Why it scored 84: Public OpenAPI 3.0 files download without login for Flights (version 11.36.0, 101 operations), Stays (22) and Pay (2) (25). `llms.txt` lists the docs, and every page has a Markdown copy at the same path with `.md` (10). Long guides explain search, pricing, booking, ticketing and exchanges and when each call applies, but 35 of the 101 Flights operations have no description in the spec (13 of 20). Typed schemas with required fields, patterns and length limits, 130 enums in Flights, and polymorphic `@type` objects. Travelport warns the files may hold unmapped roadmap objects, and the Stays FAQ says Postman and the spec disagree on some names (11 of 15). 2,237 examples in the Flights spec and published error lists with code ranges, though Pay has no error list (12 of 15). The version sits in the path with `Accept-Version` and `Content-Version` headers, and release notes are dated per API. The portal's changelog page is empty (13 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: whether Travelport runs a public status page. status.travelport.com did not answer our request and no status link was found on the portal, so the line is scored as absent
- unchecked: the trial's limits (which APIs, how long, what volume). The form sits behind a script-drawn page and the docs describe only air shopping
- unchecked: Developer Advisories, the knowledge base and the Credential Access Manager articles, which need a MyTravelport login
- Whether written authorisation for AI agent access is granted as a matter of course. The terms bar automated tools without it, while the portal markets TripServices for AI travel
- Whether production calls are rate limited and what a throttled response looks like. No limit or 429 was found in the docs or the OpenAPI files
- Security certifications such as PCI DSS, ISO 27001 or SOC 2. None was found on the pages read, which is not evidence that none is held
- Which Travelport company signs the Developer Contract and under which law. The public terms leave both to the contract

## Weaknesses

- The API and SDK Terms of Use forbid any automated process or tool, such as a bot, without written authorisation from Travelport
- No public price. Charges sit in a Developer Contract reached through sales, and production needs certification with 15 days' notice
- No status page, SLA or API rate limit was found. The only published limit is 50 token requests a second per IP
- Tokens come from the OAuth password grant with a username, password, client id and client secret, and no scopes were found
- No idempotency key, no SDK and no MCP server. Some failures arrive as HTTP 200 with an error object in the body

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Request one token and cache it for 24 hours. Travelport declines certification for refreshing more often than every 23 hours without a stated reason
- Send `Accept-Encoding: gzip, deflate` and `XAUTH_TRAVELPORT_ACCESSGROUP` (or `TVP-PCC-CORE`) on every call. Production traffic without compression is refused
- Send `offersPerPage` on a journey-based search, or later calls can't reference its results. Cached searches last 12 minutes for GDS content and 34 for NDC
- Commit a workbench within 30 minutes or it expires, and read `Result/Error` in the body even on HTTP 200
- Get written authorisation for agent access before production. The terms bar automated tools and speculative or duplicate bookings

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: whether Travelport runs a public status page. status.travelport.com did not answer our request and no status link was found on the portal, so the line is scored as absent
  • unchecked: the trial's limits (which APIs, how long, what volume). The form sits behind a script-drawn page and the docs describe only air shopping
  • unchecked: Developer Advisories, the knowledge base and the Credential Access Manager articles, which need a MyTravelport login
  • Whether written authorisation for AI agent access is granted as a matter of course. The terms bar automated tools without it, while the portal markets TripServices for AI travel
  • Whether production calls are rate limited and what a throttled response looks like. No limit or 429 was found in the docs or the OpenAPI files
  • Security certifications such as PCI DSS, ISO 27001 or SOC 2. None was found on the pages read, which is not evidence that none is held
  • Which Travelport company signs the Developer Contract and under which law. The public terms leave both to the contract

Sources 23

  1. developer portal home, trial claim and product list developer.travelport.com · seen 2026-10-08
  2. llms.txt developer.travelport.com · seen 2026-10-08
  3. authentication, hosts and token rate limit developer.travelport.com · seen 2026-10-08
  4. Flights OpenAPI 3.0 file, version 11.36.0 developer.travelport.com · seen 2026-10-08
  5. Stays OpenAPI 3.0 file developer.travelport.com · seen 2026-10-08
  6. Pay OpenAPI 3.0 file developer.travelport.com · seen 2026-10-08
  7. Flights release notes developer.travelport.com · seen 2026-10-08
  8. Flights error messaging developer.travelport.com · seen 2026-10-08
  9. common Flights headers developer.travelport.com · seen 2026-10-08
  10. certification checklist developer.travelport.com · seen 2026-10-08
  11. Flights FAQs and best practices (cache and workbench times) developer.travelport.com · seen 2026-10-08
  12. Stays FAQ (pagination, tokens, errors) developer.travelport.com · seen 2026-10-08
  13. developer kits and downloads developer.travelport.com · seen 2026-10-08
  14. support options developer.travelport.com · seen 2026-10-08
  15. Terms of Service for test system access developer.travelport.com · seen 2026-10-08
  16. API and SDK Terms of Use travelport.com · seen 2026-10-08
  17. Privacy Notice for the GDS travelport.com · seen 2026-10-08
  18. Responsible Disclosure Policy travelport.com · seen 2026-10-08
  19. trial request form (text read from the page's script) my.travelport.com · seen 2026-10-08
  20. security.txt (404) travelport.com · seen 2026-10-08
  21. RDAP for travelport.com rdap.verisign.com · seen 2026-10-08
  22. official MCP registry search, no result registry.modelcontextprotocol.io · seen 2026-10-08
  23. GitHub organisation repositories api.github.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid Paid No public price. The API and SDK Terms of Use say charges are set in each Developer Contract and invoiced monthly, and the docs send new customers to sales. A trial with no payment exists for building against realistic air shopping, requested through a form that asks for a name, work email and company. Production access is per contracted API after certification (checked 2026-10-08).

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/travelport.xml, or this listing's score history at history.json.

Connect

First request

curl -X POST https://auth.pp.travelport.net/oauth/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=password&username=$TP_USERNAME&password=$TP_PASSWORD&client_id=$TP_CLIENT_ID&client_secret=$TP_CLIENT_SECRET"

Through letme picks today, calling later

GET https://letme.dev/travelport

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Duffel Flights and Stays API DuffelB66.7travel.flights travel.stays travel.booking travel.changes travel.searchno
LetsFG LetsFGB64travel.flights travel.stays travel.booking travel.changes travel.searchno
LiteAPI (Nuitee Connect) NuiteeD53.1travel.stays travel.flights travel.booking travel.changes travel.searchno
ETG API (RateHawk) Emerging Travel GroupD53travel.stays travel.booking travel.changes travel.searchno
FlightClaw FlightClawE45.3travel.flights travel.booking travel.changes travel.searchno
Expedia Group Rapid API Expedia GroupE42.8travel.stays travel.booking travel.changes travel.searchno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Travelport TripServices APIs on Anchor Terminal, E, 45.9/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/travelport"><img src="https://www.anchorterminal.com/badges/travelport.svg" alt="Travelport TripServices APIs on Anchor Terminal" height="20"></a>
    [![Travelport TripServices APIs on Anchor Terminal](https://www.anchorterminal.com/badges/travelport.svg)](https://www.anchorterminal.com/tools/travelport)

    It counts on a page on travelport.com or one of its subdomains.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "travelport", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.