Environments
Production: https://api.transfertourism.com/v1 Sandbox: https://sandbox-api.transfertourism.com/v1
Sandbox credentials only work in sandbox. Sandbox bookings are isolated from operational dispatch, notifications and billing.
Authentication
Every request requires an API key and HMAC-SHA256 signature. Timestamp tolerance is five minutes and each nonce can be used only once for ten minutes.
X-API-KEY: partner API key X-TIMESTAMP: Unix timestamp X-NONCE: unique random value X-SIGNATURE: HMAC-SHA256
canonical = {timestamp}.{nonce}.{METHOD}.{path}.{sha256(raw-body)}
Places and quote
GET /places?query=...&country_code=TR&limit=10NormalizedAIRPORTandHOTELresults. Place types areAIRPORT,HOTEL,ADDRESSandPOI.POST /quotesfromandtorequire type, name, lat, lng, country_code; include pickup_datetime, pax and luggage.
{"from":{"type":"AIRPORT","name":"Antalya Airport","lat":36.8987,"lng":30.8005,"country_code":"TR"},"to":{"type":"HOTEL","name":"Example Hotel","lat":36.85,"lng":30.78,"country_code":"TR"},"pickup_datetime":"2026-08-01T12:00:00+03:00","pax":{"adults":2,"children":0,"infants":0},"luggage":2,"flight":{"code":"TK2439","date":"2026-08-01"}}
Bookings and operations
POST /bookingsquote_id, partner_reference and passenger.Idempotency-Keyis required; the quote locks amount and currency.GET /bookingsList a firm’s own bookings.GET /bookings/{booking_id}Operation status, timestamps, cancellation policy and dispute status.POST /bookings/{booking_id}/updateFlight number, pickup time or note before cutoff.POST /bookings/{booking_id}/cancelCancellation before cutoff.GET /bookings/updates?updated_after=...Changed records only; maximum once per minute.
Booking responses use payment_status=COLLECTED_BY_PARTNER. The partner is merchant of record; passenger payment is not collected by TransferTourism.
Affiliate tracking
POST /bookings accepts referral_id, promo_code and source_tracking with UTM values. Referral attribution and promo code may be sent together.
GET /affiliate/statisticsClicks, conversions and earnings.GET /affiliate/commissionsCommission ledger and statuses.GET /affiliate/payoutsPayout request history.
Errors, FX and billing
Errors are returned as {"error":{"code":"...","message":"...","details":{}}}. Quote currency is locked with its FX snapshot; non-TRY quotes older than 72 hours are blocked. Completed production transfers are included in the partner’s monthly open-account invoice; accepted disputes create an auditable invoice credit.
OpenAPI
Machine-readable contract: OpenAPI JSON. Executable examples: Postman collection.