Traveloka · OpenAPI Overlay 1.0.0
API Evangelist enhancements for the Traveloka Partners Network (LOKA) v2 API
15 actions
15 updates
documentation
Generated by API Evangelist
Written by API Evangelist tooling for Traveloka's API. It is a proposal applied on top of the contract, not a document Traveloka publishes.
What the actions change
operationIdsummaryx-cache-ttlx-optionalcontacttermsOfServicex-documentationx-getting-started
Targets 15
$.info
$.servers
$.paths['/oauth/accesstoken'].post
$.paths['/properties/content/hotel'].get
$.paths['/properties/content/room'].get
$.paths['/properties/:getRates'].get
$.paths['/properties/checkRate'].post
$.paths['/bookings/booking/create'].post
$.paths['/bookings'].get
$.paths['/bookings/detail'].get
$.paths['/bookings/cancellation/submit'].post
$.paths['/discovery/getGeo'].get
$.paths['/discovery/getRates'].post
$.components.securitySchemes
$
OpenAPI Overlay
overlay: 1.0.0
info:
title: API Evangelist enhancements for the Traveloka Partners Network (LOKA) v2 API
version: 1.0.0
x-provenance:
generated: '2026-08-05'
method: generated
source: openapi/traveloka-loka-partner-api-openapi.yml
extends: openapi/traveloka-loka-partner-api-openapi.yml
summary: >-
Non-destructive enhancements to the LOKA v2 OpenAPI as published. The original spec is never mutated.
Every value below is sourced from a Traveloka-published page (the docs, the FAQ, or the spec itself);
nothing is invented. The largest gaps this overlay closes: 10 of 11 operations ship with NO
operationId, the token endpoint is not modelled as an oauth2 securityScheme, and the two servers[]
entries are labelled Production and Staging but carry the SAME production URL.
actions:
- target: $.info
description: Add contact and terms the provider publishes, plus the documentation link.
update:
contact:
name: Traveloka Partners Network
email: partnersnetwork@traveloka.com
url: https://developer.travelokapartnersnetwork.com/
termsOfService: https://www.traveloka.com/en-id/termsandconditions
x-documentation: https://developer.travelokapartnersnetwork.com/api-docs
x-getting-started: https://developer.travelokapartnersnetwork.com/get-started
x-error-reference: https://developer.travelokapartnersnetwork.com/faq
- target: $.servers
description: >-
Replace the duplicated production URL with the real environment pair. The staging host is the one
named in the OAuth service description ("Sandbox: auth-api.afc.staging-traveloka.com") and in the
per-service server block of the published documentation bundle.
update:
- url: https://api.travelokapartnersnetwork.com/v2
description: Production
- url: https://api.staging-travelokapartnersnetwork.com/v2
description: Staging / sandbox
- target: $.paths['/oauth/accesstoken'].post
description: >-
Give the token operation a stable operationId. The published value is the string "Generate Token",
which is not a valid identifier for code generators.
update:
operationId: generateAccessToken
summary: Generate an access token
x-token-lifetime-minutes: 60
x-token-reuse: Reuse until expiry; do not mint a token per request.
- target: $.paths['/properties/content/hotel'].get
description: Add the missing operationId and summary.
update:
operationId: getHotelContent
summary: Get hotel content
x-cache-ttl: 7 days (provider guidance)
- target: $.paths['/properties/content/room'].get
description: Add the missing operationId and summary.
update:
operationId: getRoomContent
summary: Get room content
x-cache-ttl: 7 days (provider guidance)
- target: $.paths['/properties/:getRates'].get
description: Add the missing operationId and the published request-shape limits.
update:
operationId: getRates
summary: Search rates and availability
x-cache-ttl: 15-30 minutes (high demand) / 6-12 hours (low demand)
x-request-limits:
max_property_ids: 50
max_rooms: 8
max_adults: 30
max_children_age: 17
max_length_of_stay_days: 15
max_booking_window_days: 365
- target: $.paths['/properties/checkRate'].post
description: Add the missing operationId and record its role in the booking flow.
update:
operationId: checkRate
summary: Re-validate a rate before booking
x-flow-role: >-
Call immediately before booking creation to avoid AFI735 MISMATCHED_RATE /
AFI101 MISMATCH_EXPECTED_RATE.
- target: $.paths['/bookings/booking/create'].post
description: Add the missing operationId and record the idempotency contract.
update:
operationId: createBooking
summary: Create a booking
x-idempotency:
field: partnerBookingId
mechanism: client-supplied business key
duplicate_errors: [AFI734 BOOKING_ALREADY_EXISTS, AFI102 DOUBLE_CONFIRMATION_ID, AFI104 ALREADY_ISSUED_BOOKING]
recovery: >-
On timeout, do NOT re-issue. Poll getBookingDetail with the bookingId or partnerBookingId.
x-amount-field: partnerNettAmount
- target: $.paths['/bookings'].get
description: Add the missing operationId.
update:
operationId: listBookings
summary: List bookings
- target: $.paths['/bookings/detail'].get
description: Add the missing operationId.
update:
operationId: getBookingDetail
summary: Get booking detail
- target: $.paths['/bookings/cancellation/submit'].post
description: Add the missing operationId and the documented cancellation states.
update:
operationId: submitBookingCancellation
summary: Submit a booking cancellation
x-cancellation-states: [SUBMITTED, COMPLETED, FAILED]
- target: $.paths['/discovery/getGeo'].get
description: Add the missing operationId.
update:
operationId: getGeo
summary: Get geographic nodes
x-optional: >-
Discovery is optional and intended for partners who do not have their own master data.
- target: $.paths['/discovery/getRates'].post
description: Add the missing operationId.
update:
operationId: discoveryGetRates
summary: Search rates by geo
x-optional: >-
Discovery is optional and intended for partners who do not have their own master data.
- target: $.components.securitySchemes
description: >-
Model the documented OAuth 2.0 client-credentials flow as a first-class securityScheme. The
published spec only declares the resulting bearer credential as an apiKey-in-header scheme, and its
root security requirement references an undefined scheme name ("OAuthStaging").
update:
oauth2ClientCredentials:
type: oauth2
description: >-
Documented client-credentials exchange. POST client_id and client_secret as
application/x-www-form-urlencoded to the token endpoint; the returned access_token is valid for
60 minutes and is sent in the Authorization header.
flows:
clientCredentials:
tokenUrl: https://auth-api.afc.traveloka.com/oauth/accesstoken
refreshUrl: https://auth-api.afc.traveloka.com/oauth/accesstoken
scopes: {}
x-staging-token-url: https://auth-api.afc.staging-traveloka.com/oauth/accesstoken
- target: $
description: Attach the rate-limit, error-registry and support facts published outside the spec.
update:
x-rate-limit:
limit: 100
interval: minute
scope: api_key
exceeded_status: 429
suspension: Traffic blocked for 15 seconds when the suspension threshold is tripped.
headers_published: false
x-retry-policy:
max_attempts: 3
backoff: exponential
initial_delay_seconds: 120
x-error-registry:
url: https://developer.travelokapartnersnetwork.com/faq
artifact: errors/traveloka-error-codes.yml
code_count: 142
envelope: '{ data, error: { code, message, requestId } }'
rfc9457: false
x-access-model:
onboarding: approval
self_serve: false
signup: https://traveloka.sg.larksuite.com/share/base/form/shrlg7CyVohw5GHPRXwt8LdPCCW