Corporate Travel Management

Corporate Travel Management (CTM) is a Brisbane-founded, ASX-listed (CTD) travel management company established in 1994 that procures, books and services corporate, government, meetings and events, resources, sport and leisure travel across Australia and New Zealand, North America, Europe and Asia. CTM sits on the buy side of the travel distribution chain: an IATA-accredited agency that aggregates supplier content from GDS, direct airline APIs and airline NDC connections and resells it to corporate clients through its own proprietary technology stack — the Lightning online booking tool, CTM Portal, CTM Mobile app, CTM Approve pre-trip approval, CTM Fare Forecaster and CTM Data Hub reporting. Its API posture is closed. CTM publishes no developer portal and no public API: developer.travelctm.com, developers.travelctm.com, api.travelctm.com and docs.travelctm.com do not resolve in DNS, and /developers, /api, /docs, /openapi.json, /swagger.json, /api-docs and /.well-known/security.txt all return HTTP 404 across the AU, US and UK sites. The only live non-marketing front door is a customer login — CTM Portal at portal.travelctm.com and www.ctmsmart.com.au. CTM's technology pages assert secure integration with client HR, expense, finance, ERP and single sign-on systems, but no interface contract, schema or endpoint is documented anywhere in public: the integration surface is proprietary and undocumented, reachable only under a managed-travel commercial agreement. The only published exit path is a GDPR/CCPA data-portability request by email to privacy@travelctm.com or DPO@travelctm.com; there is no self-service export.

Corporate Travel Management publishes 1 API on the APIs.io network. Tagged areas include Travel, Australia, Corporate Travel, Travel Management Company, and Aviation.

Corporate Travel Management’s developer surface includes authentication, documentation, developer portal, engineering blog, product news, and 37 more developer resources.

23.8/100 emerging Agent 14/100 human only Full breakdown ↓
scored 2026-07-28 · rubric v0.5
1 APIs 9 Features
TravelAustraliaCorporate TravelTravel Management CompanyAviationNDCDistributionBookingHotelsMeetings and Events

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.5
Composite quality — 23.8/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 6.1 / 20
Commercial Clarity 8.4 / 20
Operational Transparency 0.0 / 13
Governance 0.0 / 12
Discoverability 9.3 / 10
Agent readiness — 14/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/corporate-travel-management: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

CTM Portal Host API

The private back-end API for CTM Portal, CTM's single sign-on customer portal. It is not documented, not announced and not offered to third parties — it was identified from the ...

Features 9

Notable capabilities this provider offers.

Lightning

CTM's proprietary online booking tool, built and managed in-house, which aggregates GDS content, direct low-cost-carrier API connections and live airline NDC offers into a singl...

CTM Portal

Single sign-on customer portal that consolidates CTM's travel tools for pre-trip planning, approvals, in-trip tracking, risk alerts and post-trip reporting. Live at portal.trave...

CTM Approve

End-to-end pre-trip approval workflow used to enforce corporate travel policy before a booking is ticketed.

CTM Data Hub

Cloud-based travel reporting and analytics platform covering air, hotel, car, rail, traveller tracking, carbon emissions and wellbeing. No export, feed or API is documented.

CTM Fare Forecaster

Predictive fare forecasting tool used to time corporate air purchases.

CTM Mobile App

Traveller mobile application for booking and itinerary management on the go.

CTM Scout

Chat-based booking and servicing channel for managing travel bookings.

Travel Risk Management

Real-time traveller risk alerts by SMS and email plus a Travel Risk Hub of destination requirements.

NDC Content Integration

Lightning ingests live NDC content from airlines — Qantas' Premium NDC connection in Australia, American Airlines and United Airlines in the United States — alongside GDS and di...

Scroll for all 9

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Corporate Travel Management Authentication

oauth2/openIdConnect · 1 scheme

SECURITY

Corporate Travel Management Domain Security

TLSv1.2 · HSTS · DMARC

SECURITY

Corporate Travel Management Trust Center

trust center published

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Corporate Travel Management Scopes

14 scopes · authorizationCode/clientCredentials/deviceCode/implicit

14 scopes

SCOPES

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 12

Reference material describing how the API behaves

Scroll for all 12

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 4

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 12

The organization behind the API

Scroll for all 12

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: corporate-travel-management
name: Corporate Travel Management
kind: company
url: https://raw.githubusercontent.com/api-evangelist/corporate-travel-management/refs/heads/main/apis.yml
humanURL: https://www.travelctm.com/
description: 'Corporate Travel Management (CTM) is a Brisbane-founded, ASX-listed (CTD) travel management company established
  in 1994 that procures, books and services corporate, government, meetings and events, resources, sport and leisure travel
  across Australia and New Zealand, North America, Europe and Asia. CTM sits on the buy side of the travel distribution chain:
  an IATA-accredited agency that aggregates supplier content from GDS, direct airline APIs and airline NDC connections and
  resells it to corporate clients through its own proprietary technology stack — the Lightning online booking tool, CTM Portal,
  CTM Mobile app, CTM Approve pre-trip approval, CTM Fare Forecaster and CTM Data Hub reporting. Its API posture is closed.
  CTM publishes no developer portal and no public API: developer.travelctm.com, developers.travelctm.com, api.travelctm.com
  and docs.travelctm.com do not resolve in DNS, and /developers, /api, /docs, /openapi.json, /swagger.json, /api-docs and
  /.well-known/security.txt all return HTTP 404 across the AU, US and UK sites. The only live non-marketing front door is
  a customer login — CTM Portal at portal.travelctm.com and www.ctmsmart.com.au. CTM''s technology pages assert secure integration
  with client HR, expense, finance, ERP and single sign-on systems, but no interface contract, schema or endpoint is documented
  anywhere in public: the integration surface is proprietary and undocumented, reachable only under a managed-travel commercial
  agreement. The only published exit path is a GDPR/CCPA data-portability request by email to privacy@travelctm.com or DPO@travelctm.com;
  there is no self-service export.'
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
tags:
- Travel
- Australia
- Corporate Travel
- Travel Management Company
- Aviation
- NDC
- Distribution
- Booking
- Hotels
- Meetings and Events
created: '2026-07-28'
modified: '2026-07-28'
specificationVersion: '0.19'
apis:
- aid: corporate-travel-management:ctm-portal-host-api
  name: CTM Portal Host API
  description: 'The private back-end API for CTM Portal, CTM''s single sign-on customer portal. It is not documented, not
    announced and not offered to third parties — it was identified from the portal''s own client bootstrap, which sets hostApiUrl
    to https://portal-host.api.ctmsmart.com/api. The host is live (GET / and GET /api return HTTP 200 text/plain "Healthy")
    and is an ASP.NET Core application that emits RFC 7807-style application/problem+json errors, but every specification
    path — /openapi.json, /swagger.json, /swagger/v1/swagger.json, /api-docs, /graphql — returns 404, and no /.well-known/oauth-protected-resource
    metadata is served. Calls are bearer-token protected through CTM''s Auth0 tenant (travelctm-au-production.au.auth0.com),
    whose OIDC discovery document is the only anonymous machine-readable surface CTM operates. Recorded here as an observed,
    undocumented integration surface, not as an available API: there is no developer sign-up, no documentation, no sandbox
    and no terms permitting third-party use.'
  humanURL: https://www.ctmsmart.com.au/
  baseURL: https://portal-host.api.ctmsmart.com/api
  tags:
  - Corporate Travel
  - Travel
  - Booking
  - Undocumented
  properties:
  - type: Authentication
    url: authentication/corporate-travel-management-authentication.yml
  - type: OAuthScopes
    url: scopes/corporate-travel-management-scopes.yml
  - type: Conventions
    url: conventions/corporate-travel-management-conventions.yml
  - type: WellKnown
    url: well-known/corporate-travel-management-well-known.yml
  - type: Login
    url: https://www.ctmsmart.com.au/
common:
- type: DomainSecurity
  url: security/corporate-travel-management-domain-security.yml
- type: WellKnown
  url: well-known/corporate-travel-management-well-known.yml
- type: OpenIDConnect
  url: well-known/corporate-travel-management-openid-configuration.json
- type: Authentication
  url: authentication/corporate-travel-management-authentication.yml
- type: OAuthScopes
  url: scopes/corporate-travel-management-scopes.yml
- type: Conventions
  url: conventions/corporate-travel-management-conventions.yml
- type: Conformance
  url: conformance/corporate-travel-management-conformance.yml
- type: Lifecycle
  url: lifecycle/corporate-travel-management-lifecycle.yml
- type: Packages
  url: packages/corporate-travel-management-packages.yml
- type: Components
  url: components/corporate-travel-management-components.yml
- type: LLMsTxt
  url: llms/corporate-travel-management-llms.txt
- type: Documentation
  url: https://compass.ctmdevelopment.com/
- type: Website
  url: https://www.travelctm.com/
- type: Website
  url: https://au.travelctm.com/
- type: Website
  url: https://us.travelctm.com/
- type: Website
  url: https://uk.travelctm.com/
- type: Website
  url: https://asia.travelctm.com/
- type: Portal
  url: https://portal.travelctm.com/
- type: Login
  url: https://www.ctmsmart.com.au/
- type: Documentation
  url: https://au.travelctm.com/technology/
- type: Documentation
  url: https://au.travelctm.com/technology/lightning/
- type: Documentation
  url: https://au.travelctm.com/technology/travel-portal/
- type: Documentation
  url: https://au.travelctm.com/technology/travel-reporting/
- type: Documentation
  url: https://au.travelctm.com/technology/pre-trip-approval/
- type: Documentation
  url: https://au.travelctm.com/technology/travel-forecasting/
- type: Documentation
  url: https://au.travelctm.com/technology/ctm-mobile-app/
- type: Documentation
  url: https://au.travelctm.com/technology/ctm-scout/
- type: Documentation
  url: https://au.travelctm.com/technology/risk-management/
- type: Documentation
  url: https://au.travelctm.com/ndc/
- type: Documentation
  url: https://us.travelctm.com/ndc/
- type: Blog
  url: https://au.travelctm.com/blog/
- type: BlogRSS
  url: https://au.travelctm.com/blog/feed/
- type: BlogRSS
  url: https://us.travelctm.com/feed/
- type: News
  url: https://au.travelctm.com/news/
- type: TermsOfService
  url: https://au.travelctm.com/terms-and-conditions/
- type: PrivacyPolicy
  url: https://au.travelctm.com/privacy/
- type: CookiePolicy
  url: https://au.travelctm.com/cookie-policy/
- type: Compliance
  url: https://au.travelctm.com/payment-card-industry-data-security-standard/
- type: InvestorRelations
  url: https://investor.travelctm.com.au/
- type: Careers
  url: https://au.travelctm.com/careers/
- type: Contact
  url: https://au.travelctm.com/contact/
- type: LinkedIn
  url: https://www.linkedin.com/company/corporate-travel-management-ctm-group
- type: Features
  data:
  - name: Lightning
    description: CTM's proprietary online booking tool, built and managed in-house, which aggregates GDS content, direct low-cost-carrier
      API connections and live airline NDC offers into a single policy-controlled corporate search and booking flow.
  - name: CTM Portal
    description: Single sign-on customer portal that consolidates CTM's travel tools for pre-trip planning, approvals, in-trip
      tracking, risk alerts and post-trip reporting. Live at portal.travelctm.com and www.ctmsmart.com.au for existing customers
      only.
  - name: CTM Approve
    description: End-to-end pre-trip approval workflow used to enforce corporate travel policy before a booking is ticketed.
  - name: CTM Data Hub
    description: Cloud-based travel reporting and analytics platform covering air, hotel, car, rail, traveller tracking, carbon
      emissions and wellbeing. No export, feed or API is documented.
  - name: CTM Fare Forecaster
    description: Predictive fare forecasting tool used to time corporate air purchases.
  - name: CTM Mobile App
    description: Traveller mobile application for booking and itinerary management on the go.
  - name: CTM Scout
    description: Chat-based booking and servicing channel for managing travel bookings.
  - name: Travel Risk Management
    description: Real-time traveller risk alerts by SMS and email plus a Travel Risk Hub of destination requirements.
  - name: NDC Content Integration
    description: Lightning ingests live NDC content from airlines — Qantas' Premium NDC connection in Australia, American
      Airlines and United Airlines in the United States — alongside GDS and direct API content. CTM consumes NDC; it does
      not publish an NDC endpoint of its own.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
  url: https://kinlane.com