Transat · Authentication Profile
Transat Authentication
Authentication
Air Transat's direct-connect distribution API does not use OAuth, OpenID Connect, API keys or mutual TLS. It uses a two-stage vendor credential exchange inherited from the Radixx (Sabre) passenger service system: a system-level logon that returns a session GUID, followed by a travel-agent logon that binds that session to a Transat-assigned IATA agency. There is no self-serve key issuance, no developer portal and no sandbox; every credential is provisioned by Transat under a commercial agreement.
Transat secures its APIs with vendor-credential-exchange across 2 declared security schemes, as derived from its OpenAPI definitions.
TravelCanadaAviationAirlineDistributionNDCBookingTour OperatorCorporate TravelGDS
Methods: vendor-credential-exchange
Schemes: 2
OAuth flows:
API key in:
Security Schemes
RetrieveSecurityToken vendor-credential-exchange
LoginTravelAgent vendor-credential-exchange