Flights
POST/v1/flights/orders
Book an offer — charged to your account
The airline reprices before booking; that is the rule, not the exception. Set maxTotalCents and we refuse above it with 409 price_changed — nothing booked, nothing charged. Without it we book at the new price and charge what was actually due.
- Auth
- API key
- Scope
- flights:book
- Rate limit
- BOOKING
- Search quota
- Free
- Idempotency
- Idempotency-Key
Request headers
Request body
CreateFlightOrderDto — required, sent as application/json.
Responses
201 · FlightOrderDto
Errors
Every one of these carries the same envelope. What each error.type means, and whether a retry can succeed, is on the error index — once, for all operations.
Response headers
Set on every response of this operation, successful or not.
Example
curl -sS -X POST "$VACABEE_API_URL/v1/flights/orders" \
-H "Authorization: Bearer $VACABEE_API_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{
"offerId": "off_8f2c…",
"externalReference": "order-2026-0915-abc",
"passengers": [
{
"firstName": "Ada",
"lastName": "Lovelace"
}
],
"contact": {
"email": "ada@example.com"
}
}'Set VACABEE_API_URL to https://api.vacabee.com with a live key, or to https://sandbox-api.vacabee.com with a vcb_test_ key. Binding a host to one kind of key is planned and is not enforced by the host yet, so nothing stops a key from being answered at the wrong base URL — assert the prefix against your configured URL yourself. What the sandbox answers
TypeScript SDK
await vacabee.flights.book(…);The typed method sends the right headers, derives the idempotency key where one is required, and returns the response type generated from this document. Installing and using the SDK

