Tools & SDK
Postman collection
A ready-to-import Postman v2.1 collection with one request per message, foldered by domain group, plus a Negative tests folder. Each message request is prefilled with a valid example body and ships a saved example response; its description says whether the airline implements it.
⬇ Download the collection · Sandbox environment
Import & run:
- In Postman: Import → drop in the collection and an environment file.
- Select the NDC 24.4 — sandbox environment.
- Fill
clientIdandclientSecretand your agency id insellerId. The environment already points at the sandbox (https://ndc.retailaer.com) and its token URL. - Send any request. A collection pre-request script fetches/refreshes the OAuth token
into
{{accessToken}}; a test script asserts a 2xx, well-formed-XML response. The example bodies are minimal XSD samples — put real ids in them (see Onboarding for a full journey).
Negative tests. One request per documented error a partner must handle — bad
credentials, a missing scope, another seller's order, a stale offer, a card number sent
in clear, a declined card, 3-D Secure required, a held order paid too late, pricing rules
unavailable, cancelling after check-in, a stale reshop offer. Each asserts the HTTP
status and the X-NDC-Error code, and names in its description the sandbox state it
needs (for example foreignOrderId, expiredHeldOrderId) — fill those environment
variables first.
The collection's variables ({{baseUrl}}, {{accessToken}}/{{apiKey}}, participant
ids) are resolved from the selected environment, so you configure them once.
Start the gateway (pnpm ndc:api) and the domain services (pnpm dev:services),
then set the environment's baseUrl and tokenUrl to http://localhost:3018 and
http://localhost:3018/oauth/token. Requests route to the real offer/order services
as the ndc channel; what is wired is on the Capabilities page, and
anything else returns 501.
The @oms/ndc-24-4 reference SDK
The same TypeScript library that generates this documentation is a fully-typed client SDK: types + strict/lenient Zod validators + an XML codec for every message.
import { IATA_AirShoppingRQ } from '@oms/ndc-24-4';
// Build a request object (fully typed), then serialize to XML:
const xml = IATA_AirShoppingRQ.toXML(payload, { pretty: true });
// Parse a received XML response back into a typed object:
const obj = IATA_AirShoppingRQ.parseXML(xml);
// Validate against the strict schema (throws on violation):
IATA_AirShoppingRQ.schema.parse(obj);
// `lenient` is a relaxed variant for tolerant inbound parsing:
IATA_AirShoppingRQ.lenient.parse(obj);
Every message module exports the same surface: ROOT_ELEMENT, toXML, parseXML,
schema, and lenient. Import the whole barrel, or a single message:
import * as ndc from '@oms/ndc-24-4'; // all messages + META
import { IATA_OrderCreateRQ } from '@oms/ndc-24-4'; // one message
Because the docs, OpenAPI, and Postman are all generated from this package, the examples you see here are exactly what the codec produces — they can't drift from the code.
OpenAPI 3.1 contract
The transport is described as an OpenAPI 3.1 contract, rendered in-site with
Redoc. Use it to generate clients or to explore every operation, its application/xml
request body, and its example response.