Skip to main content

Tools & SDK

Postman collection​

A ready-to-import Postman v2.1 collection with one request per message, foldered by domain group, plus a Negative tests folder. Each message request is prefilled with a valid example body and ships a saved example response; its description says whether the airline implements it.

⬇ Download the collection · Sandbox environment

Import & run:

  1. In Postman: Import → drop in the collection and an environment file.
  2. Select the NDC 24.4 — sandbox environment.
  3. Fill clientId and clientSecret and your agency id in sellerId. The environment already points at the sandbox (https://ndc.retailaer.com) and its token URL.
  4. Send any request. A collection pre-request script fetches/refreshes the OAuth token into {{accessToken}}; a test script asserts a 2xx, well-formed-XML response. The example bodies are minimal XSD samples — put real ids in them (see Onboarding for a full journey).

Negative tests. One request per documented error a partner must handle — bad credentials, a missing scope, another seller's order, a stale offer, a card number sent in clear, a declined card, 3-D Secure required, a held order paid too late, pricing rules unavailable, cancelling after check-in, a stale reshop offer. Each asserts the HTTP status and the X-NDC-Error code, and names in its description the sandbox state it needs (for example foreignOrderId, expiredHeldOrderId) — fill those environment variables first.

The collection's variables ({{baseUrl}}, {{accessToken}}/{{apiKey}}, participant ids) are resolved from the selected environment, so you configure them once.

Run it against the local gateway

Start the gateway (pnpm ndc:api) and the domain services (pnpm dev:services), then set the environment's baseUrl and tokenUrl to http://localhost:3018 and http://localhost:3018/oauth/token. Requests route to the real offer/order services as the ndc channel; what is wired is on the Capabilities page, and anything else returns 501.

The @oms/ndc-24-4 reference SDK​

The same TypeScript library that generates this documentation is a fully-typed client SDK: types + strict/lenient Zod validators + an XML codec for every message.

import { IATA_AirShoppingRQ } from '@oms/ndc-24-4';

// Build a request object (fully typed), then serialize to XML:
const xml = IATA_AirShoppingRQ.toXML(payload, { pretty: true });

// Parse a received XML response back into a typed object:
const obj = IATA_AirShoppingRQ.parseXML(xml);

// Validate against the strict schema (throws on violation):
IATA_AirShoppingRQ.schema.parse(obj);

// `lenient` is a relaxed variant for tolerant inbound parsing:
IATA_AirShoppingRQ.lenient.parse(obj);

Every message module exports the same surface: ROOT_ELEMENT, toXML, parseXML, schema, and lenient. Import the whole barrel, or a single message:

import * as ndc from '@oms/ndc-24-4'; // all messages + META
import { IATA_OrderCreateRQ } from '@oms/ndc-24-4'; // one message

Because the docs, OpenAPI, and Postman are all generated from this package, the examples you see here are exactly what the codec produces — they can't drift from the code.

OpenAPI 3.1 contract​

The transport is described as an OpenAPI 3.1 contract, rendered in-site with Redoc. Use it to generate clients or to explore every operation, its application/xml request body, and its example response.