aid: corporate-travel-management name: Corporate Travel Management kind: company url: https://raw.githubusercontent.com/api-evangelist/corporate-travel-management/refs/heads/main/apis.yml humanURL: https://www.travelctm.com/ description: >- Corporate Travel Management (CTM) is a Brisbane-founded, ASX-listed (CTD) travel management company established in 1994 that procures, books and services corporate, government, meetings and events, resources, sport and leisure travel across Australia and New Zealand, North America, Europe and Asia. CTM sits on the buy side of the travel distribution chain: an IATA-accredited agency that aggregates supplier content from GDS, direct airline APIs and airline NDC connections and resells it to corporate clients through its own proprietary technology stack — the Lightning online booking tool, CTM Portal, CTM Mobile app, CTM Approve pre-trip approval, CTM Fare Forecaster and CTM Data Hub reporting. Its API posture is closed. CTM publishes no developer portal and no public API: developer.travelctm.com, developers.travelctm.com, api.travelctm.com and docs.travelctm.com do not resolve in DNS, and /developers, /api, /docs, /openapi.json, /swagger.json, /api-docs and /.well-known/security.txt all return HTTP 404 across the AU, US and UK sites. The only live non-marketing front door is a customer login — CTM Portal at portal.travelctm.com and www.ctmsmart.com.au. CTM's technology pages assert secure integration with client HR, expense, finance, ERP and single sign-on systems, but no interface contract, schema or endpoint is documented anywhere in public: the integration surface is proprietary and undocumented, reachable only under a managed-travel commercial agreement. The only published exit path is a GDPR/CCPA data-portability request by email to privacy@travelctm.com or DPO@travelctm.com; there is no self-service export. image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg tags: - Travel - Australia - Corporate Travel - Travel Management Company - Aviation - NDC - Distribution - Booking - Hotels - Meetings and Events created: '2026-07-28' modified: '2026-07-28' specificationVersion: '0.19' apis: - aid: corporate-travel-management:ctm-portal-host-api name: CTM Portal Host API description: >- The private back-end API for CTM Portal, CTM's single sign-on customer portal. It is not documented, not announced and not offered to third parties — it was identified from the portal's own client bootstrap, which sets hostApiUrl to https://portal-host.api.ctmsmart.com/api. The host is live (GET / and GET /api return HTTP 200 text/plain "Healthy") and is an ASP.NET Core application that emits RFC 7807-style application/problem+json errors, but every specification path — /openapi.json, /swagger.json, /swagger/v1/swagger.json, /api-docs, /graphql — returns 404, and no /.well-known/oauth-protected-resource metadata is served. Calls are bearer-token protected through CTM's Auth0 tenant (travelctm-au-production.au.auth0.com), whose OIDC discovery document is the only anonymous machine-readable surface CTM operates. Recorded here as an observed, undocumented integration surface, not as an available API: there is no developer sign-up, no documentation, no sandbox and no terms permitting third-party use. humanURL: https://www.ctmsmart.com.au/ baseURL: https://portal-host.api.ctmsmart.com/api tags: - Corporate Travel - Travel - Booking - Undocumented properties: - type: Authentication url: authentication/corporate-travel-management-authentication.yml - type: OAuthScopes url: scopes/corporate-travel-management-scopes.yml - type: Conventions url: conventions/corporate-travel-management-conventions.yml - type: WellKnown url: well-known/corporate-travel-management-well-known.yml - type: Login url: https://www.ctmsmart.com.au/ common: - type: DomainSecurity url: security/corporate-travel-management-domain-security.yml - type: WellKnown url: well-known/corporate-travel-management-well-known.yml - type: OpenIDConnect url: well-known/corporate-travel-management-openid-configuration.json - type: Authentication url: authentication/corporate-travel-management-authentication.yml - type: OAuthScopes url: scopes/corporate-travel-management-scopes.yml - type: Conventions url: conventions/corporate-travel-management-conventions.yml - type: Conformance url: conformance/corporate-travel-management-conformance.yml - type: Lifecycle url: lifecycle/corporate-travel-management-lifecycle.yml - type: Packages url: packages/corporate-travel-management-packages.yml - type: Components url: components/corporate-travel-management-components.yml - type: LLMsTxt url: llms/corporate-travel-management-llms.txt - type: Documentation url: https://compass.ctmdevelopment.com/ - type: Website url: https://www.travelctm.com/ - type: Website url: https://au.travelctm.com/ - type: Website url: https://us.travelctm.com/ - type: Website url: https://uk.travelctm.com/ - type: Website url: https://asia.travelctm.com/ - type: Portal url: https://portal.travelctm.com/ - type: Login url: https://www.ctmsmart.com.au/ - type: Documentation url: https://au.travelctm.com/technology/ - type: Documentation url: https://au.travelctm.com/technology/lightning/ - type: Documentation url: https://au.travelctm.com/technology/travel-portal/ - type: Documentation url: https://au.travelctm.com/technology/travel-reporting/ - type: Documentation url: https://au.travelctm.com/technology/pre-trip-approval/ - type: Documentation url: https://au.travelctm.com/technology/travel-forecasting/ - type: Documentation url: https://au.travelctm.com/technology/ctm-mobile-app/ - type: Documentation url: https://au.travelctm.com/technology/ctm-scout/ - type: Documentation url: https://au.travelctm.com/technology/risk-management/ - type: Documentation url: https://au.travelctm.com/ndc/ - type: Documentation url: https://us.travelctm.com/ndc/ - type: Blog url: https://au.travelctm.com/blog/ - type: BlogRSS url: https://au.travelctm.com/blog/feed/ - type: BlogRSS url: https://us.travelctm.com/feed/ - type: News url: https://au.travelctm.com/news/ - type: TermsOfService url: https://au.travelctm.com/terms-and-conditions/ - type: PrivacyPolicy url: https://au.travelctm.com/privacy/ - type: CookiePolicy url: https://au.travelctm.com/cookie-policy/ - type: Compliance url: https://au.travelctm.com/payment-card-industry-data-security-standard/ - type: InvestorRelations url: https://investor.travelctm.com.au/ - type: Careers url: https://au.travelctm.com/careers/ - type: Contact url: https://au.travelctm.com/contact/ - type: LinkedIn url: https://www.linkedin.com/company/corporate-travel-management-ctm-group - type: Features data: - name: Lightning description: CTM's proprietary online booking tool, built and managed in-house, which aggregates GDS content, direct low-cost-carrier API connections and live airline NDC offers into a single policy-controlled corporate search and booking flow. - name: CTM Portal description: Single sign-on customer portal that consolidates CTM's travel tools for pre-trip planning, approvals, in-trip tracking, risk alerts and post-trip reporting. Live at portal.travelctm.com and www.ctmsmart.com.au for existing customers only. - name: CTM Approve description: End-to-end pre-trip approval workflow used to enforce corporate travel policy before a booking is ticketed. - name: CTM Data Hub description: Cloud-based travel reporting and analytics platform covering air, hotel, car, rail, traveller tracking, carbon emissions and wellbeing. No export, feed or API is documented. - name: CTM Fare Forecaster description: Predictive fare forecasting tool used to time corporate air purchases. - name: CTM Mobile App description: Traveller mobile application for booking and itinerary management on the go. - name: CTM Scout description: Chat-based booking and servicing channel for managing travel bookings. - name: Travel Risk Management description: Real-time traveller risk alerts by SMS and email plus a Travel Risk Hub of destination requirements. - name: NDC Content Integration description: Lightning ingests live NDC content from airlines — Qantas' Premium NDC connection in Australia, American Airlines and United Airlines in the United States — alongside GDS and direct API content. CTM consumes NDC; it does not publish an NDC endpoint of its own. maintainers: - FN: Kin Lane email: kin@apievangelist.com url: https://kinlane.com