# JetBlue > JetBlue Airways (IATA B6) is a New York-headquartered low-cost U.S. carrier. It publishes NO public developer portal, NO API reference and NO downloadable OpenAPI or NDC schema. Its inventory reaches third parties only through the GDS channel (settled via ARC in the U.S. and IATA BSPs internationally) and a gated IATA NDC program whose documentation and message schemas are supplied to onboarded, certified partners only. The one machine-readable contract JetBlue serves anonymously is the OpenID Connect / OAuth 2.0 discovery surface of its Okta-hosted consumer identity provider, accounts.jetblue.com. Generated by API Evangelist from https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/apis.yml on 2026-07-28. JetBlue serves no /llms.txt of its own (https://www.jetblue.com/llms.txt returns 404). ## APIs - No public API is documented by JetBlue. `developer.jetblue.com`, `developers.jetblue.com`, `docs.jetblue.com`, `apis.jetblue.com`, `ndc.jetblue.com` and `partners.jetblue.com` do not resolve; `api.jetblue.com` resolves behind Fastly and returns HTTP 404 at every probed path. ## Distribution and NDC - [Travel agents hub](https://www.jetblue.com/travel-agents): the only published third-party distribution surface; every documented workflow is a GDS workflow. - [NDC program](https://www.jetblue.com/travel-agents/ndc): names IATA New Distribution Capability; direct integrations for TMCs and technology partners after business use-case submission, onboarding, certification testing and go-live. NDC API documentation, schema and message samples, certification guidelines and release notes are partner-only. Contacts: ndcsales@jetblue.com (commercial), ndcsupport@jetblue.com (technical). - [Ticketing authority](https://www.jetblue.com/travel-agents/ticketing-authority): ARC accreditation (U.S.) or IATA accreditation plus local BSP participation (international). "We only work with a few Online Travel Agencies (OTAs) and we are not accepting new applications at this time." - [Booking policies](https://www.jetblue.com/travel-agents/booking-policies) · [Ticketing policies](https://www.jetblue.com/travel-agents/ticketing-policies) · [EMDs](https://www.jetblue.com/travel-agents/emd) · [Debit memos](https://www.jetblue.com/travel-agents/debit-memo) · [Chargebacks](https://www.jetblue.com/travel-agents/chargeback-policy) ## Identity surface (machine-readable) - [OpenID Connect discovery](https://accounts.jetblue.com/.well-known/openid-configuration): Okta-hosted issuer `https://accounts.jetblue.com`; authorization_code, implicit, refresh_token, password, device_code and CIBA grants; PKCE S256; DPoP; PAR; introspection and revocation endpoints. - [OAuth 2.0 authorization server metadata (RFC 8414)](https://accounts.jetblue.com/.well-known/oauth-authorization-server) - This is the consumer sign-in / TrueBlue identity backend for JetBlue's own clients. There is no published client-onboarding path for third parties. ## Artifacts in this repo - [apis.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/apis.yml) — APIs.json 0.19 provider record - [review.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/review.yml) — full switching-cost analysis and every probed URL with HTTP status - [well-known/jetblue-well-known.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/well-known/jetblue-well-known.yml) — /.well-known probe index across every JetBlue host - [well-known/jetblue-openid-configuration.json](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/well-known/jetblue-openid-configuration.json) - [well-known/jetblue-oauth-authorization-server.json](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/well-known/jetblue-oauth-authorization-server.json) - [authentication/jetblue-authentication.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/authentication/jetblue-authentication.yml) - [scopes/jetblue-scopes.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/scopes/jetblue-scopes.yml) - [conformance/jetblue-conformance.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/conformance/jetblue-conformance.yml) - [security/jetblue-vulnerability-disclosure.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/security/jetblue-vulnerability-disclosure.yml) - [security/jetblue-domain-security.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/security/jetblue-domain-security.yml) - [packages/jetblue-packages.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/packages/jetblue-packages.yml) - [mcp/jetblue-mcp.yml](https://raw.githubusercontent.com/api-evangelist/jetblue/refs/heads/main/mcp/jetblue-mcp.yml) ## Security - [Vulnerability Disclosure Policy](https://www.jetblue.com/legal/vulnerability-disclosure-policy) — coordinated disclosure, safe harbor for good-faith research, anonymous reports accepted. - [HackerOne program](https://hackerone.com/jetblue) — the reporting channel. No /.well-known/security.txt is served. ## Legal - [Website terms](https://www.jetblue.com/legal/website-terms) — section 9.1.5 prohibits robot/spider/page-scrape access without prior written consent. Do not scrape jetblue.com. - [Privacy policy](https://www.jetblue.com/legal/privacy) — manual right-to-know/right-to-delete via privacy@jetblue.com; no bulk or machine-readable export. - [Contract of carriage](https://legacycms.jetblue.com/public/dam/ui-assets/p/contract_of_carriage.pdf)