# TUI Group > The world's largest integrated leisure tourism business — a vertically integrated tour operator that owns the hotels, cruise ships, airlines and retail brands it sells through, serving 34.7 million customers a year. TUI publishes a real, publicly readable developer portal at https://developer.tui fronted by an Apigee X gateway on the .tui brand TLD, listing 21 API products across flight shopping and booking, departure control, packages, accommodation content, cruise and metasearch distribution. A public OpenAPI 3.0 document exists for every product (1,261 operations in total). The documentation is open; the runtime is not — every product requires partner-manager approval, most flight products additionally require a Navitaire New Skies agent profile and a production IP allowlist, and the TUI fly OTA API requires a signed contract before step one. ## How to use TUI's APIs - Base URL pattern: `https://{env}.api.tui/{API_NAME}` where env is `prod`, `playground` or `pre-prod`. - Auth: OAuth 2.0 client credentials at `https://prod.api.tui/oauth2/token` (HTTP Basic with base64(consumer_id:consumer_secret)), token_type Bearer, lifetime 3599s. - Several products layer a second credential on top of the gateway token — a Navitaire New Skies agent session token, an `apikey` query parameter (Payment API), or a four-digit `anvrcode` header (ANVR G7). - There is no idempotency key anywhere in the estate. Never blind-retry a booking, order or payment call. - There are no rate-limit response headers and no documented 429. Throttle client-side to your assigned quota tier (Bronze 3 rps / Silver 6 / Gold 9 / Platinum 12; development 500 calls per day at 1 rps). - There are no webhooks, no callbacks and no AsyncAPI. The only push-shaped channel is the Supply SFTP file drop. ## Portal and documentation - [Developer portal](https://developer.tui/): the public API portal (Drupal 10 / Pronovix in front of Apigee X). - [API catalog](https://developer.tui/api-catalog): all 21 API products across 5 categories. - [Overview](https://developer.tui/docs/overview) - [Getting started](https://developer.tui/docs/getting-started) - [Environments](https://developer.tui/docs/getting-started_environments) - [Technical integration and quotas](https://developer.tui/docs/getting-started_technical-integration) - [OAuth 2.0](https://developer.tui/docs/general/oauth2) - [Authentication and app registration](https://developer.tui/docs/general/authentication) - [Sign up](https://signup.developer.tui) - [Support](https://developer.tui/support) ## APIs — flights - [TUI Flight NDC Gateway (Navitaire)](https://developer.tui/api-catalog/flight-ndc-gateway-navitaire): IATA NDC 21.3 Shopping / Selling / Servicing routed to Navitaire. `https://prod.api.tui/flight/ndc` - [TUI New Skies Digital API](https://developer.tui/api-catalog/newskies-digital-api): the Navitaire New Skies PSS surface — create and maintain flight bookings. `https://prod.api.tui/flight/newskies/rest` - [TUI New Skies GoNow API](https://developer.tui/api-catalog/newskies-gonow-api): full Departure Control System — check-in, baggage, boarding passes, disruption. `https://prod.api.tui/flight/newskies/gonow` - [TUI New Skies Payment API](https://developer.tui/api-catalog/newskies-payment-api): PCI-DSS scoped payment proxy, REST plus a legacy SOAP 1.1 channel. `https://prod.api.tui/flight/newskies/payment` - [TUI Flight Availability Search API (NSKCC)](https://developer.tui/api-catalog/nskcc-availability-search-api): real-time flight availability and pricing. `https://prod.api.tui/flight/newskies/availability/v2` - [TUI New Skies PriceFile API](https://developer.tui/api-catalog/tui-newskies-pricefile-api): base64 ZIP bulk fare files regenerated every ~15 minutes. `https://prod.api.tui/flight/newskies/pricefile` - [TUI CheckInHandler Service API](https://developer.tui/api-catalog/checkinhandler-service-api): `https://prod.api.tui/flight/newskies/checkinhandler` - [TUI Flight OTA API](https://developer.tui/api-catalog/tui-flight-ota-api): TUI fly Benelux content for resellers. `https://prod.api.tui/ota` ## APIs — packages, content and supply - [TUI TravelMessage G7 v3.1 API](https://developer.tui/api-catalog/b2bota-g7): session-based ANVR G7 XML booking flow for travel agents. `https://prod.api.tui/travelmessage/v3.1` - [TUI OTA Content API](https://developer.tui/api-catalog/ota-content-api): accommodation content companion to G7, JSON. `https://prod.api.tui/sales-ota-content` - [TUI Supply v1.5.1](https://developer.tui/api-catalog/supply): bulk package supply XML over SFTP (full and delta loads). `sftp://prod.sftp.tui-b2bota-g7.nl` ## APIs — search - [TUI WallDy Holiday Offers Search API](https://developer.tui/api-catalog/walldy-api): POST /offers, JSON or x-json-stream. `https://prod.api.tui/search-walldy` - [TUI HolidayOffersController API](https://developer.tui/api-catalog/holidayofferscontroller-api): `https://prod.api.tui/search-holiday-offers` ## APIs — metasearch partners - [TUI Meta Search Generics API](https://developer.tui/api-catalog/meta-search-generic-api): German accommodation inventory and availability. `https://prod.api.tui/sales/pip/germany/tui/generic` - [TUI Meta Partner Packages & Flights API](https://developer.tui/api-catalog/meta-partner-packages-flights): Nordic packages and flights. `https://prod.api.tui/sales/pip-package/partner` - [TUI Partner Live Search API](https://developer.tui/api-catalog/meta-partner-package-live-search): `https://prod.api.tui/sales/pip-package/live-search` - [TUI Partner Content API](https://developer.tui/api-catalog/partner-content-api): `https://prod.api.tui/sales/pip-package/content` ## APIs — cruise - [TUI Cruise Price and Availability API](https://developer.tui/api-catalog/tui-cruise-price-and-availability): cruise offers, alternate cabin/board/flight/stay search, stay upsell. `https://prod.api.tui/cruisepriceresults` - [TUI Cruise OTA Booking APIs](https://developer.tui/api-catalog/tui-cruise-booking-apis): validate-holiday, checkout-holiday, confirm-holiday. `https://prod.api.tui/cruise-ota-book` - [TUI Cruise Cabin Availability API](https://developer.tui/api-catalog/cruise-cabin-availability): `https://prod.api.tui/v2/cruises/cabinsavailability` - [TUI Ship Content API](https://developer.tui/api-catalog/ship-content-api): the estate's only GraphQL surface — cabin types, boards, deck plans. `https://prod.api.tui/cruises/ship` ## Machine-readable artifacts in this repo - `openapi/` — all 21 published OpenAPI 3.0 documents, harvested verbatim. - `overlays/` — one OpenAPI Overlay 1.0.0 per spec carrying API Evangelist enhancements. - `schemas/tui-b2bota-g7-travelmessage-v31.xsd` — TUI's variant of the ANVR G7 TravelMessage 3.1 XSD. - `collections/` — TUI's own downloadable Postman collections and environments (NDC Gateway, ANVR G7, PriceFile). - `authentication/tui-group-authentication.yml`, `scopes/tui-group-scopes.yml` — the auth and OAuth profile. - `well-known/` — the live OIDC discovery, RFC 8414 metadata, JWKS and RFC 9116 security.txt. - `conventions/tui-group-conventions.yml` — cross-cutting request/response semantics. - `errors/tui-group-problem-types.yml` — the four incompatible error envelopes in the estate. - `lifecycle/tui-group-lifecycle.yml`, `changelog/tui-group-changelog.yml` — versioning, deprecation, per-product release notes. - `conformance/tui-group-conformance.yml` — standards conformance (NDC 21.3, ANVR G7 3.1, OAuth 2.0, RFC 9457, PCI-DSS claim). - `rate-limits/tui-group-rate-limits.yml` — the published quota tiers. - `sandbox/tui-group-sandbox.yml` — the playground environment and what it does and does not give you. - `data-model/tui-group-data-model.yml` — the entity graph derived from the specs. - `mcp/` — the API Evangelist candidate MCP tool surface and its crosswalk to OpenAPI operations. TUI ships no MCP server. - `skills/` — packaged agent operating instructions for the marquee flows. - `security/` — domain security probe and vulnerability disclosure. - `agentic-access/tui-group-agentic-access.yml` — recommended x-agentic-access execution contracts. ## Security and policy - [Vulnerability disclosure policy](https://vdp.tui.com/p/Policy) - [Report a vulnerability](https://vdp.tui.com/p/Send-a-report) - [security.txt](https://www.tui.com/.well-known/security.txt) - [Privacy policy](https://developer.tui/privacy-policy) - [Terms of use](https://developer.tui/terms-of-use) — note: the page body is still unfilled placeholder text. ## Known gaps - No idempotency key on any of the 1,261 operations, including OrderCreate, booking payments and confirm-holiday. - No status page, no SLA, no RFC 8594 Sunset/Deprecation header, no deprecation notice period. - No AsyncAPI, no webhooks, no event catalogue. - No MCP server. No SDKs, no CLI, no embeddable components. - No `/.well-known/api-catalog` despite a 21-product public catalogue; the OIDC discovery documents at the gateway are unlinked from the portal. - No bulk export or data-portability operation for a departing partner.