# Virgin Atlantic > Virgin Atlantic Airways (IATA code VS) is a United Kingdom long-haul carrier based at London Heathrow and Manchester. Its only published API surface is distribution: the VS NDC Connect portal at ndc.virginatlantic.com documents twelve IATA NDC 21.3 messages with full request/response reference pages, airline-authored XML samples, workflow guides, a partner certification programme and downloadable IATA NDC 21.3.3 XSD schema assets — all readable without a login. There is no consumer, flight-status or loyalty API, no OpenAPI/Swagger/GraphQL/AsyncAPI document, no SDK and no published base URL. Transport is HTTP POST with `application/xml` request and response bodies, authenticated with a single API key in the `Ocp-Apim-Subscription-Key` header. Test API keys are self-serve on portal registration; production access requires IATA accreditation plus Virgin Atlantic ticketing authority, RED-tier certification and signed TUA/DPA/ASA agreements. This file was generated by API Evangelist from the public VS NDC Connect documentation and the artifacts harvested into the api-evangelist/virgin-atlantic repository. Virgin Atlantic does not publish an llms.txt of its own (`/llms.txt` returns 404 on every Virgin Atlantic host). ## APIs Twelve IATA NDC 21.3 messages, each documented with a request reference, a response reference and airline-authored XML samples. - [AirShopping](https://ndc.virginatlantic.com/docs/airshopping): Flight shopping and availability search returning Virgin Atlantic offers, including calendar and multi-city itineraries. - [OfferPrice](https://ndc.virginatlantic.com/docs/offerprice): Prices a selected offer and returns the firm, bookable price with applicable rules before an order is created. - [OrderCreate](https://ndc.virginatlantic.com/docs/ordercreate): Creates the Order and PNR from a priced offer, including passenger details and form of payment; returns an OrderView response. - [SeatAvailability](https://ndc.virginatlantic.com/docs/seatavailability): Returns the seat map and seat pricing for an offer or an existing order. - [ServiceList](https://ndc.virginatlantic.com/docs/servicelist): Returns the ancillary services available against an offer or an order, such as bags and paid services. - [OrderRetrieve](https://ndc.virginatlantic.com/docs/orderretrieve): Retrieves a single Order by order identifier or PNR record locator. - [OrderReshop](https://ndc.virginatlantic.com/docs/orderreshop): Searches for alternative offers against an existing order, for voluntary date and time changes. - [OrderQuote](https://ndc.virginatlantic.com/docs/orderquote): Quotes the price of a proposed change to an existing order, including requote and confirm of a held booking. - [OrderChange](https://ndc.virginatlantic.com/docs/orderchange): Applies changes to an existing order — APIS amendment, name correction, split order, post-sale seat and service purchase, voluntary cancellation. - [OrderChangeNotif](https://ndc.virginatlantic.com/docs/orderchangenotif): Airline-initiated push to the seller for schedule changes, cancellations and irregular operations. Subscription required. - [OrderList](https://ndc.virginatlantic.com/docs/orderlist): Returns a list of orders matching search criteria for the authenticated seller. - [OrderHistory](https://ndc.virginatlantic.com/docs/orderhistory): Returns the change history of an order. Per-order only — there is no bulk export operation. ## Specs and schemas - [IATA NDC 21.3.3 schema assets](https://ndc.virginatlantic.com/file-lists/schema-assets): The downloadable XSD set (targetNamespace `http://www.iata.org/IATA/2015/EASD/00/IATA_OffersAndOrdersMessage`, schema version 9.001, id IATA2021.3). Harvested to `schemas/`. - [IATA XSD viewer](https://retailing.iata.org/tools/xsd_viewer/): The tool Virgin Atlantic points partners at for reading the schemas. - No OpenAPI, Swagger, AsyncAPI, GraphQL SDL, Postman collection or `/.well-known/` document exists on any Virgin Atlantic host. ## Getting started - [VS NDC Connect portal](https://ndc.virginatlantic.com/) - [How to access the NDC APIs](https://ndc.virginatlantic.com/help/how-to-access-ndc-apis): The accreditation and agreement gate. - [How to start your build](https://ndc.virginatlantic.com/help/how-to-start-your-build): Headers, HTTP method, encoding and the API key. - [Register](https://ndc.virginatlantic.com/account/register): Self-serve organisation registration; test API keys follow. - [Certification](https://ndc.virginatlantic.com/certification): RED / SILVER / GOLD tiers. RED is the minimum for a production key. - [Testing your build](https://ndc.virginatlantic.com/docs/testing-your-build): Published test credit card numbers, 3DS test values and test Flying Club numbers. ## Capabilities and workflows - [Offer capabilities](https://ndc.virginatlantic.com/capability/offer): Prime Sale Without Seat, Prime Sale With Seat, Prime Sale With Service, Private/Corporate Fares. - [Order capabilities](https://ndc.virginatlantic.com/capability/order): Hold Booking, Requote/Confirm Held Booking, Post Sale Seat Purchase, Post Sale Service Purchase, Name Correction, Split Order, Amend APIS Info, Voluntary Change, Voluntary Cancellation. - [NDC roadmap](https://ndc.virginatlantic.com/capability/ndc-roadmap): Dated public roadmap with PreLive and Live dates per capability. - [Release notes](https://ndc.virginatlantic.com/product-release): Public page; row content requires a partner login. ## Runtime rules - Authentication: API key in the `Ocp-Apim-Subscription-Key` HTTP header. No OAuth, no OIDC, no mTLS. Failure code `111 — Invalid Agent's IATA API Key`. - Transport: HTTP POST to every endpoint. `Accept: application/xml`, `Content-Type: application/xml`, UTF-8. - Base URL: not published. Endpoints are issued with the API key after approval. - Errors: repeating `` elements carrying a PADIS 9321 ``, ``, ``, `` and a `` processing status (NotProcessed | Processed | Unavailable | Unknown | Retry). Not RFC 9457. - Idempotency: not supported. Duplicate protection comes from the offer lifecycle instead — an OfferID is single-use and time-limited, and replaying a consumed or expired offer returns error `913`. - Pagination: none documented. Result sets are bounded by business rules (AirShopping accepts a maximum of 9 passengers and rejects more than 6 origin/destination pairs — error `724`). - Rate limits: none published. - Versioning: by IATA NDC schema release (currently 21.3). No version header, no URI version segment, no deprecation policy and no Sunset header support. ## Support and policies - [Support](https://ndc.virginatlantic.com/support) - [News](https://ndc.virginatlantic.com/news) - [Partner hub policies](https://flywith.virginatlantic.com/gb/en/partner-hub/policies.html) - [Distribution policy](https://flywith.virginatlantic.com/gb/en/partner-hub/policies/distribution-policy.html) - [NDC Novation policy](https://flywith.virginatlantic.com/gb/en/partner-hub/policies/NDC_Novation_Policy.html) - [Privacy notice](https://www.virginatlantic.com/policies/virgin-atlantic-airways-and-virgin-atlantic-holidays-privacy-notice) ## API Evangelist artifacts Repository: https://github.com/api-evangelist/virgin-atlantic - `apis.yml` — APIs.json index for the twelve NDC messages. - `schemas/` — harvested IATA NDC 21.3.3 XSDs. - `examples/` — 92 airline-authored XML request/response samples (`examples/_index.yml`). - `authentication/virgin-atlantic-authentication.yml` — API-key auth profile. - `conventions/virgin-atlantic-conventions.yml` — cross-cutting runtime semantics. - `errors/virgin-atlantic-error-codes.yml` — published PADIS error and warning registry. - `data-model/virgin-atlantic-data-model.yml` — NDC list-and-reference entity graph. - `asyncapi/virgin-atlantic-orderchangenotif-webhooks.yml` — the OrderChangeNotif push surface. - `sandbox/virgin-atlantic-sandbox.yml` — published test keys, test cards, 3DS values, test Flying Club numbers. - `lifecycle/virgin-atlantic-lifecycle.yml` — versioning, roadmap, release and status posture. - `changelog/virgin-atlantic-changelog.yml` — dated change history. - `conformance/virgin-atlantic-conformance.yml` — standards conformance (IATA NDC, ARM, PADIS, XSD, 3DS2). - `packages/virgin-atlantic-packages.yml` — registry probe results (no first-party SDK exists). - `well-known/virgin-atlantic-well-known.yml` — `/.well-known/` probe results (nothing published). - `security/virgin-atlantic-domain-security.yml` — TLS/HSTS/DNS posture. - `skills/` — packaged agent skills for the marquee published flows.