# Webjet Group > Webjet Group Limited (ASX: WJL) is the Australian consumer travel company created when Webjet Limited demerged in September 2024 — the B2C half, while the B2B WebBeds bed bank went to Web Travel Group (ASX: WEB). It operates Webjet OTA (webjet.com.au / webjet.co.nz), the GoSee vehicle-rental brands Airport Rentals and Motorhome Republic, and Trip Ninja, a travel-technology business selling flight-construction software to other travel platforms. Read this first: the group's API posture is lopsided. The consumer brands publish **no** developer documentation and **no** public API — developer/api/docs subdomains do not resolve and www.webjet.com.au returns 403 to non-browser clients. Every API artifact below belongs to **Trip Ninja**. Trip Ninja supplies no air content of its own: it optimises content the consuming platform has already sourced from its own GDS, NDC or aggregator connections. Access is gated. Docs are freely readable with no login, but production use requires a commercial agreement, Trip Ninja-issued Admin Panel credentials, IP allow-listing and a certification pass. Every API host returns 403 to a non-allow-listed IP even with a valid token. There is no self-serve signup. Generated by API Evangelist (https://apievangelist.com) — 2026-07-28. Not published by Webjet Group. ## APIs - [Trip Ninja SmartFlights API (v3, current)](https://devhub.tripninja.io/smartflights/overview/): Post a traveller search to /v3/get-searches/, run the returned content queries against your own sources, post the zlib+Base64-compressed responses to /v3/generate-solutions/, receive unified split-ticket and virtual-interlined itineraries with machine-learned markups. Report outcomes via /v3/report/book/ and /v3/report/cancel/. Base: https://sandbox.tripninja.io (production: https://api.tripninja.io). - [Trip Ninja Admin Panel API](https://devhub.tripninja.io/smartflights/authentication/): POST /adminpanel/refresh-token/ exchanges a refresh token for a new 90-day access token. - [Trip Ninja FareStructure API (v2, deprecated)](https://devhub.tripninja.io/deprecated/farestructure/overview): split ticketing across multiple content sources for multi-city itineraries. - [Trip Ninja Virtual Interlining API (v2, deprecated)](https://devhub.tripninja.io/deprecated/virtual-interlining/overview): combines segments from carriers with no interline agreement into one sellable itinerary. Folded into SmartFlights. - [Trip Ninja DataStream API](https://devhub.tripninja.io/data-stream/overview/): separately credentialled product. Documented in prose; no OpenAPI and no base URL published. - [Trip Ninja Flights Core / Pricing & Booking / Hotels / MSDP (GitHub-published)](https://github.com/trip-ninja-inc/trip_ninja_api_docs): six further OpenAPI 3.0.0 documents published in Trip Ninja's own GitHub organisation, covering flight search + price confirmation + booking + ticketing + cancellation, a full booking/ticketing/queue surface, hotel shopping, and MSDP dynamic packaging. Host: https://preprodapi.tripninja.io. Last updated 2023-12-14 and not linked from the current developer hub. ## Specs - [SmartFlights get-searches](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-smartflights-get-searches-openapi.yml) - [SmartFlights generate-solutions](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-smartflights-generate-solutions-openapi.yml) - [SmartFlights report/book](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-smartflights-report-book-openapi.yml) - [SmartFlights report/cancel](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-smartflights-report-cancel-openapi.yml) - [Admin Panel refresh-token](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-adminpanel-refresh-token-openapi.yml) - [Flights core (GitHub-published)](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-flights-core-openapi.yml) - [Pricing & booking (GitHub-published)](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-pricing-booking-openapi.yml) - [Hotels (GitHub-published)](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-hotels-openapi.yml) - [MSDP dynamic packaging (GitHub-published)](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-msdp-openapi.yml) - [FareStructure v2 (deprecated)](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-farestructure-get-searches-openapi.yml) - [Virtual Interlining v2 (deprecated)](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/openapi/webjet-tripninja-virtual-interlining-get-searches-openapi.yml) ## Operating rules - [Authentication](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/authentication/webjet-authentication.yml): `Authorization: Token ` (90-day expiry) or HTTP Basic. No OAuth, no OIDC, no scopes. The SDKs additionally use `POST /sdk/auth/` with `X-Client-ID` / `X-Client-Secret`. - [Conventions](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/conventions/webjet-conventions.yml): REST/JSON, POST-only on v3, mandatory zlib+Base64 request compression on generate-solutions, **no idempotency contract**, no request-id header, no rate-limit headers. - [Error codes](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/errors/webjet-error-codes.yml): 43 published IExx codes in a proprietary `{status, message}` envelope. Not RFC 9457. - [Rate limits](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/rate-limits/webjet-rate-limits.yml): 5,000 requests/day in sandbox. No production limit published. - [Sandbox](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/sandbox/webjet-sandbox.yml): real pre-production environment, but no self-serve access and no magic test values. - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/lifecycle/webjet-lifecycle.yml): uri-path versioning, v2 deprecated by documentation placement only. No status page, no changelog, no roadmap, no SLA. - [Data model](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/data-model/webjet-data-model.yml): Trip -> DatasourceRequest -> PricingSolution -> Itinerary -> BookingReport. No read/list/export operation on the current surface. - [Conformance](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/conformance/webjet-conformance.yml): OpenAPI 3.0.0 only. No NDC, OpenTravel/OTA, HTNG or ONE Order. IATA codes are used as data, not IATA message standards. - [Agent skills](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/skills/_index.yml) - [Tool crosswalk](https://raw.githubusercontent.com/api-evangelist/webjet/refs/heads/main/mcp/webjet-tool-crosswalk.yml) ## SDKs - [tn-sdk (Python)](https://pypi.org/project/tn-sdk/) — `python3 -m pip install -U tn_sdk`, Apache-2.0, source at https://github.com/trip-ninja-inc/tn-sdk-python - [TripNinja.SDK (C#)](https://www.nuget.org/packages/TripNinja.SDK) — `dotnet add package TripNinja.SDK`, Apache-2.0, source at https://github.com/trip-ninja-inc/tn-sdk-csharp Both are narrow compression + auth helpers, not full API clients. ## Docs - [Developer hub](https://devhub.tripninja.io/) - [SmartFlights setup](https://devhub.tripninja.io/smartflights/setup/) - [Authentication](https://devhub.tripninja.io/smartflights/authentication/) - [Certification](https://devhub.tripninja.io/smartflights/certification/) - [Troubleshooting / error codes](https://devhub.tripninja.io/smartflights/troubleshooting/) - [SDK quick start](https://devhub.tripninja.io/sdk/quick-start-guide/) - [Postman workspace](https://www.postman.com/tripninjadevteam/trip-ninja-public/overview) - [Admin Panel](https://app.tripninja.io) - [Trip Ninja pricing](https://www.tripninja.io/pricing) - [Contact / access request](https://www.tripninja.io/contact) - [Terms of Service](https://www.tripninja.io/legal/qt-tc) - [GDPR terms](https://www.tripninja.io/legal/gdpr) - [Webjet Group corporate site](https://www.webjetgroup.com/) ## Not published No status page. No changelog or release notes. No roadmap. No SLA. No webhooks, events or AsyncAPI. No GraphQL. No MCP server. No CLI. No embedded UI components. No `/.well-known/` document of any kind on any host — no security.txt, no OIDC metadata, no api-catalog. No bug bounty or vulnerability disclosure programme. No trust centre and no named security certification (no SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim). No data-export or portability operation — exit is contractual (60-day return of Customer Personal Data under the GDPR terms), not an API call.