{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Welcome to the TrueFlight External API","description":"Machine-to-machine HTTP API for flight schools—schedules, CRM, maintenance, LMS, and billing reads. OpenAPI is the contract.","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"welcome-to-the-trueflight-external-api","__idx":0},"children":["Welcome to the TrueFlight External API"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This portal documents TrueFlight’s machine-to-machine HTTP API for flight schools and training organizations. Use it to sync schedules, CRM data, maintenance, training (LMS), and billing-adjacent reads with your own systems, data warehouse, or partner tools."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The API reference in this site is generated from the same OpenAPI document linked below. Responses use JSON with a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["data"]}," envelope where noted; field names in payloads are snake_case, matching the live implementation."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"who-this-is-for","__idx":1},"children":["Who this is for"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You are building a server-side integration (cron jobs, ETL, middleware, or a trusted backend), not a browser client. All routes live under ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/api/external/v1"]}," on your TrueFlight deployment host—the same hostname you use for the web application. (Default is: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://trueflight.app"]},")"]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"getting-started","__idx":2},"children":["Getting started"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create an API key in the TrueFlight web app under Settings → Developer API. Keys are shown once; store them in a secret manager."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Call the API with the header:"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Authorization: Bearer <your_api_key>"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Keys are prefixed (for example ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["tf_live_…"]},") so you can tell environment and type at a glance."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Check connectivity with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GET /health"]}," (no auth required), then ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GET /me"]}," to confirm organization, allowed locations, and key scopes."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Respect scopes: read-only operations use read scope; create, update, and delete operations require write scope. The reference marks each operation accordingly."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Location context: many resources are scoped to an organization and optionally a location. Location-scoped keys behave predictably; org-wide keys often require a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["location_id"]}," query parameter where the resource is per-base. Details are in each operation’s description."]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"what-you-can-integrate","__idx":3},"children":["What you can integrate"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The current surface includes, subject to your plan and permissions:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Identity and ops — Health and caller context (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/me"]},", including location list where applicable)."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Schedule — Reservations (read and limited update where documented), aircraft, simulators, reservation types, instructors."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["CRM and billing reads — Companies (customers), invoices, read-only payments for reconciliation."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Maintenance — Squawks, maintenance reminders, and work orders."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["LMS — Courses, enrollments, exams, and exam attempts (including grading updates where documented)."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Read-only depth — Document templates and instances, store orders, contracts, discovery flight products—useful for reporting and portals without mutating regulated flows here."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For every shipped route, the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/tf-docs"},"children":["OpenAPI 3.1 description"]}," is the contract. Download it for codegen, contract tests, or importing into Postman, Insomnia, or your API gateway."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"webhooks","__idx":4},"children":["Webhooks"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["TrueFlight can POST event payloads to HTTPS endpoints you configure. Each delivery includes headers such as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["x-tf-signature"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["x-tf-timestamp"]},", and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["x-tf-delivery-id"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Verify authenticity by computing HMAC-SHA256 over the canonical string ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["timestamp.deliveryId.rawBody"]}," (using your endpoint’s signing secret, as shown once when the endpoint is created) and comparing to the hex signature in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["x-tf-signature"]},". Treat verification failures as non-retryable for that payload until you fix configuration."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Event types and payload shapes are summarized in the OpenAPI ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["info.description"]}," and in the reference; user lifecycle events (invites, acceptances, archive status) are documented there with field notes."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"errors-and-stability","__idx":5},"children":["Errors and stability"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Errors follow a consistent problem style (HTTP status plus a machine-readable ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["type"]}," and human-readable ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["detail"]}," where applicable). Prefer idempotent retries on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["5xx"]}," and transient network failures with backoff. Do not log full API keys or webhook signing secrets."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"openapi-file-in-this-folder","__idx":6},"children":["OpenAPI file in this folder"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/tf-docs"},"children":["OpenAPI description"]}," is the file this site uses to build the reference and link checker targets in this bundle. It is maintained in lockstep with the application so it is always up-to-date."]}]},"headings":[{"value":"Welcome to the TrueFlight External API","id":"welcome-to-the-trueflight-external-api","depth":1},{"value":"Who this is for","id":"who-this-is-for","depth":2},{"value":"Getting started","id":"getting-started","depth":2},{"value":"What you can integrate","id":"what-you-can-integrate","depth":2},{"value":"Webhooks","id":"webhooks","depth":2},{"value":"Errors and stability","id":"errors-and-stability","depth":2},{"value":"OpenAPI file in this folder","id":"openapi-file-in-this-folder","depth":2}],"frontmatter":{"seo":{"title":"Welcome to the TrueFlight External API"}},"lastModified":"2026-04-26T14:30:29.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}