# Quickstart

This walk-through books and cancels a transfer with a sandbox credential. Nothing real is created. It takes a few minutes and shows the pattern you will use on every product.

## Before you start

You need a sandbox credential. Ask your account manager for one (see [Support](/developers/guides/support)). A sandbox credential is a normal credential that Highstar Travel has marked as test. You cannot turn test mode on from the request, and the `X-Test-Mode` header is ignored.

In the examples, `YOUR_CREDENTIAL` stands for that credential. Send it in the `Authorization` header on every call.

## 1. List the catalog

```bash
curl -X POST "https://highstartravel.com/api/v1/transfer/getCatalog" \
  -H "Authorization: Bearer YOUR_CREDENTIAL" \
  -H "Content-Type: application/json" \
  -d '{}'
```

The response groups products by destination and service:

```json
{
  "success": true,
  "code": 200,
  "catalog": [
    {
      "id": 12,
      "title": "Orlando",
      "services": [
        {
          "id": 3,
          "title_es": "Aeropuerto a hotel",
          "title_en": "Airport to hotel",
          "service_types": [
            {
              "id": 301,
              "title_es": "MCO a zona Disney",
              "title_en": "MCO to Disney Area",
              "description_es": "Traslado privado",
              "description_en": "Private transfer",
              "max_pax": 4
            }
          ]
        }
      ]
    }
  ],
  "request_id": "3f8a9b7c1d2e4f5a6b7c8d9e0f1a2b3c"
}
```

The values in this page are examples. Your catalog has its own ids. The `id` inside `service_types` is the `id_product` you use in the next calls.

## 2. Ask for a price

```bash
curl -X POST "https://highstartravel.com/api/v1/transfer/getPrice" \
  -H "Authorization: Bearer YOUR_CREDENTIAL" \
  -H "Content-Type: application/json" \
  -d '{
    "id_product": 301,
    "adults": 2,
    "children": 0,
    "date": "2026-11-17"
  }'
```

You get a calendar with one row per date. Pick a date with `available: true` and keep its `price`:

```json
{
  "success": true,
  "code": 200,
  "product": { "id": 301, "title_es": "MCO a zona Disney", "title_en": "MCO to Disney Area", "id_destination": 12, "id_service": 3 },
  "pax": { "adults": 2, "children": 0, "infants": 0, "total_pax": 2 },
  "from_date": "2026-11-17",
  "to_date": "2026-11-17",
  "calendar": [ { "date": "2026-11-17", "available": true, "price": 120.0 } ],
  "request_id": "3f8a9b7c1d2e4f5a6b7c8d9e0f1a2b3c"
}
```

## 3. Confirm the booking

Send the price you just read as `total_amount`. The first passenger is the lead traveler and needs a name, surname, phone and nationality.

```bash
curl -X POST "https://highstartravel.com/api/v1/transfer/transferConfirm" \
  -H "Authorization: Bearer YOUR_CREDENTIAL" \
  -H "Content-Type: application/json" \
  -d '{
    "id_product": 301,
    "adults": 2,
    "children": 0,
    "date": "2026-11-17",
    "total_amount": 120.00,
    "external_reference": "MY-SYSTEM-0001",
    "pax": [
      { "name": "John", "surname": "Doe", "phone": "+1 407 555 0100", "nationality": "US" }
    ]
  }'
```

With a sandbox credential the response has `test_mode: true`:

```json
{
  "success": true,
  "code": 200,
  "id_order": 168001,
  "pdf_voucher": "https://highstartravel.com/api/v1/transfer/pdf?order_id=168001",
  "test_mode": true,
  "request_id": "3f8a9b7c1d2e4f5a6b7c8d9e0f1a2b3c"
}
```

Keep `id_order`. You need it for the next two steps.

## 4. Download the voucher

```bash
curl "https://highstartravel.com/api/v1/transfer/pdf?order_id=168001" \
  -H "Authorization: Bearer YOUR_CREDENTIAL" \
  -o voucher.pdf
```

A sandbox voucher is marked as a test and has no validity.

## 5. Cancel

```bash
curl -X POST "https://highstartravel.com/api/v1/transfer/transferCancelation" \
  -H "Authorization: Bearer YOUR_CREDENTIAL" \
  -H "Content-Type: application/json" \
  -d '{ "id_order": 168001 }'
```

## If a call fails

Every error has the same JSON shape, with an `error` label, a `message` and the `request_id`. Branch on the HTTP status and the `error` label, and keep the `request_id` to send to support. See [Errors](/developers/guides/errors).

## Next

- [Transfers](/developers/guides/transfers) explains each step of this flow and the optional fields.
- [Conventions](/developers/guides/conventions) covers retries, rate limits and idempotency.
- [Sandbox](/developers/guides/sandbox) shows how test mode behaves on hotels, Universal and Disney.
