curl --request POST \
--url https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--header 'X-Signature: <x-signature>' \
--header 'X-Timestamp: <x-timestamp>' \
--data '
{
"reason": "customer_request",
"note": "Customer has an unexpected work conflict."
}
'import requests
url = "https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel"
payload = {
"reason": "customer_request",
"note": "Customer has an unexpected work conflict."
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"X-Timestamp": "<x-timestamp>",
"X-Signature": "<x-signature>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
'X-Timestamp': '<x-timestamp>',
'X-Signature': '<x-signature>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({reason: 'customer_request', note: 'Customer has an unexpected work conflict.'})
};
fetch('https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'reason' => 'customer_request',
'note' => 'Customer has an unexpected work conflict.'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>",
"X-Signature: <x-signature>",
"X-Timestamp: <x-timestamp>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel"
payload := strings.NewReader("{\n \"reason\": \"customer_request\",\n \"note\": \"Customer has an unexpected work conflict.\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("X-Timestamp", "<x-timestamp>")
req.Header.Add("X-Signature", "<x-signature>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel")
.header("Idempotency-Key", "<idempotency-key>")
.header("X-Timestamp", "<x-timestamp>")
.header("X-Signature", "<x-signature>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"reason\": \"customer_request\",\n \"note\": \"Customer has an unexpected work conflict.\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["X-Timestamp"] = '<x-timestamp>'
request["X-Signature"] = '<x-signature>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"reason\": \"customer_request\",\n \"note\": \"Customer has an unexpected work conflict.\"\n}"
response = http.request(request)
puts response.read_bodyCancel a booking
Cancels the booking and computes the refundable amount according to the rate pack’s cancellation tier (see ADR-012). The refund is:
- Net Safariat → partner: deducted from the current month’s settlement.
- Bank customer total: indicative only (the bank refunds its customer out-of-band on its platform).
No actual transfer takes place through this endpoint — the deduction appears on the next monthly invoice.
curl --request POST \
--url https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--header 'X-Signature: <x-signature>' \
--header 'X-Timestamp: <x-timestamp>' \
--data '
{
"reason": "customer_request",
"note": "Customer has an unexpected work conflict."
}
'import requests
url = "https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel"
payload = {
"reason": "customer_request",
"note": "Customer has an unexpected work conflict."
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"X-Timestamp": "<x-timestamp>",
"X-Signature": "<x-signature>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
'X-Timestamp': '<x-timestamp>',
'X-Signature': '<x-signature>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({reason: 'customer_request', note: 'Customer has an unexpected work conflict.'})
};
fetch('https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'reason' => 'customer_request',
'note' => 'Customer has an unexpected work conflict.'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>",
"X-Signature: <x-signature>",
"X-Timestamp: <x-timestamp>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel"
payload := strings.NewReader("{\n \"reason\": \"customer_request\",\n \"note\": \"Customer has an unexpected work conflict.\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("X-Timestamp", "<x-timestamp>")
req.Header.Add("X-Signature", "<x-signature>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel")
.header("Idempotency-Key", "<idempotency-key>")
.header("X-Timestamp", "<x-timestamp>")
.header("X-Signature", "<x-signature>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"reason\": \"customer_request\",\n \"note\": \"Customer has an unexpected work conflict.\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.safarapi.com/api/partner/v1/bookings/{booking_number}/cancel")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["X-Timestamp"] = '<x-timestamp>'
request["X-Signature"] = '<x-signature>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"reason\": \"customer_request\",\n \"note\": \"Customer has an unexpected work conflict.\"\n}"
response = http.request(request)
puts response.read_bodyAuthorizations
API key authentication. Issued by the Safariat admin or via the partner portal. The secret is shown only once at generation.
Production sk_live_* keys must additionally sign every write request
(POST/PUT/DELETE) with the X-Timestamp and X-Signature headers.
Sandbox sk_test_* keys are exempt from request signing: X-Signature and
X-Timestamp are not required for writes in the sandbox (so the developer-portal
"Try it" playground works end to end). The Idempotency-Key header remains
required on writes in both environments.
Headers
Opaque, client-generated string unique per logical operation (a UUID v4 is
recommended but any non-blank value up to 255 chars is accepted). Same key +
same body = the cached response is returned with the Idempotent-Replayed: true
header. Same key + different body = 409 Conflict. Retained for 24 h.
255Unix timestamp in seconds at the time the request is issued. Validity window
±5 minutes — beyond that the request is rejected. Required for production
sk_live_* keys only; not required for sandbox sk_test_* keys.
hex(HMAC_SHA256(secret, "{X-Timestamp}\n{METHOD}\n{path}\n{body}")).
The path includes the query string. The body is the exact JSON representation
sent — any reformatting invalidates the signature. Required for production
sk_live_* keys only; not required for sandbox sk_test_* keys.
^[a-f0-9]{64}$Path Parameters
Safariat booking number (format MV-XXXXXX). In the sandbox, create a booking first (POST /bookings) and use the returned number here.
^MV-[A-Z0-9]{6}$Body
Response
Booking cancelled, refund amounts computed
CANCELLED One refund tier of a cancellation grid, as published by the operator and frozen on the booking at confirmation. The same shape is returned by the rate pack, by the cancellation quote and by the cancellation itself.
Show child attributes
Show child attributes
Show child attributes
Show child attributes