What partner access includes

Partner data is available through two channels, both served from a single endpoint dedicated to your organisation.

APIs

JSON resources are shared as REST APIs over HTTPS: the request and response model you use when your application asks for data on demand, such as arrivals or departures for a given day.

Messages

The same kind of information is also available as a message stream you subscribe to, for real-time updates rather than polling. Messages are delivered over AMQP over WebSockets, on a topic and subscription dedicated to your organisation.

One endpoint for both

APIs and messages are served from a single partner endpoint assigned to you, in the form {your organization name}.api.gva.ch. You register and secure one entry point rather than one per channel.

How access is protected

  • IP filtering: only requests coming from the public IP addresses or ranges you register can reach your endpoint. This applies to APIs and messages alike.

  • OAuth 2.0 client credentials: requests that pass the network check are authorised with a token, obtained using either a client secret or a client certificate.

Compatibility and change

We understand the importance of seamless integration between our systems and yours. Our data needs evolve, which sometimes means adding fields to a schema. Such changes are designed with backward and forward compatibility in mind wherever possible. Where full compatibility is not feasible a new schema version is created, and the previous version gets a defined deprecation period so you have time to migrate.

Detailed technical documentation, including authentication, endpoints, code samples and message connection details, becomes available once your organisation is registered.

Powered by Genève Aéroport