50
Travellers per quote
You can price 1 to 50 people in a single call. Past ten travellers the group product takes over: the same price per person, whatever their age.
Developer platform
A signed conversion API, tracked deep links and an S2S postback into your stack. Free to integrate and free per call: you are paid on commission.
What sits behind the API
50
You can price 1 to 50 people in a single call. Past ten travellers the group product takes over: the same price per person, whatever their age.
193
The traveller gets priced whatever country they set out from.
193
Every destination, high-risk areas included.
26
Journey, documents and summary in the traveller's own language.
33
The price shows in the traveller's own currency.
28
Health, assistance, trip, belongings, liability, activities, expat. Ceilings and deductibles in the response.
What you do not have to build
HelloSafe is the regulated distributor and carries the compliance. You embed the experience, not the regulation.
One call, the whole catalogue. The connections, the product updates and the policy documents stay with us.
The sandbox key is one click from your account. No review, no card, no meeting.
Integration paths
From a tracked link in an afternoon to a REST quote API: pick your level of integration. Same cover, same commissions.
One tracked link per piece of content or campaign, with a Sub-ID. The fastest way to start, zero code.
Notify Atlas when an attributed sale lands or changes state. HMAC-signed request, state machine, idempotent.
Send conversions back to wherever you run your business: Impact, Partnerize, Awin, Voluum, RedTrack, Everflow or a BI webhook.
Price a trip across insurers, mint the tracked sale link, and read what a traveller's card leaves uncovered. One key for all of it. Create an account and the sandbox key is one click away.
Expose HelloSafe as typed tools your LLM can call: search, compare, hand over the tracked link. In private beta.
Documentation
The docs are public and in English. No login, no form: everything the API answers is written down.
Sandbox key, signed request, first priced offers. Node, cURL and PHP.
Quickstart →Endpoints, trip fields, cover slugs, error codes and quotas.
API reference →The machine readable contract, for your client generator.
OpenAPI spec →Live check of the API, availability commitments and incident log.
API status →The conversion API, concretely
The conversion API is live today. You post an attributed sale, Atlas matches it to the link, converts to EUR (our accounting currency) and computes the commission from your rate card.
During the launch phase, keys are granted on request. You get a key_id and a signing secret scoped to your integration.
Compute HMAC-SHA256 of the secret over timestamp.body, then send the x-atlas-key-id, x-atlas-timestamp and x-atlas-signature headers. The replay window is 5 minutes.
Send ref and externalOrderId, plus the gross amount in its native currency and the state. Atlas freezes the FX rate, computes the commission and returns the applied state.
import { createHmac } from "node:crypto";
const secret = process.env.ATLAS_SIGNING_SECRET;
const body = JSON.stringify({
ref: "hs-acme-7f3k9",
externalOrderId: "ORDER-5821",
amount: 79.90,
currency: "GBP",
status: "validated"
});
const ts = Math.floor(Date.now() / 1000).toString();
const signature = "v1=" + createHmac("sha256", secret)
.update(`${ts}.${body}`)
.digest("hex");
await fetch("https://atlas.hellosafe.com/api/postback/conversion", {
method: "POST",
headers: {
"Content-Type": "application/json",
"x-atlas-key-id": "pbk_live_a1b2c3",
"x-atlas-timestamp": ts,
"x-atlas-signature": signature
},
body
});
// → 200 { ok: true, action: "inserted", status: "validated" } Postback signed with HMAC-SHA256. A 200 returns the applied action and state.
Payload reference
JSON. ref and externalOrderId are required; everything else is optional. Any commission you send is ignored, the ledger is the source of truth.
| Field | Type | Required | Description |
|---|---|---|---|
ref | string | Yes | Attribution identifier, in the partnerCode-shortCode format. |
externalOrderId | string | Yes | Your order identifier. Acts as the idempotency key on the Atlas side. |
amount | number | No | Gross sale amount, in its native currency. |
currency | string (3) | No | ISO 4217 code. An unknown currency is stored needs_fx and priced later. |
status | enum | No | pending, validated or cancelled. Defaults to pending. |
subId | string | No | Campaign or content sub-identifier, for your reporting. |
Response codes
Explicit HTTP codes. Forbidden state transitions are never silently applied.
| Code | Meaning |
|---|---|
200 | Conversion recorded. action: inserted, updated, transitioned or unchanged. |
400 | Missing fields, invalid ref, or a ref that does not match the link owner. |
401 | Invalid signature, key or timestamp (5-minute window). |
404 | No link found for this ref. |
409 | Forbidden state transition: the state machine refuses it. |
422 | Amount above the per-conversion safety ceiling. |
Authentication & security
Every caller has its own key and its own secret. Nothing is shared, everything is revocable.
A distinct key_id and signing secret per integration. Revoke one without touching the others.
The signature covers timestamp.body byte for byte. Any tampering with the body invalidates the request.
Requests whose timestamp is more than 5 minutes off are rejected. No replaying a captured request.
pending to validated or cancelled; validated to cancelled only; cancelled is terminal. Re-sending the same state is a no-op.
Reliability & support
The conversion API and tracked links run on Cloudflare's edge network. Here is what you can plan around for uptime, retries and support.
99.9%
Postbacks and tracked links run on Cloudflare Workers with automatic failover. No single region can take the service down.
300+
Requests are served from the Cloudflare point of presence nearest your users; commission and FX are then computed asynchronously, off your checkout's critical path.
< 24h
Email support answers within one business day, on business days. Integration questions reach the partner engineering team, not an anonymous queue.
5 min
Idempotent by externalOrderId: retry on any timeout without double-counting, and a captured request cannot be replayed past five minutes.
The status page is public: a live check of the API, what we commit to, and every incident since the API opened. Your integration and incident contact stays the partner team, reachable from the contact page. API status →
AI agents
The MCP server exposes pricing, comparison and the card check as typed tools. Access on request.
No per-insurer integration, no quoting logic to write, no regulatory plumbing. Your copilot, your chatbot or your booking flow calls a tool and gets a real offer back, with its ceilings and its documents. Tell us what you are building.
What teams ask before they integrate.
Nothing. There is no setup fee, no monthly platform fee and no per-call charge on the conversion API or deep links. You earn 50% of commissions on sales your integration drives; that is the only money flow in the programme.
Both are live. The conversion (postback) API and the pricing REST API: create an account and mint a sandbox key in one click, then apply for production once your integration runs.
Per-caller signed keys. You compute HMAC-SHA256 of the secret over timestamp.body and send it in x-atlas-signature, with a 5-minute replay window. A legacy Bearer path exists while existing callers migrate.
The gross amount in its native currency, with the currency code (GBP for UK sales). Atlas freezes the rate at ingest, converts to EUR (our internal accounting currency) and computes the commission from your rate card. Any commission you send is ignored.
Yes. externalOrderId is the key: re-sending the same state is a no-op, and the state machine refuses forbidden transitions with a 409 rather than applying them silently.
Yes. We expose a standard S2S postback that connects natively to Impact, Partnerize, Awin, Voluum, RedTrack and Everflow, or a webhook to your BI.
Yes, published at /openapi.json, OpenAPI 3.1, with the full reference at /platform/api/documentation. The conversion API is documented by its contract above: endpoint, signed headers, payload and response codes.
Yes, in private beta. The MCP server exposes quoting, comparison and binding as typed tools your LLM or agent can call.
The conversion API and tracked links run on Cloudflare Workers, deployed across 300+ edge locations with automatic failover, for a target of 99.9% uptime. Email support answers within one business day. The postback is idempotent, so any timeout is safe to retry. A public status page is on the roadmap.
No. One key opens every endpoint: pricing, tracked links and the Coach briefing. The sandbox key you mint from the dashboard carries all three scopes, so you can try the whole API before talking to anyone.
Have a technical or commercial question? Contact us
Let's build
Create your account and mint a sandbox key in one click: fixed sample data, no insurer called, nothing to sign. Live access is a short review once your integration runs.