Single Trip Quote to Purchase Flow

Sequence diagram and text equivalent for the deferred hosted-payment Single Trip Quote to Purchase workflow.

Audience: Partner developers and solution architects implementing single-trip quote-to-purchase flowsLast Updated: August 18, 2026

Single Trip Quote to Purchase Flow

This workflow shows the recommended deferred hosted-payment sequence for a single-trip policy purchase. Use it with the API Integration Guide and Payment Integration Guide when wiring quote, staging, hosted payment, and policy binding requests.

Sequence Diagram

sequenceDiagram
    autonumber
    actor Traveler as Traveler
    participant PartnerApp as Partner app
    participant PartnerBackend as Partner backend
    participant TiiGraphQL as Travel Insured GraphQL API
    participant PaymentApp as Travel Insured payment app
    participant HostedForm as Hosted payment form

    Traveler->>PartnerApp: Enter trip and traveler details
    PartnerApp->>PartnerBackend: Submit quote request inputs
    PartnerBackend->>TiiGraphQL: quote
    TiiGraphQL-->>PartnerBackend: Available plans and quoted premiums
    PartnerBackend-->>PartnerApp: Present eligible plans and coverage
    Traveler->>PartnerApp: Select plan and provide purchaser details
    PartnerApp->>PartnerBackend: Submit selected plan and purchaser details
    PartnerBackend->>TiiGraphQL: stagePolicyPurchase
    TiiGraphQL-->>PartnerBackend: planGuid, quoteNumber, amount due
    PartnerBackend->>PaymentApp: Create embedded payment session with planGuid
    PaymentApp-->>PartnerBackend: paymentSessionId, embedToken, expiresAt
    PartnerBackend-->>PartnerApp: Return safe payment session values
    PartnerApp->>HostedForm: Mount hosted payment form with embedToken
    Traveler->>HostedForm: Enter card details
    HostedForm->>PaymentApp: Tokenize and submit card data
    PaymentApp-->>PartnerApp: Payment status event
    PartnerApp->>PartnerBackend: Confirm successful payment status
    PartnerBackend->>TiiGraphQL: policyBindRequest
    TiiGraphQL-->>PartnerBackend: Policy number and bound policy status
    PartnerBackend-->>PartnerApp: Return confirmation details
    PartnerApp-->>Traveler: Show purchase confirmation
Single Trip Quote to Purchase flow from quote creation through hosted payment and policy binding.

Text Sequence Equivalent

StepInitiatorRequest or eventResult
1TravelerEnters trip and traveler details in the partner experiencePartner app has the information needed to request a quote
2Partner backendCalls quote on the Travel Insured GraphQL APIEligible plans, coverage options, and quoted premiums are returned
3TravelerSelects a plan and provides purchaser detailsPartner app can stage the selected policy purchase
4Partner backendCalls stagePolicyPurchaseTravel Insured returns planGuid, quoteNumber, and amount due
5Partner backendCreates an embedded payment session with the Travel Insured payment appSafe client values such as paymentSessionId, embedToken, and expiresAt are returned
6Partner appMounts the hosted payment form using the safe session valuesTraveler sees the secure Travel Insured-hosted card-entry form
7TravelerEnters card details in the hosted payment formCard data is tokenized and submitted without touching partner servers
8Payment appSends a safe payment status event to the partner appPartner app can notify the backend that payment succeeded
9Partner backendCalls policyBindRequest after successful paymentTravel Insured returns the policy number and bound policy status
10Partner appDisplays confirmation detailsTraveler receives purchase confirmation

Implementation Notes

  • Keep partner API credentials on the server. Never send Authorization or x-api-key values to the browser.
  • Use quote before staging so the traveler can review eligible plans and premium amounts before purchase.
  • Use stagePolicyPurchase to create the planGuid required by the hosted payment session.
  • Pass only safe payment session values, such as paymentSessionId and embedToken, from your backend to your browser application.
  • Call policyBindRequest only after a successful payment status is confirmed by your backend.
  • Treat all identifiers and status events received by the browser as untrusted until your backend verifies the transaction state server-side.