Play Tickets

API

A key for one client

Each key belongs to one client. It can read that client’s events, orders, and tickets, create an event, and mark a ticket used. It cannot see another client, and it cannot charge a card. Sign in as the client (or a partner selling on its own), open API keys, and create a key. The full key is shown once. Store it like a password. Revoking a key makes it stop working immediately.

https://playticketing.fun

Call it

Send the key on every call except the index and this OpenAPI file.

curl https://playticketing.fun/api/v1/me \
  -H "Authorization: Bearer pwmt_your_key"

A bad or revoked key returns 401. A missing event, order, or ticket returns 404, including one that belongs to someone else. A bad body returns 400. Every error looks like this.

{ "error": "That API key is not valid." }

Money is cents. Times are ISO-8601 in UTC. status on an order is paid, pending, expired, or failed. A price of 0 is a free ticket. usedAt is null until the guest is admitted.

GET /api/v1/me

Who this key belongs to.

Response

{
  "client": { "id": "…", "name": "The Rooftop", "slug": "the-rooftop" },
  "key": { "name": "Door app", "prefix": "pwmt_a1B2c3D" }
}
curl https://playticketing.fun/api/v1/me \
  -H "Authorization: Bearer pwmt_your_key"

GET /api/v1/events

Every event for this client, newest first, with ticket types and how many are left.

Response

{
  "events": [
    {
      "id": "…",
      "name": "Rooftop Friday",
      "slug": "rooftop-friday",
      "venue": "The Rooftop",
      "startsAt": "2026-11-01T02:00:00.000Z",
      "summary": "",
      "merchant": "stripe",
      "paused": false,
      "promoUrl": "https://playticketing.fun/go/the-rooftop/rooftop-friday",
      "sold": 2,
      "capacity": 100,
      "grossCents": 5000,
      "ticketTypes": [
        { "id": "…", "name": "General admission", "priceCents": 2500, "qty": 100, "sold": 2, "remaining": 98 }
      ]
    }
  ]
}
curl https://playticketing.fun/api/v1/events \
  -H "Authorization: Bearer pwmt_your_key"

POST /api/v1/events

Create an event and its ticket types. Price is cents, and 0 is a free ticket. One to six types. merchant is stripe or 3thix and defaults to stripe.

Body

{
  "name": "Rooftop Friday",
  "venue": "The Rooftop",
  "summary": "Doors at 8.",
  "startsAt": "2026-11-01T02:00:00.000Z",
  "merchant": "stripe",
  "ticketTypes": [
    { "name": "General admission", "priceCents": 2500, "qty": 100 }
  ]
}

Response

{ "event": { "id": "…", "name": "Rooftop Friday", "slug": "rooftop-friday" } }
curl -X POST https://playticketing.fun/api/v1/events \
  -H "Authorization: Bearer pwmt_your_key" \
  -H "Content-Type: application/json" \
  -d '{ "name": "Rooftop Friday", "venue": "The Rooftop", "summary": "Doors at 8.", "startsAt": "2026-11-01T02:00:00.000Z", "merchant": "stripe", "ticketTypes": [ { "name": "General admission", "priceCents": 2500, "qty": 100 } ] }'

GET /api/v1/events/{id}

One event. A missing event, or another client’s event, is a 404.

Response

{ "event": { "id": "…", "name": "Rooftop Friday", "ticketTypes": [] } }
curl https://playticketing.fun/api/v1/events/EVENT_ID \
  -H "Authorization: Bearer pwmt_your_key"

GET /api/v1/events/{id}/orders

Orders for one event, newest first. limit is 1 to 100 and defaults to 50. status is paid, pending, expired, or failed.

Response

{
  "orders": [
    {
      "id": "…",
      "eventId": "…",
      "email": "fan@example.com",
      "method": "apple",
      "detail": "Apple Pay",
      "status": "paid",
      "totalCents": 5000,
      "createdAt": "2026-10-09T22:00:00.000Z",
      "tickets": [
        { "code": "PWMT-LZF4ESNW", "name": "General admission", "usedAt": null }
      ]
    }
  ]
}
curl https://playticketing.fun/api/v1/events/EVENT_ID/orders?limit=50 \
  -H "Authorization: Bearer pwmt_your_key"

GET /api/v1/orders/{id}

One order and its tickets.

Response

{ "order": { "id": "…", "status": "paid", "tickets": [] } }
curl https://playticketing.fun/api/v1/orders/EVENT_ID \
  -H "Authorization: Bearer pwmt_your_key"

GET /api/v1/tickets/{code}

Look up a ticket by its code, such as PWMT-LZF4ESNW.

Response

{
  "ticket": {
    "code": "PWMT-LZF4ESNW",
    "name": "General admission",
    "eventId": "…",
    "eventName": "Rooftop Friday",
    "venue": "The Rooftop",
    "startsAt": null,
    "email": "fan@example.com",
    "usedAt": null
  }
}
curl https://playticketing.fun/api/v1/tickets/PWMT-CODE \
  -H "Authorization: Bearer pwmt_your_key"

POST /api/v1/tickets/{code}/admit

Mark the ticket used. A second call returns the same usedAt and alreadyUsed true. It does not admit the guest again.

Response

{
  "alreadyUsed": false,
  "ticket": { "code": "PWMT-LZF4ESNW", "usedAt": "2026-10-09T23:10:00.000Z" }
}
curl -X POST https://playticketing.fun/api/v1/tickets/PWMT-CODE/admit \
  -H "Authorization: Bearer pwmt_your_key"