A key for one client
Each key belongs to one client. It can read that client’s events, orders, and tickets, create an event, and mark a ticket used. It cannot see another client, and it cannot charge a card. Sign in as the client (or a partner selling on its own), open API keys, and create a key. The full key is shown once. Store it like a password. Revoking a key makes it stop working immediately.
https://playticketing.fun
Call it
Send the key on every call except the index and this OpenAPI file.
curl https://playticketing.fun/api/v1/me \
-H "Authorization: Bearer pwmt_your_key"
A bad or revoked key returns 401. A missing event, order, or ticket returns 404, including one that belongs to someone else. A bad body returns 400. Every error looks like this.
{ "error": "That API key is not valid." }Money is cents. Times are ISO-8601 in UTC. status on an order is paid, pending, expired, or failed. A price of 0 is a free ticket. usedAt is null until the guest is admitted.
GET /api/v1/me
Who this key belongs to.
Response
{
"client": { "id": "…", "name": "The Rooftop", "slug": "the-rooftop" },
"key": { "name": "Door app", "prefix": "pwmt_a1B2c3D" }
}curl https://playticketing.fun/api/v1/me \
-H "Authorization: Bearer pwmt_your_key"
GET /api/v1/events
Every event for this client, newest first, with ticket types and how many are left.
Response
{
"events": [
{
"id": "…",
"name": "Rooftop Friday",
"slug": "rooftop-friday",
"venue": "The Rooftop",
"startsAt": "2026-11-01T02:00:00.000Z",
"summary": "",
"merchant": "stripe",
"paused": false,
"promoUrl": "https://playticketing.fun/go/the-rooftop/rooftop-friday",
"sold": 2,
"capacity": 100,
"grossCents": 5000,
"ticketTypes": [
{ "id": "…", "name": "General admission", "priceCents": 2500, "qty": 100, "sold": 2, "remaining": 98 }
]
}
]
}curl https://playticketing.fun/api/v1/events \
-H "Authorization: Bearer pwmt_your_key"
POST /api/v1/events
Create an event and its ticket types. Price is cents, and 0 is a free ticket. One to six types. merchant is stripe or 3thix and defaults to stripe.
Body
{
"name": "Rooftop Friday",
"venue": "The Rooftop",
"summary": "Doors at 8.",
"startsAt": "2026-11-01T02:00:00.000Z",
"merchant": "stripe",
"ticketTypes": [
{ "name": "General admission", "priceCents": 2500, "qty": 100 }
]
}Response
{ "event": { "id": "…", "name": "Rooftop Friday", "slug": "rooftop-friday" } }curl -X POST https://playticketing.fun/api/v1/events \
-H "Authorization: Bearer pwmt_your_key" \
-H "Content-Type: application/json" \
-d '{ "name": "Rooftop Friday", "venue": "The Rooftop", "summary": "Doors at 8.", "startsAt": "2026-11-01T02:00:00.000Z", "merchant": "stripe", "ticketTypes": [ { "name": "General admission", "priceCents": 2500, "qty": 100 } ] }'GET /api/v1/events/{id}
One event. A missing event, or another client’s event, is a 404.
Response
{ "event": { "id": "…", "name": "Rooftop Friday", "ticketTypes": [] } }curl https://playticketing.fun/api/v1/events/EVENT_ID \
-H "Authorization: Bearer pwmt_your_key"
GET /api/v1/events/{id}/orders
Orders for one event, newest first. limit is 1 to 100 and defaults to 50. status is paid, pending, expired, or failed.
Response
{
"orders": [
{
"id": "…",
"eventId": "…",
"email": "fan@example.com",
"method": "apple",
"detail": "Apple Pay",
"status": "paid",
"totalCents": 5000,
"createdAt": "2026-10-09T22:00:00.000Z",
"tickets": [
{ "code": "PWMT-LZF4ESNW", "name": "General admission", "usedAt": null }
]
}
]
}curl https://playticketing.fun/api/v1/events/EVENT_ID/orders?limit=50 \
-H "Authorization: Bearer pwmt_your_key"
GET /api/v1/orders/{id}
One order and its tickets.
Response
{ "order": { "id": "…", "status": "paid", "tickets": [] } }curl https://playticketing.fun/api/v1/orders/EVENT_ID \
-H "Authorization: Bearer pwmt_your_key"
GET /api/v1/tickets/{code}
Look up a ticket by its code, such as PWMT-LZF4ESNW.
Response
{
"ticket": {
"code": "PWMT-LZF4ESNW",
"name": "General admission",
"eventId": "…",
"eventName": "Rooftop Friday",
"venue": "The Rooftop",
"startsAt": null,
"email": "fan@example.com",
"usedAt": null
}
}curl https://playticketing.fun/api/v1/tickets/PWMT-CODE \
-H "Authorization: Bearer pwmt_your_key"
POST /api/v1/tickets/{code}/admit
Mark the ticket used. A second call returns the same usedAt and alreadyUsed true. It does not admit the guest again.
Response
{
"alreadyUsed": false,
"ticket": { "code": "PWMT-LZF4ESNW", "usedAt": "2026-10-09T23:10:00.000Z" }
}curl -X POST https://playticketing.fun/api/v1/tickets/PWMT-CODE/admit \
-H "Authorization: Bearer pwmt_your_key"