Booking Service API Changes - v1.74.0
Release Date: 2026-10-07
Authentication and version support
These private v2 endpoints use X-API-Key: {organizationToken} from your backend. Tenant integrations send X-API-Key: {tenantToken} with X-Organization-ID: {orgId}. Tokens are opaque and supplied through your configured secret store; keep them out of the browser. Confirm the installed backend version and feature settings before using the new endpoints.
Event series (SEAT-1245)
An active series groups events that share a published template. Creation copies the template’s prices, seat assignments, and assignment properties. The series retains its schema, and a member event’s start cannot be edited through ordinary event updates, including in the editor. Its name, description, and end date remain editable.
All paths below are relative to /api/private/v2.0/.
| Method | Path | Contract |
|---|---|---|
POST |
series/ |
Creates a series; returns 201. |
GET |
series/ |
Lists series with pagination and optional status. |
GET |
series/{id} |
Reads a series. |
PUT |
series/{id} |
Updates name, time zone, status, or a published template from the same schema. |
DELETE |
series/{id} |
Archives the series; existing events are retained. |
POST |
series/{id}/events/ |
Creates a published event; 201 for a new start and 200 when that start already exists. |
GET |
series/{id}/events/ |
Lists member events, earliest start first. |
GET |
series/{id}/assignments/ |
Lists booked seats across the series, with optional reference filtering. |
The series body requires name, templateEventId, and an IANA timeZone. status can be ACTIVE or PAUSED; archive with DELETE.
{
"name": "Season",
"templateEventId": "11111111-1111-4111-8111-111111111111",
"timeZone": "Europe/Paris",
"status": "ACTIVE"
}
To create a member event, send start and end as local date-times in the series time zone; both are required and end must follow start. name is optional. The request field is end, while ordinary event models use endDate.
{
"start": "2026-11-15T21:00:00",
"end": "2026-11-15T23:00:00",
"name": "Opening match"
}
An archived or paused series refuses event creation with 409 SERIES_NOT_BOOKABLE. Public booking for a series event closes at its start in the series time zone. Organization-side booking operations and confirmation of an existing session remain available after start.
Confirmed booking references and properties
POST /api/private/v2.0/session/{id}/confirm accepts an optional reference of at most 255 characters and optional properties, containing any JSON up to 16 KB serialized.
{
"reference": "ACC-2026-0042",
"properties": { "admissionClass": "season" }
}
A non-null reference is unique among confirmed sessions of the same event. Reusing it for another confirmation returns 409 REFERENCE_TAKEN. References can be reused on different events. Retrying confirmation of an already confirmed session is idempotent; it does not replace that session’s reference or properties.
PUT /api/private/v2.0/session/{id}/properties replaces the properties of a confirmed session. Send the JSON value itself as the request body, rather than wrapping it in a properties object. Properties are private and omitted from public session responses.
POST /api/private/v2.0/session/{id}/release releases a confirmed session’s numbered seats and general-admission capacity, changes its state to CANCELLED, and frees its reference for reuse. Releasing an already cancelled session is idempotent. Do not expect a RELEASED state.
The private session list and event assignments accept an optional reference filter, as does the series assignments endpoint. Booked-seat responses include a booking object with sessionId, reference, and session properties; available seats omit it. Session properties and the seat assignment’s own properties are distinct fields. V2 price assignments also preserve their supplied properties.
Event end date (SEAT-1251)
Booking API v1 accepts endDate while retaining killAfter for legacy readers and writers. If both are present, endDate wins regardless of JSON field order. V2 already uses endDate. The editor now exposes the End date field; setting it records a date and does not automatically archive the event.
Upgrade editor-service and let it complete V121–V127 before starting this booking-service version.
Direct sale and orphan seat prevention (SEAT-1398)
POST /api/private/v2.0/booking/directsale records a sale that is already final in your system, so orphan seat prevention does not apply to it: the sale goes through even when it leaves a single unsold seat between taken ones. Its only 422 response is EVENT_NOT_PUBLISHED. It validates cartSeatIds when sent and does not use it.
lock and sale keep orphan seat prevention and answer 422 ORPHAN_SEATS_REFUSED with the refused seats, as before.
Organization administrator accounts (SEAT-1428)
POST /api/private/management/v2.0/organizations/, sent with X-API-Key: {tenantToken}, makes the account with the supplied email the new organization’s administrator. Email matching ignores letter case. When no account uses the email, one is created with the supplied password.
An existing account is reused only when it is the only account that matches, belongs to at least one organization, every organization it belongs to is owned by your tenant, and it holds neither the super-admin nor the global-admin role. A reused account keeps its own password; the supplied password is not applied. Any other existing account gets 409 Conflict with errorCode ACCOUNT_EMAIL_IN_USE, and nothing is created: provision that organization with a different email. An organization name that is already in use also answers 409.
Autologin (SEAT-1427)
POST /api/public/v2.0/autologin/ accepts organization accounts only. An account with the super-admin or global-admin role gets HTTP 403 and must sign in to the Editor with its own password. An integration that autologins as such an account needs a regular organization account instead.