Skip to content

API reference

Authentication

Server requests use a bearer token created in the VenueGo portal. The token is shown once.

Send the key on every request:

Authorization: Bearer vm_live_...

Keys look like vm_live_… or vm_test_…. Both call the same production API. The prefix is there so you can tell a key’s purpose in your own systems. VenueGo stores only a hash. If you lose a key, revoke it and create another.

Create and revoke keys under Developers in the portal. Treat the key like a password: keep it on your server, not in a mobile app, a front-end bundle, or a ticket email.

A missing or revoked key

The response is 401 with this body:

{
  "error": {
    "code": "unauthenticated",
    "message": "This API token is invalid or has been revoked."
  }
}

There is no session cookie on /api/v1. Browser logins are a different surface and cannot call these routes.

Where the key is allowed

  • Your backend, when creating, reading, or cancelling a session.
  • A secret store or environment variable on that server.

Do not send the key from the guest’s phone. The guest uses the url from the create response, which is already scoped to that one session.