# Get a booking

`GET /api/v1/bookings/{id}`

One booking by id. Requires the "bookings:read" scope.

Scope: `bookings:read`

## Parameters

- `id` (path, string, required) — Awrora id (UUID) for the booking.

## Responses

- `200` — The booking.
- `401` — Missing, invalid, revoked or expired API key — codes "api_key_missing", "api_key_invalid", "api_key_revoked", "api_key_expired".
- `403` — The API app is off, the plan does not include the API, or the key lacks the required scope — codes "app_not_enabled", "plan_upgrade_required", "insufficient_scope" (the last carries "required_scope").
- `404` — No such resource. The same response is returned for a resource that belongs to another organization — code "not_found".
- `429` — Rate limit exceeded — code "rate_limited". See the x-ratelimit-* headers.
- `500` — Something went wrong on our side — code "internal_error".

## Response `200`

- `id` (string, required) — Awrora id (UUID) for the booking.
- `booking_number` (integer | null, required) — Sequential booking number within the organization, or null for legacy rows.
- `status` ("pending" | "confirmed" | "cancelled", required) — pending = created, awaiting payment; confirmed = active; cancelled = cancelled.
- `source` (string | null, required) — Where the booking came from: online, admin, agency, ai or api.
- `created_at` (string, required) — ISO 8601 timestamp with offset.
- `updated_at` (string, required) — ISO 8601 timestamp with offset.
- `experience` (object, required) — The experience that was booked.
- `departure` (object, required) — The departure that was booked.
- `customer` (object, required) — The guest details captured at checkout. Not the customer record — see /v1/customers.
- `guests` (object[], required) — Guest lines. May be empty for legacy rows.
- `add_ons` (object[], required) — Add-on lines. Empty when none were bought.
- `totals` (object, required) — Money totals for the booking.
- `payment` (object, required) — How the booking is paid, and where that payment stands.
- `note` (string | null, required) — Free-text note from the buyer or staff, or null.
- `manage_url` (string | null, required) — Link where the guest can open and finish their own booking. Only returned to keys with the "bookings:write" scope — read-only keys and webhook/event payloads always get null, because anyone holding the link can see the booking and complete it. Also null when no valid link exists (no token, or the token has expired). Treat it as a secret.

## Example

```bash
curl -X GET "https://your-site.awrora.app/api/v1/bookings/id_8f2k3n" \
  -H "Authorization: Bearer $AWRORA_API_KEY"
```