The Awrora API lets an external system read and write the same booking data your staff see in Awrora: experiences, departures with live seat counts, bookings, customers and gift cards. It can create and cancel bookings, and it can push changes to you as webhooks instead of making you poll.
It is a plain JSON REST API over HTTPS. No SDK is required. The API is in beta: the shapes are stable and will not break without a new version, but we are still adding to them.
Base URL#
https://your-site.awrora.app/api/v1Use your own Awrora address — the same host your staff log in on. There is no separate API domain.
Which organisation you are reading comes from the API key, never from the host and never from a parameter. A key issued by one organisation cannot see another's data, and a request for an id that belongs to someone else answers 404, exactly like an id that does not exist.
Who can use it#
The API is included in the paid plans and is managed under SettingsAppsFor developers. Administrators and the owner can see that section; only the owner can create and revoke keys and manage webhooks. Two independent gates apply:
| Gate | Response when closed | Who opens it |
|---|---|---|
| The organisation has no API yet | 403 app_not_enabled | The owner, by creating their first key or webhook |
| The plan does not include the API | 403 plan_upgrade_required | Requires a plan change |
Quick start#
Create a key
In Awrora, open SettingsAppsFor developers and click New API key. Pick the scopes you need. The key is shown once — copy it now.
Call GET /v1/me
GET /v1/me needs no scope and is the auth test:
bash
curl -H "Authorization: Bearer aur_YOUR_KEY" \
https://your-site.awrora.app/api/v1/meCheck the answer
The response names the organisation the key belongs to and what the key may do — see Get me. A 401 means the key is wrong; see Authentication.
Conventions#
- JSON in, JSON out. Send
Content-Type: application/jsonon requests with a body. Every response is JSON except204 No Content. - Timestamps are ISO 8601 with an offset, in the organisation's own timezone (
organization.timezonefrom/v1/me), e.g.2026-09-11T20:00:00+02:00. Date-only parameters areYYYY-MM-DDin that same timezone. - Money is an integer plus a currency:
{ "amount_minor": 120000, "currency": "SEK" }is SEK 1,200.00. Never a float, never a formatted string. - Ids are UUIDs — treat them as opaque strings.
booking_numberis the short human-facing number, unique per organisation only; it is not an id. - Nulls are real. A field that can be absent is
null, not omitted. - Unknown fields are ignored in query strings and bodies. That means a typo in a body field is silent — check the returned resource against what you sent.
Read on
AuthenticationAPI keys, scopes and the 401 codes. | |
ErrorsThe error envelope, every code and what to retry. | |
PaginationCursor-based list endpoints. | |
IdempotencySafe retries with Idempotency-Key. | |
Rate limitsPer-key and per-organisation limits. | |
WebhooksSigned event delivery and retries. | |
VersioningWhat counts as breaking, and the changelog. | |
API referenceEvery endpoint, generated from the OpenAPI document. |