Create a booking

POST/api/v1/bookings
Scope: bookings:writeIdempotency-Key required

Books seats on a departure, exactly as a manual booking made in Awrora does: the same capacity check (including seats held in someone else's checkout), the same customer record, the same timeline entry and the same confirmation email. The booking is recorded with source "api". Prices come from the experience's price tiers — the body carries counts, never amounts. Requires the "bookings:write" scope and an "Idempotency-Key" header.

Headers#

FieldTypeDescription
Idempotency-Keyrequired
string≥ 8 chars · ≤ 200 chars

A unique key for this request, 8-200 characters (a UUID is a good choice). Retrying with the same key replays the first response verbatim — same status, same body, plus "Idempotent-Replayed: true" — instead of acting twice. Reusing a key with a different body answers 422.

Request body#

FieldTypeDescription
experience_date_idrequired
stringuuid

The departure to book, from GET /v1/availability. A departure that belongs to another organization answers 404, exactly like one that does not exist.

guestsrequired
object[]

At least one guest line. Several lines may use different price tiers.

add_ons
object[]

Optional add-ons. Requires the "Add-ons" app to be enabled for the organization.

customerrequired
object

Who the booking is for.

note
string≤ 2000 chars

Free-text note stored on the booking and shown to staff.

paymentrequired
string

How the booking is paid. "pay_on_site": confirmed, the guest pays the operator on arrival (the platform on-site fee is accrued, exactly as for a checkout booking). "invoice": confirmed and flagged for invoicing by staff. "external_paid": confirmed and already paid somewhere else — no card is charged and no invoice is created. There is no card option: this API never takes payment.

"pay_on_site""invoice""external_paid"
send_confirmation_email
booleandefault true

Send the organization's booking confirmation email to the guest. Set false when your own system already told them.

notify_staff
booleandefault true

Send the organization's internal "new booking" notification email to its staff, the same one a checkout booking triggers. Honors the organization's own notification settings: if they have switched that notification off, nothing is sent either way. Set false when your integration already tells staff itself.

Example request#

bash

curl -X POST "https://your-site.awrora.app/api/v1/bookings" \
  -H "Authorization: Bearer $AWRORA_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "experience_date_id": "3f6c1f0e-8a2b-4f4e-9d7a-2b1c5e0a9f11",
  "guests": [
    {
      "tier_id": "tier_8f2k3n",
      "count": 1
    }
  ],
  "add_ons": [
    {
      "id": "3f6c1f0e-8a2b-4f4e-9d7a-2b1c5e0a9f11",
      "count": 1
    }
  ],
  "customer": {
    "name": "string",
    "email": "anna@example.com",
    "phone": "string"
  },
  "note": "string",
  "payment": "pay_on_site",
  "send_confirmation_email": true,
  "notify_staff": true
}'

Responses#

  • 200The booking that was created — the same shape GET /v1/bookings/{id} returns. Returned when nothing new was created — the resource already existed, or this is a replay of an earlier request with the same Idempotency-Key.
  • 201The booking that was created — the same shape GET /v1/bookings/{id} returns.
  • 400Invalid request — codes "validation_failed" or, on an endpoint that requires one, "idempotency_key_required".
  • 401Missing, invalid, revoked or expired API key — codes "api_key_missing", "api_key_invalid", "api_key_revoked", "api_key_expired".
  • 403The API app is off, the plan does not include the API, or the key lacks the required scope — codes "app_not_enabled", "plan_upgrade_required", "insufficient_scope" (the last carries "required_scope").
  • 404No such resource. The same response is returned for a resource that belongs to another organization — code "not_found".
  • 409The request conflicts with the current state — codes "insufficient_capacity" (carries "seats_available"), "conflict", or "idempotency_in_progress" when another request with the same Idempotency-Key is still running.
  • 422The request was understood but cannot be fulfilled as asked — codes "validation_failed" or "idempotency_key_reused" (the same Idempotency-Key was already used with a different body).
  • 429Rate limit exceeded — code "rate_limited". See the x-ratelimit-* headers.
  • 500Something went wrong on our side — code "internal_error".

Response 200

FieldTypeDescription
idrequired
string

Awrora id (UUID) for the booking.

booking_numberrequired
integer | null

Sequential booking number within the organization, or null for legacy rows.

statusrequired
string

pending = created, awaiting payment; confirmed = active; cancelled = cancelled.

"pending""confirmed""cancelled"
sourcerequired
string | null

Where the booking came from: online, admin, agency, ai or api.

created_atrequired
string

ISO 8601 timestamp with offset.

updated_atrequired
string

ISO 8601 timestamp with offset.

experiencerequired
object

The experience that was booked.

departurerequired
object

The departure that was booked.

customerrequired
object

The guest details captured at checkout. Not the customer record — see /v1/customers.

guestsrequired
object[]

Guest lines. May be empty for legacy rows.

add_onsrequired
object[]

Add-on lines. Empty when none were bought.

totalsrequired
object

Money totals for the booking.

paymentrequired
object

How the booking is paid, and where that payment stands.

noterequired
string | null

Free-text note from the buyer or staff, or null.

manage_urlrequired
string | null

Link where the guest can open and finish their own booking. Only returned to keys with the "bookings:write" scope — read-only keys and webhook/event payloads always get null, because anyone holding the link can see the booking and complete it. Also null when no valid link exists (no token, or the token has expired). Treat it as a secret.

200 response

{
  "id": "res_8f2k3n",
  "booking_number": -9007199254740991,
  "status": "pending",
  "source": "string",
  "created_at": "string",
  "updated_at": "string",
  "experience": {
    "id": "res_8f2k3n",
    "title": "string",
    "slug": "string"
  },
  "departure": {
    "id": "res_8f2k3n",
    "starts_at": "string",
    "ends_at": "string"
  },
  "customer": {
    "name": "string",
    "email": "anna@example.com",
    "phone": "string"
  },
  "guests": [
    {
      "tier_id": "tier_8f2k3n",
      "tier_label": "string",
      "count": -9007199254740991,
      "unit_price": {
        "amount_minor": -9007199254740991,
        "currency": "SEK"
      }
    }
  ],
  "add_ons": [
    {
      "id": "res_8f2k3n",
      "label": "string",
      "count": -9007199254740991,
      "unit_price": {
        "amount_minor": -9007199254740991,
        "currency": "SEK"
      }
    }
  ],
  "totals": {
    "subtotal": {
      "amount_minor": -9007199254740991,
      "currency": "SEK"
    },
    "discount": {
      "amount_minor": -9007199254740991,
      "currency": "SEK"
    },
    "gift_card": {
      "amount_minor": -9007199254740991,
      "currency": "SEK"
    },
    "total": {
      "amount_minor": -9007199254740991,
      "currency": "SEK"
    }
  },
  "payment": {
    "method": "string",
    "source": "stripe",
    "status": "paid"
  },
  "note": "string",
  "manage_url": "https://example.com/webhooks/awrora"
}