Skip to content

Manage links & cancellations

A guest has no password. Their credential is the manage token returned once at confirmation and included in the confirmation message.

https://<slug>.sites.mrcharles.app/r/<manageToken>
Terminal window
curl -s https://api.mrcharles.app/api/v1/public/bookings/manage/1000bb60…47da3a0
{
"success": true,
"data": {
"reference": "MC-TGRMY5",
"status": "confirmed",
"paymentMode": "on_site",
"paymentStatus": "unpaid",
"studioName": "Studio Uno",
"roomName": "Rehearsal B",
"date": "2026-10-08", "startTime": "17:00", "endTime": "19:00",
"timezone": "Europe/Madrid",
"startsAt": "2026-10-08T17:00:00+02:00",
"minutes": 120,
"priceCents": 5000, "depositCents": 0, "currency": "EUR",
"cancelNoticeHours": 24,
"mayCancel": true,
"notes": "Trio, we bring our own cymbals."
}
}

mayCancel already applies the policy: it is false once the booking is inside the cancelNoticeHours window, cancelled or past. Use it to show or hide your button — the server enforces it anyway.

Terminal window
curl -s -X POST https://api.mrcharles.app/api/v1/public/bookings/manage/1000bb60…/cancel \
-H 'Content-Type: application/json' \
-d '{"reason":"Our drummer is ill"}'

Too late → 409 CANCEL_TOO_LATE. The guest should then call the studio; show the phone or WhatsApp from the site payload. Already cancelled → 409 INVALID_STATE.

Refunds of a card deposit are the studio’s decision, made from its dashboard. Cancelling does not refund automatically.

  • Treat it like a password: 32 random bytes, and only its hash is stored. We cannot recover it — if the guest loses it, the studio looks the booking up by reference.
  • Keep it out of your server logs and analytics. If you render a manage page yourself, put the token in the path and set Referrer-Policy: no-referrer so it does not leak to third parties.
  • Do not email it to anyone but the guest.

If you would rather not build this at all, send the guest to manageUrl — the hosted page handles reading, cancelling, the policy and the three languages.