Manage links & cancellations
A guest has no password. Their credential is the manage token returned once at confirmation and included in the confirmation message.
https://<slug>.sites.mrcharles.app/r/<manageToken>Read a booking
Section titled “Read a booking”curl -s https://api.mrcharles.app/api/v1/public/bookings/manage/1000bb60…47da3a0{ "success": true, "data": { "reference": "MC-TGRMY5", "status": "confirmed", "paymentMode": "on_site", "paymentStatus": "unpaid", "studioName": "Studio Uno", "roomName": "Rehearsal B", "date": "2026-10-08", "startTime": "17:00", "endTime": "19:00", "timezone": "Europe/Madrid", "startsAt": "2026-10-08T17:00:00+02:00", "minutes": 120, "priceCents": 5000, "depositCents": 0, "currency": "EUR", "cancelNoticeHours": 24, "mayCancel": true, "notes": "Trio, we bring our own cymbals." }}mayCancel already applies the policy: it is false once the booking is inside the cancelNoticeHours window, cancelled or past. Use it to show or hide your button — the server enforces it anyway.
Cancel
Section titled “Cancel”curl -s -X POST https://api.mrcharles.app/api/v1/public/bookings/manage/1000bb60…/cancel \ -H 'Content-Type: application/json' \ -d '{"reason":"Our drummer is ill"}'Too late → 409 CANCEL_TOO_LATE. The guest should then call the studio; show the phone or WhatsApp from the site payload. Already cancelled → 409 INVALID_STATE.
Refunds of a card deposit are the studio’s decision, made from its dashboard. Cancelling does not refund automatically.
Handling the token
Section titled “Handling the token”- Treat it like a password: 32 random bytes, and only its hash is stored. We cannot recover it — if the guest loses it, the studio looks the booking up by reference.
- Keep it out of your server logs and analytics. If you render a manage page yourself, put the token in the path and set
Referrer-Policy: no-referrerso it does not leak to third parties. - Do not email it to anyone but the guest.
Not your job
Section titled “Not your job”If you would rather not build this at all, send the guest to manageUrl — the hosted page handles reading, cancelling, the policy and the three languages.