Studio back office
Everything so far was public. The endpoints on this page act as a studio member and need a signed-in session.
Authentication
Section titled “Authentication”Sign in with the studio owner’s credentials and send the access token as a bearer:
TOKEN=$(curl -s -X POST https://api.mrcharles.app/api/v1/auth/login \ -H 'Content-Type: application/json' \ -d '{"email":"owner@studiouno.es","password":"…"}' | jq -r .data.accessToken)
curl -s https://api.mrcharles.app/api/v1/studios/$STUDIO_ID/site/bookings \ -H "Authorization: Bearer $TOKEN"- Bearer tokens are exempt from CSRF; cookies are not needed.
- Access tokens are short-lived — refresh them rather than storing credentials.
- Call these from your server. Browser CORS only allows our own apps.
| Action | owner | manager | staff |
|---|---|---|---|
| Read bookings | ✅ | ✅ | ✅ |
| Mark paid / no-show / complete / cancel / note | ✅ | ✅ | ✅ |
| Edit the website, domain, room policy | ✅ | ✅ | — |
| Publish / unpublish | ✅ | ✅ | — |
Typical automations
Section titled “Typical automations”Today’s bookings into your own dashboard
curl -s "https://api.mrcharles.app/api/v1/studios/$STUDIO_ID/site/bookings?from=2026-10-08&to=2026-10-08" \ -H "Authorization: Bearer $TOKEN"Each item carries the guest’s name, phone/email, times, price, payment state and the studio’s own notes.
Mark a booking paid when your till closes
curl -s -X POST ".../site/bookings/$BOOKING_ID/mark_paid" \ -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \ -d '{"note":"Cash, closing shift"}'Actions: mark_paid, mark_refunded, no_show, complete, cancel, note. Every one is recorded in the booking’s event trail with the member who did it.
Open or close online booking for a room
curl -s -X PUT ".../rooms/$ROOM_ID/booking-settings" \ -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \ -d '{"onlineEnabled":true,"minMinutes":60,"maxMinutes":240,"stepMinutes":30, "paymentModes":["card","on_site"],"depositPercent":30,"cancelNoticeHours":24, "instructions":{"es":"Llama al timbre 2."},"photos":[]}'The response includes blockers — the reasons a room still is not bookable (no price, no hours, inactive, studio unverified).
Full list in the studio endpoints reference.
What there is no API for yet
Section titled “What there is no API for yet”Creating studios and rooms, uploading media, and the lessons / bands / venues side of Mr Charles are not exposed publicly yet. If you need them, tell us what for — that is how this list shrinks.