Manage a booking
GET /public/bookings/manage/{token}
Section titled “GET /public/bookings/manage/{token}”curl -s https://api.mrcharles.app/api/v1/public/bookings/manage/1000bb60…Returns the booking summary — same shape as booking in the confirm response. Cache-Control: no-store.
| Field | Why it matters |
|---|---|
mayCancel | true only while the booking is cancellable right now |
cancelNoticeHours | The policy snapshot taken when the booking was made |
status, paymentStatus | Poll these after a card payment until confirmed |
| Status | Code | Cause |
|---|---|---|
| 404 | RESOURCE_NOT_FOUND | Unknown or mistyped token |
POST /public/bookings/manage/{token}/cancel
Section titled “POST /public/bookings/manage/{token}/cancel”{ "reason": "Our drummer is ill" }reason is optional and reaches the studio. Returns the updated booking with "status": "cancelled".
| Status | Code | Cause |
|---|---|---|
| 409 | CANCEL_TOO_LATE | Inside the notice window — the guest must call the studio |
| 409 | INVALID_STATE | Already cancelled, completed or past |
Cancelling frees the slot immediately. A paid deposit is not refunded automatically; that is the studio’s call from its dashboard.
Token handling
Section titled “Token handling”- 32 random bytes, hex-encoded. Only a hash is stored — it cannot be looked up or recovered.
- Equivalent to a password for that one booking. Keep it out of logs, analytics and
Refererheaders. - Rate limited: 120 reads/min and 15 writes/min per IP.