The API is scoped to one Business Unit. A key is created inside a Business Unit and can read and write only that unit’s events — not another unit, not another organization. See API keys.
A buyer-facing site with no backend uses the Storefront API: a publishable key in the frontend, the catalog read from the browser, and checkout sessions that hand the buyer to orriven’s hosted pages. This page describes the secret-key, server-to-server surface.
What the API covers
Automations run for API actions the same way they run for console actions. A registration created over the API triggers the “attendee added” automation. An approval triggers the confirmation flow. An arrival check-in triggers the welcome flow.
Base URL and interactive docs
Every endpoint in these pages lives under/v1 on the orriven API host. Examples use $BASE:
GET $BASE/openapi.json returns the OpenAPI 3.1 specification, for generating a client. $BASE/docs serves an interactive reference.
Requests and responses
- Requests and responses are JSON. Send
Content-Type: application/jsonon writes. - Timestamps are ISO 8601 with an offset (
2026-09-01T09:00:00+08:00). - Money is an integer in minor units of the event’s currency (¥120.00 →
12000), tax-inclusive — the same convention as the console. - Every request carries the key:
Authorization: Bearer <secret>. - The API is date-versioned. The key is pinned at creation. Every response echoes the effective version in the
Orriven-Versionheader.
Next
API keys
Generate a key in the console. The secret is shown once.
Quickstart
Event → ticket type → registration → check-in, in seven curl calls.
Endpoint reference
Resources, methods, and status codes.
Ticket types
Console concepts the API mirrors.
Command-line tool
Manage keys, webhooks and logs from a terminal.
Agents
MCP server integration for administrative workflows and programmatic Developer API access.
Storefront API
Event sites without a backend: publishable keys, the catalog in the browser, hosted checkout.