RSVPSorted

Venue API

Your booking system calls us when a host taps Make your invite, when a booking moves or is cancelled, and, if you like, to say which packages offer invites. Nothing is sent to us before the host taps.

The OpenAPI 3.1 description

The full contract, served without a key and generated from the same schemas the API validates with. Point your client generator at it.

Open the JSON

Overview

When a parent books a party with you, your confirmation page and emails show a Make your invite button. When they tap it, your server calls us with the party details, and we reply with a link to send them to. They land on an invite with the date, time and place already filled in and locked, pick a design and share it. Your team then sees the party’s headcount in the venue dashboard: numbers only, never guests’ names or notes.

  • Data moves only when the host taps, so a booking that never makes invites is never shared with us.
  • The booking email is included so only the person who booked can claim the invite.
  • Calls are idempotent per booking: a repeat handoff for the same reference returns the same link.
  • Any party works, not only a children’s birthday: send the occasion, or set one per package in your venue dashboard.

Authentication

Every call carries your venue’s API key as a bearer token. Create and revoke keys in the venue dashboard; keep them on your server, never in a browser or an email.

Authorization: Bearer YOUR_API_KEY

Each key can make 120 requests a minute. To rotate a key, create a new one, switch your server over to it, then revoke the old one. The base URL ishttps://app.rsvpsorted.com.

Create a handoff

PUT/api/v1/venue/handoffs/:externalRef

Call this when the parent taps the button. externalRef is your booking reference: letters, numbers, dots, dashes and underscores, up to 64 characters. Send a JSON body; unknown fields are rejected.

FieldTypeRequiredWhat it is
occasionone of "kids_birthday", "adult_birthday", "baby_shower", "bridal_shower", "christening", "gender_reveal", "hen_do", "stag_do", "halloween", "christmas", "dinner", "get_together", "memorial"NoWhat the party is. Leave it out for a children’s birthday, or to use the occasion you set for the package in your venue dashboard. One of kids_birthday (Kids' birthday), adult_birthday (Adult birthday), baby_shower (Baby shower), bridal_shower (Bridal shower), christening (Christening), gender_reveal (Gender reveal), hen_do (Hen do), stag_do (Stag do), halloween (Halloween), christmas (Christmas), dinner (Dinner at home), get_together (Any get-together), memorial (Memorial or celebration of life). Only occasions open to hosts are accepted.
childFirstNametext, 1 to 40 charactersYesThe first name of the person the party is for: the child, for a children’s party. It goes on the invite.
childAgewhole number, 0 to 120, or nullNoThe age they’re turning, if you know it. Leave it out or send null if not. Birthdays only.
partyDatedate, YYYY-MM-DDYesThe party date, local to the venue (Europe/London).
startTimetime, HH:MM (24-hour)YesWhen the party starts, local to the venue.
endTimetime, HH:MM (24-hour)YesWhen the party ends, local to the venue.
hostFirstNametext, up to 40 charactersNoThe host’s first name, used to greet them. Optional.
capacitywhole number, 1 to 1000, or nullNoHow many places the booking is for, if you limit it: children for a children’s party, guests for a grown-up one. Guests can’t reply coming for more than this; the host sees it as “booked for up to N” and can lower it. Optional.
roomNametext, 1 to 80 charactersNoThe room or space booked, as you name it, such as “Jungle room”. It is shown to the host and their guests with your address. Optional.
bookingEmailemail addressYesThe email address on the booking. Only someone signed in with this address can save the invite. We keep a one-way hash and a masked hint, never the address itself.
bookingPhonetext, up to 32 charactersNoThe UK mobile number on the booking, in any usual form (07700 900123 or +44 7700 900123). Someone who signs in by text with this number can save the invite, as the booking email can. We keep a keyed hash and a masked hint, never the number. Optional.
bookingTypeobject with "id" and "name"NoThe party package booked: your id for it and its name. You choose in your venue dashboard which packages offer invites; a package you have switched off is refused with not_offered. Optional.
curl -X PUT https://app.rsvpsorted.com/api/v1/venue/handoffs/KB-20417 \
  -H "Authorization: Bearer $RSVP_SORTED_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "childFirstName": "Ava",
    "childAge": 7,
    "partyDate": "2026-10-17",
    "startTime": "14:00",
    "endTime": "16:00",
    "hostFirstName": "Jo",
    "bookingEmail": "jo@example.com"
  }'

A successful call returns 200 with the link to redirect the parent to, usually with a 303 See Other from your own route:

{ "url": "https://app.rsvpsorted.com/start/…" }

Make the call outside any database transaction on your side, and if it fails, show the host a friendly “Invites are having a moment, try again shortly” page. The link opens the host’s draft, so never store it, log it or put it in an email: hand it over with a redirect from a button they pressed.

Moves and cancellations

PATCH/api/v1/venue/bookings/:externalRef

Call this whenever a confirmed booking changes date or time, or is cancelled or expires. It carries no personal data. If the parent has shared the invite, guests see the new details, or that the party is cancelled, the next time they open it.

FieldTypeRequiredWhat it is
partyDatedate, YYYY-MM-DDYesThe booking’s date now, local to the venue.
startTimetime, HH:MM (24-hour)YesThe booking’s start time now.
endTimetime, HH:MM (24-hour)YesThe booking’s end time now.
statusone of "confirmed", "cancelled"YesSend cancelled when the booking is cancelled or expires; confirmed otherwise.
curl -X PATCH https://app.rsvpsorted.com/api/v1/venue/bookings/KB-20417 \
  -H "Authorization: Bearer $RSVP_SORTED_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "partyDate": "2026-10-24", "startTime": "14:00", "endTime": "16:00", "status": "confirmed" }'

It returns { "updated": true }. A 404 means the host never made invites, so there is nothing to update. Send these from a queue and retry with backoff on anything else.

Packages that offer invites

A package is a party product your booking system sells, such as a jungle party or an adult hire. Name it in each handoff’s bookingType and we learn it from there; you then choose in your venue dashboard which packages offer invites, and what each one’s invites start as. Two optional calls keep your system in step.

GET/api/v1/venue/booking-types

Ask before showing the button, and cache the answer for a few minutes. Show the button when the venue-wide switch is on and the booking’s package offers invites, or, for a package we haven’t seen, when new packages are set to offer.

FieldTypeAlways sentWhat it is
offerInvitestrue or falseYesThe venue-wide switch. When false, show the button for no booking, whatever its package.
newBookingTypesone of "offer", "ask"YesWhat happens to a package we haven’t seen yet: offer means its bookings offer invites straight away, ask means they wait until you switch it on.
bookingTypeslist of object with "id" and "name" and "offerInvites"YesEvery package we know, with its id, name and whether its bookings offer invites.

PUT/api/v1/venue/booking-types/:bookingTypeId

Registers or renames a package ahead of any booking, so the venue can decide on it before anyone books. bookingTypeId is your own id for it: letters, numbers, dots, dashes and underscores, up to 64 characters. It never changes whether the package offers invites; that stays with the venue dashboard.

FieldTypeRequiredWhat it is
nametext, 1 to 80 charactersYesThe package’s name, as your staff know it. Sending a new name renames it.
curl https://app.rsvpsorted.com/api/v1/venue/booking-types \
  -H "Authorization: Bearer $RSVP_SORTED_API_KEY"

curl -X PUT https://app.rsvpsorted.com/api/v1/venue/booking-types/jungle-party \
  -H "Authorization: Bearer $RSVP_SORTED_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "name": "Jungle party" }'

Both answer with the package as we now hold it: { "id": "jungle-party", "name": "Jungle party", "offerInvites": true }.

Errors

Errors are RFC 9457 problem details (application/problem+json) with a stable code. Log the code and the status, never the body you sent, which carries personal data.

StatusCodeWhat to do
400invalid_requestThe reference or body doesn’t match the schema. errors lists each field that failed, as a JSON pointer.
401unauthorisedThe API key is missing, wrong or revoked.
403not_offeredInvites are switched off for your venue or for this package. Treat it like any other failure and don’t show the button for that package.
404not_foundBooking updates only: the host never made invites for this booking. Safe to ignore.
405method_not_allowedThe path exists but not with that method; the Allow header says which.
429rate_limitedMore than 120 requests in a minute with one key. Wait a minute and retry.
500internal_errorSomething went wrong on our side. Retry with backoff, and tell us if it keeps happening.
503unavailableHandoffs are paused on our side. Show the host a friendly message and let them try again shortly.

Where to show the link

  • On your booking confirmation page, next to Add to my calendar, for confirmed and paid bookings only.
  • In the booking confirmation and payment emails, as a link to a page on your site with one button. Mail scanners and link previews open links before anyone clicks, so the handoff itself must only ever happen from a button someone pressed, never from the email link.
  • Wherever hosts look up their booking.

Suggested wording: “Make invites for Ava’s party in a minute, free with your booking.” The button itself says Make your invite.

Security and data

  • We store the child’s first name and age, the party date and times, and the parent’s first name. For the booking email we store a one-way hash and a masked hint only.
  • Booking updates carry no personal data.
  • Invites, replies and everything attached to them are deleted 90 days after the party.
  • Your dashboard shows each party’s numbers: children coming, grown-ups staying and who is still to reply. Never guests’ names, notes or contact details.
  • We act as a separate controller for the host’s and guests’ data. Add a line to your privacy notice saying that if a parent chooses to make invitations, you share their child’s first name, age, party details and email address with RSVP Sorted.

Questions about connecting? Email hello@rsvpsorted.com.