BookedNG
AppearanceDevice
Appearance
BOOKEDNG DEVELOPERS

API reference and access

The current external API surface is intentionally narrow. This page distinguishes supported contracts from BookedNG’s internal application routes.

Last reviewed 30 September 2026

Supported external API

No general partner API is currently offered. BookedNG does not currently issue self-service API keys or OAuth clients for websites to read listings, availability, orders, customers, tickets, payments, refunds or reports.

The supported public integration contract is the canonical listing URL described in Website integration options.

Why public JSON routes are not a partner API

BookedNG’s web application uses unauthenticated JSON routes to render public marketplaces and listings. Those routes are rate limited, but they do not have the published schemas, partner authentication, authorisation model, data-use agreement, versioning guarantee, service commitment or operational onboarding required for an officially supported API. A browser-visible route is not a supported partner API.

Do not build an external integration against /api/v1/public/…, /api/v1/events/…, /api/v1/appointments/… or /api/v1/experiences/… merely because a browser can reach part of that surface. Routes may change with the BookedNG frontend.

Access matrix

Access typeStatusAlternative
Partner API credentialsUnavailableUse public listing links; contact support for a reviewed use case
Sandbox partner accountUnavailableUse an approved isolated BookedNG test environment
Public OpenAPI/Swagger referenceUnavailableThis page is the authoritative external-access statement
Customer or provider dashboard APIsInternal and authenticatedUse the relevant BookedNG dashboard
CSV exportsSupported inside authorised dashboardsDownload manually and protect the file

Requesting a future integration

Send support the business owner, website domain, BookedNG vertical, read/write operations, expected volume, data retention need, security contact and desired launch date. BookedNG must review authentication, least-privilege authorisation, personal-data exposure, rate limits, auditing, operational ownership and deprecation before any new external API is released.