Public API
The Eveos public API lets integrations read and manage data permitted by the role assigned to an API key. It is designed for CRMs, no-code tools, Zapier automations, and AI assistants.
Get started
Section titled “Get started”- Create an API key with the required role and project scope.
- Open the interactive reference.
- In the Authentication block, paste the key into the Value field of
X-Api-Key, then run a test request with Test Request.
Available resources
Section titled “Available resources”The API covers projects, sessions, participants, exhibitors, program items, speakers, places, categories, products, promo codes, taxonomies, custom fields, custom modules, check-ins, checkpoints, widgets, media, exhibitor checklists, and non-financial analytics.
Integration practices
Section titled “Integration practices”1. Authenticate every request
Section titled “1. Authenticate every request”Send your API key in the X-Api-Key header. The key determines the organizer,
accessible projects, and permissions available to your integration. Do not send
an organizerId in an attempt to select a different organizer.
GET /api/v1/public/projects HTTP/1.1Host: backend.eveos.comX-Api-Key: evk_live_your_key2. Create without duplicates using Idempotency-Key
Section titled “2. Create without duplicates using Idempotency-Key”Every POST request requires an Idempotency-Key header. Generate a unique,
random value for one create attempt, and keep it when retrying that same
operation after a timeout or network failure.
POST /api/v1/public/sessions/ses_123/participants HTTP/1.1Host: backend.eveos.comX-Api-Key: evk_live_your_keyIdempotency-Key: 9d3c98bb-6afc-4bb0-a7cf-75c8d75b7dc1Content-Type: application/json
{ "person": { "firstName": "Ana", "lastName": "Martin", "email": "ana@example.com" } }For 24 hours, a retry using the same API key and the same
Idempotency-Key creates nothing else. Eveos returns the first response from
storage with Idempotency-Replayed: true. Use a new value for every new create,
including when creating another resource. A missing, empty, or over-200-character
header returns 400.
3. Read an entire list
Section titled “3. Read an entire list”Collection endpoints return items and, when more results exist, a
nextCursor. Send that opaque value unchanged in cursor to get the next
page. Do not decode it or construct offsets yourself.
GET /api/v1/public/sessions/ses_123/participants?limit=100 HTTP/1.1X-Api-Key: evk_live_your_key{ "items": [{ "id": "par_123" }], "nextCursor": "NjM4..."}GET /api/v1/public/sessions/ses_123/participants?limit=100&cursor=NjM4... HTTP/1.1X-Api-Key: evk_live_your_keyNo nextCursor means the list is complete. limit is optional, defaults to
25, and cannot exceed 100.
4. Handle errors reliably
Section titled “4. Handle errors reliably”Functional errors use the standard RFC 7807 application/problem+json format.
Check the HTTP status code, then use title as the machine-readable category
and detail as the actionable message.
{ "status": 403, "title": "forbidden", "detail": "The API key does not have the required permission."}Common cases are 400 (invalid request), 401 (missing or invalid key), 403
(valid key but unauthorized permission or project), 404 (resource not found
within your scope), and 429 (rate limited). Retry gradually after 429 or a
network failure; for a POST, reuse the same Idempotency-Key.
5. Stay compatible with future changes
Section titled “5. Stay compatible with future changes”The /api/v1/public URL stays stable for compatible changes. Eveos may add
fields or resources without changing its version. Your client should read only
the fields it needs and ignore unknown fields; do not use strict deserialization
for properties you do not use.
Zapier and AI agents
Section titled “Zapier and AI agents”Zapier can make HTTP requests with X-Api-Key and receive events configured through webhooks. A custom GPT can import the OpenAPI document directly:
https://backend.eveos.com/openapi/public-v1.jsonFor autonomous agents, restrict each key to the minimum role and project scope. Keep human confirmation for deletes and high-impact configuration changes.

