Skip to content

Public API

The Eveos public API lets integrations read and manage data permitted by the role assigned to an API key. It is designed for CRMs, no-code tools, Zapier automations, and AI assistants.

  1. Create an API key with the required role and project scope.
  2. Open the interactive reference.
  3. In the Authentication block, paste the key into the Value field of X-Api-Key, then run a test request with Test Request.

The API covers projects, sessions, participants, exhibitors, program items, speakers, places, categories, products, promo codes, taxonomies, custom fields, custom modules, check-ins, checkpoints, widgets, media, exhibitor checklists, and non-financial analytics.

Send your API key in the X-Api-Key header. The key determines the organizer, accessible projects, and permissions available to your integration. Do not send an organizerId in an attempt to select a different organizer.

GET /api/v1/public/projects HTTP/1.1
Host: backend.eveos.com
X-Api-Key: evk_live_your_key

2. Create without duplicates using Idempotency-Key

Section titled “2. Create without duplicates using Idempotency-Key”

Every POST request requires an Idempotency-Key header. Generate a unique, random value for one create attempt, and keep it when retrying that same operation after a timeout or network failure.

POST /api/v1/public/sessions/ses_123/participants HTTP/1.1
Host: backend.eveos.com
X-Api-Key: evk_live_your_key
Idempotency-Key: 9d3c98bb-6afc-4bb0-a7cf-75c8d75b7dc1
Content-Type: application/json
{ "person": { "firstName": "Ana", "lastName": "Martin", "email": "ana@example.com" } }

For 24 hours, a retry using the same API key and the same Idempotency-Key creates nothing else. Eveos returns the first response from storage with Idempotency-Replayed: true. Use a new value for every new create, including when creating another resource. A missing, empty, or over-200-character header returns 400.

Collection endpoints return items and, when more results exist, a nextCursor. Send that opaque value unchanged in cursor to get the next page. Do not decode it or construct offsets yourself.

GET /api/v1/public/sessions/ses_123/participants?limit=100 HTTP/1.1
X-Api-Key: evk_live_your_key
{
"items": [{ "id": "par_123" }],
"nextCursor": "NjM4..."
}
GET /api/v1/public/sessions/ses_123/participants?limit=100&cursor=NjM4... HTTP/1.1
X-Api-Key: evk_live_your_key

No nextCursor means the list is complete. limit is optional, defaults to 25, and cannot exceed 100.

Functional errors use the standard RFC 7807 application/problem+json format. Check the HTTP status code, then use title as the machine-readable category and detail as the actionable message.

{
"status": 403,
"title": "forbidden",
"detail": "The API key does not have the required permission."
}

Common cases are 400 (invalid request), 401 (missing or invalid key), 403 (valid key but unauthorized permission or project), 404 (resource not found within your scope), and 429 (rate limited). Retry gradually after 429 or a network failure; for a POST, reuse the same Idempotency-Key.

The /api/v1/public URL stays stable for compatible changes. Eveos may add fields or resources without changing its version. Your client should read only the fields it needs and ignore unknown fields; do not use strict deserialization for properties you do not use.

Zapier can make HTTP requests with X-Api-Key and receive events configured through webhooks. A custom GPT can import the OpenAPI document directly:

https://backend.eveos.com/openapi/public-v1.json

For autonomous agents, restrict each key to the minimum role and project scope. Keep human confirmation for deletes and high-impact configuration changes.