Message the venue about a booking
/api/book/{slug}/manage/{token}Allowed regardless of the change cutoff and on any status, unlike PATCH and DELETE. "I am running late" and "why was this cancelled" are exactly the moments someone needs to reach a venue; refusing them because the booking is two hours away would be backwards.
A manage link is public to anyone holding it, so there is a flood cap: 20 guest messages per booking, after which the guest is told to contact the venue directly. That is a cheap guard, not real rate limiting; there is none anywhere in this API yet.
Path Parameters
The organization's public booking slug, i.e. the {slug} in /{slug}. Only orgs with status active resolve; anything else is a 404.
The booking's manage token.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/api/book/string/manage/string" \ -H "Content-Type: application/json" \ -d '{ "message": "string" }'{ "ok": true}Release a held table DELETE
The guest closed the sheet or hit back. Releases the table immediately rather than waiting out the hold window. Only ever deletes a row whose status is still `hold`; a confirmed booking is cancelled from the dashboard or the manage link, never dropped by an unauthenticated caller holding an id.
Move a booking to another time PATCH
Guest-initiated reschedule, for both engines. Which engine is in play is resolved from the org's `business_type` inside `loadByToken`, so the caller does not choose; this is the one endpoint that serves both and the only one where that is correct, because a manage link is a link to *a booking*, not to a product. Only the time changes. Same service, same staff member, same party size; that is what keeps a guest reschedule auto-approvable without staff review. The new time must satisfy the org's notice period too, or a guest could sidestep the cutoff by moving to a slot an hour from now. The slot is re-derived server-side and the update is a compare-and-set on the current status, so a booking staff cancelled mid-flow is not resurrected.