Move a booking to another time
/api/book/{slug}/manage/{token}Guest-initiated reschedule, for both engines. Which engine is in play is resolved from the org's business_type inside loadByToken, so the caller does not choose; this is the one endpoint that serves both and the only one where that is correct, because a manage link is a link to a booking, not to a product.
Only the time changes. Same service, same staff member, same party size; that is what keeps a guest reschedule auto-approvable without staff review.
The new time must satisfy the org's notice period too, or a guest could sidestep the cutoff by moving to a slot an hour from now. The slot is re-derived server-side and the update is a compare-and-set on the current status, so a booking staff cancelled mid-flow is not resurrected.
Path Parameters
The organization's public booking slug, i.e. the {slug} in /{slug}. Only orgs with status active resolve; anything else is a 404.
The booking's manage_token (a uuid) from its confirmation email. This IS the credential; there is no session. A non-uuid string is rejected before it reaches Postgres and reads as "link not valid".
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://example.com/api/book/string/manage/string" \ -H "Content-Type: application/json" \ -d '{ "startsAt": "2019-08-24T14:15:22Z" }'{ "booking": { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "starts_at": "2019-08-24T14:15:22Z", "ends_at": "2019-08-24T14:15:22Z" }}Message the venue about a booking POST
Allowed regardless of the change cutoff and on any status, unlike PATCH and DELETE. "I am running late" and "why was this cancelled" are exactly the moments someone needs to reach a venue; refusing them because the booking is two hours away would be backwards. A manage link is public to anyone holding it, so there is a flood cap: 20 guest messages per booking, after which the guest is told to contact the venue directly. That is a cheap guard, not real rate limiting; there is none anywhere in this API yet.
Cancel a booking DELETE
Sets status to `cancelled` rather than deleting, so the venue keeps the history and the slot or table is released by exactly the rules a staff cancellation uses. Compare-and-set on the current status.