docs
/
EventOxygen

Environment

Which backend, organization and keys the app is built against, and the headers every request carries.

EventOxygen has two environments, selected at build time in lib/config/environment.dart (EnvironmentConfig). A debug build runs against development; kReleaseMode switches to production. There is no runtime switch and no settings screen for it.

The two environments

KeyDevelopmentProduction
appengineEndpointhttp://192.168.1.239:3300https://appengine.appmint.io
appIddemoevventapp
appKey / appSecretset (demo app credentials)set
orgId (also siteName)demoeventos
stripePublishableKeyplaceholderplaceholder

The development endpoint is a LAN address, not localhost, so a phone on the same Wi-Fi reaches the developer's machine. Change it to your own machine's address before running on a device.

Stripe keys in this file are placeholders

The app never uses them. The publishable key is fetched at purchase time from GET /client/events/stripe/config, falling back to the key returned with the payment intent. See payments.

Other constants: request timeouts 30 seconds, three retries, default page size 20 (maximum 100), domainAsOrg = true, app name "Event App" (display name EventOxygen).

App credentials and tokens

Two tokens travel on requests:

TokenObtained bySent as
App tokenPOST /profile/app/key with {appId, secret, key} and the orgid headerAuthorization: Bearer …
Customer tokenPOST /profile/customer/signin (or refresh)x-client-authorization: Bearer … on calls that need a person

The app token identifies the installation; the customer token identifies the attendee. Public routes (browsing events, buying as a guest, reading a post) work with the app token alone. A 401 renews the app token once and retries.

Tokens live in the device's secure storage (access_token, refresh_token); the customer record is cached in preferences (user_data).

Headers on every request

HeaderValue
orgid, shared-org-id, x-client-orgidThe organization from the environment
domainAsOrgtrue
x-client-infoJSON snapshot: platform, OS and version, device type and model, app package, version and build, language, timezone, user agent
x-client-protocol, x-client-timezoneTransport and zone

The client deliberately sends no host, domain or x-client-host header. The server resolves the customer-facing site from siteName, and the links inside booking and ticket emails are built from that. Adding a host header from the app would make those links point at the API host instead of the website.

lib/config/legal_urls.dart: privacy https://eventos.app/privacy, terms https://eventos.app/terms, support [email protected] with the subject "Eventos — Support Request". These appear on the profile screen and in the store listing.

Activity tracking

POST /crm/customer-activity/record receives a page view for the main screens (browse, event detail, my events, tickets, schedule, people, feed, media) and an action record for ticket purchases (importance 5). Each record carries source: app, the customer email once signed in, a stable device id, platform and app version. This is the same customer-activity timeline staff see in the CRM.