EventOxygen has two environments, selected at build time in lib/config/environment.dart (EnvironmentConfig). A debug build runs against development; kReleaseMode switches to production. There is no runtime switch and no settings screen for it.
The two environments
| Key | Development | Production |
|---|---|---|
appengineEndpoint | http://192.168.1.239:3300 | https://appengine.appmint.io |
appId | demo | evventapp |
appKey / appSecret | set (demo app credentials) | set |
orgId (also siteName) | demo | eventos |
stripePublishableKey | placeholder | placeholder |
The development endpoint is a LAN address, not localhost, so a phone on the same Wi-Fi reaches the developer's machine. Change it to your own machine's address before running on a device.
The app never uses them. The publishable key is fetched at purchase time from GET /client/events/stripe/config, falling back to the key returned with the payment intent. See payments.
Other constants: request timeouts 30 seconds, three retries, default page size 20 (maximum 100), domainAsOrg = true, app name "Event App" (display name EventOxygen).
App credentials and tokens
Two tokens travel on requests:
| Token | Obtained by | Sent as |
|---|---|---|
| App token | POST /profile/app/key with {appId, secret, key} and the orgid header | Authorization: Bearer … |
| Customer token | POST /profile/customer/signin (or refresh) | x-client-authorization: Bearer … on calls that need a person |
The app token identifies the installation; the customer token identifies the attendee. Public routes (browsing events, buying as a guest, reading a post) work with the app token alone. A 401 renews the app token once and retries.
Tokens live in the device's secure storage (access_token, refresh_token); the customer record is cached in preferences (user_data).
Headers on every request
| Header | Value |
|---|---|
orgid, shared-org-id, x-client-orgid | The organization from the environment |
domainAsOrg | true |
x-client-info | JSON snapshot: platform, OS and version, device type and model, app package, version and build, language, timezone, user agent |
x-client-protocol, x-client-timezone | Transport and zone |
The client deliberately sends no host, domain or x-client-host header. The server resolves the customer-facing site from siteName, and the links inside booking and ticket emails are built from that. Adding a host header from the app would make those links point at the API host instead of the website.
Legal and support
lib/config/legal_urls.dart: privacy https://eventos.app/privacy, terms https://eventos.app/terms, support [email protected] with the subject "Eventos — Support Request". These appear on the profile screen and in the store listing.
Activity tracking
POST /crm/customer-activity/record receives a page view for the main screens (browse, event detail, my events, tickets, schedule, people, feed, media) and an action record for ticket purchases (importance 5). Each record carries source: app, the customer email once signed in, a stable device id, platform and app version. This is the same customer-activity timeline staff see in the CRM.