docs
/
EventOxygen

Organization settings

The organization and site the app belongs to, what is public without a token, rate limiting and the server variables behind events and community.

The attendee app is bound to one organization at build time. Everything else about how it behaves — which events exist, who may enter where, which emails go out — is data in that organization.

Organization and site

The app's orgId doubles as siteName. The server uses the site to work out the customer-facing web host, and builds the links in ticket and booking emails from it. That is why the app sends no host header of its own: the website is the canonical home for those links, not the API.

Production is organization eventos; development uses demo, the shared sandbox organization, which is why demo data (events, participants, posts) from other products shows up there.

Event-level settings

Most behaviour is per event, not per organization. settings on the event record covers networking, leads, check-in requirement, QR rotation and its interval, walk-ins, approval and per-session caps. See event setup.

Notification settings

Base-setting keys read by the events, reservations and storefront modules:

KeyPurpose
notificationCopyToCopy recipients per module; the reservation copy defaults to the organization email unless set to false
systemEmailFrom-address for platform email
systemPhone, systemSmsPhoneSending numbers for SMS

Templates themselves are edited in Studio Manager. See notifications.

What needs no token

These routes are marked public on the server and work with the app token alone. Everything else requires a signed-in customer.

GET/client/eventsNo auth
GET/client/events/:eventIdNo auth
GET/client/events/:eventId/ticket-typesNo auth
GET/client/events/:eventId/sessionsNo auth
GET/client/events/:eventId/scheduleNo auth
GET/client/events/:eventId/mediaNo auth
GET/client/events/bookingNo auth
POST/client/events/tickets/purchaseNo auth
POST/client/events/tickets/confirm-orderNo auth
GET/client/events/stripe/configNo auth
POST/client/events/stripe/intentNo auth
GET/client/community/feedNo auth
GET/client/community/posts/:postIdNo auth
GET/client/community/posts/:postId/commentsNo auth
GET/client/community/pagesNo auth
GET/client/community/pages/:pageId/announcementsNo auth
GET/client/community/storiesNo auth
GET/client/community/people/:emailNo auth
GET/client/community/hashtags/trendingNo auth

Participants (GET /client/events/:eventId/participants), tickets, the wallet, connections, messages, notifications, bookmarks, follows, meetings and media uploads all require the customer token.

Public feed, private flags

The feed is public, but viewerLiked and viewerSaved are only stamped when a customer token is present. The app sends it; a browser hitting the route anonymously sees the posts without those flags.

Rate limiting

The API applies one global limiter: a 15-minute window with RATE_LIMIT_MAX requests per client address (default 10,000). Preflight requests and the health check are exempt. A burst from scripted tests on one address returns 429 Too Many Requests; the app on a phone is not affected by a developer's laptop hitting the limit. TRUST_PROXY_HOPS (default 2) controls how the client address is read behind a proxy.

Server variables

Environment variables the events, community, reservations and related modules read:

VariableUsed for
SHARED_ORG, ROOT_ORGFallback organizations for shared configuration
NODE_ENVProduction toggles, including secure link schemes
GOOGLE_MAPS_API_KEYAddress and venue lookups
VIDEOSDK_API_ENDPOINTVirtual meeting tokens for reservations
RESERVATION_REMINDER_TEST_MODEShortens reminder offsets for testing
JWT_SECRETToken signing
RATE_LIMIT_MAX, TRUST_PROXY_HOPSSee above

Push for the staff softphone uses a separate set (APPMINT_FCM_SERVICE_ACCOUNT_JSON_BASE64, APPMINT_APNS_VOIP_*, APPMINT_APNS_SANDBOX); the attendee app does not use them.