curl --request POST \
--url https://api.passlet.io/v1/passes \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"externalPassId": "<string>",
"label": "<string>",
"templateId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"variables": {}
}
'import requests
url = "https://api.passlet.io/v1/passes"
payload = {
"externalPassId": "<string>",
"label": "<string>",
"templateId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"variables": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
externalPassId: '<string>',
label: '<string>',
templateId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
variables: {}
})
};
fetch('https://api.passlet.io/v1/passes', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.passlet.io/v1/passes",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'externalPassId' => '<string>',
'label' => '<string>',
'templateId' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'variables' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.passlet.io/v1/passes"
payload := strings.NewReader("{\n \"externalPassId\": \"<string>\",\n \"label\": \"<string>\",\n \"templateId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"variables\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.passlet.io/v1/passes")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"externalPassId\": \"<string>\",\n \"label\": \"<string>\",\n \"templateId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"variables\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.passlet.io/v1/passes")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"externalPassId\": \"<string>\",\n \"label\": \"<string>\",\n \"templateId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"variables\": {}\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"externalPassId": "<string>",
"label": "<string>",
"status": "QUEUED",
"version": 123,
"templateVersionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"templateId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"variables": {},
"redemption": {
"windows": [
{
"start": "<string>",
"end": "<string>",
"maxUses": 50000
}
],
"maxUses": 50000,
"autoVoidOnExhaustion": true,
"perPeriod": {
"unit": "day",
"count": 50000,
"timezone": "<string>"
},
"minIntervalMinutes": 263520,
"activation": {
"basis": "firstScan",
"validForHours": 43920
}
},
"expiresAt": "2023-11-07T05:31:56Z",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"hostedLinks": {
"apple": "<string>",
"google": "<string>",
"smart": "<string>"
}
}{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"externalPassId": "<string>",
"label": "<string>",
"status": "QUEUED",
"version": 123,
"templateVersionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"templateId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"variables": {},
"redemption": {
"windows": [
{
"start": "<string>",
"end": "<string>",
"maxUses": 50000
}
],
"maxUses": 50000,
"autoVoidOnExhaustion": true,
"perPeriod": {
"unit": "day",
"count": 50000,
"timezone": "<string>"
},
"minIntervalMinutes": 263520,
"activation": {
"basis": "firstScan",
"validForHours": 43920
}
},
"expiresAt": "2023-11-07T05:31:56Z",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"hostedLinks": {
"apple": "<string>",
"google": "<string>",
"smart": "<string>"
}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}Create a pass
Creates a wallet pass from a template and returns it with hosted add-to-wallet links. Issuance is asynchronous: the pass is returned in QUEUED status (201) and a background worker signs and issues it. Creation is idempotent on externalPassId: reusing one returns the existing pass with 200 instead of creating a duplicate. variables are validated against the template’s published version, which the pass is pinned to.
Requires the passes:write scope on the access token.
curl --request POST \
--url https://api.passlet.io/v1/passes \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"externalPassId": "<string>",
"label": "<string>",
"templateId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"variables": {}
}
'import requests
url = "https://api.passlet.io/v1/passes"
payload = {
"externalPassId": "<string>",
"label": "<string>",
"templateId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"variables": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
externalPassId: '<string>',
label: '<string>',
templateId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
variables: {}
})
};
fetch('https://api.passlet.io/v1/passes', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.passlet.io/v1/passes",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'externalPassId' => '<string>',
'label' => '<string>',
'templateId' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'variables' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.passlet.io/v1/passes"
payload := strings.NewReader("{\n \"externalPassId\": \"<string>\",\n \"label\": \"<string>\",\n \"templateId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"variables\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.passlet.io/v1/passes")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"externalPassId\": \"<string>\",\n \"label\": \"<string>\",\n \"templateId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"variables\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.passlet.io/v1/passes")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"externalPassId\": \"<string>\",\n \"label\": \"<string>\",\n \"templateId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"variables\": {}\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"externalPassId": "<string>",
"label": "<string>",
"status": "QUEUED",
"version": 123,
"templateVersionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"templateId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"variables": {},
"redemption": {
"windows": [
{
"start": "<string>",
"end": "<string>",
"maxUses": 50000
}
],
"maxUses": 50000,
"autoVoidOnExhaustion": true,
"perPeriod": {
"unit": "day",
"count": 50000,
"timezone": "<string>"
},
"minIntervalMinutes": 263520,
"activation": {
"basis": "firstScan",
"validForHours": 43920
}
},
"expiresAt": "2023-11-07T05:31:56Z",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"hostedLinks": {
"apple": "<string>",
"google": "<string>",
"smart": "<string>"
}
}{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"externalPassId": "<string>",
"label": "<string>",
"status": "QUEUED",
"version": 123,
"templateVersionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"templateId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"variables": {},
"redemption": {
"windows": [
{
"start": "<string>",
"end": "<string>",
"maxUses": 50000
}
],
"maxUses": 50000,
"autoVoidOnExhaustion": true,
"perPeriod": {
"unit": "day",
"count": 50000,
"timezone": "<string>"
},
"minIntervalMinutes": 263520,
"activation": {
"basis": "firstScan",
"validForHours": 43920
}
},
"expiresAt": "2023-11-07T05:31:56Z",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"hostedLinks": {
"apple": "<string>",
"google": "<string>",
"smart": "<string>"
}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}{
"errorCode": "UNAUTHORIZED",
"message": "<string>",
"correlationId": "<string>",
"details": {}
}Authorizations
Passlet access token (plt_*) sent as Authorization: Bearer <token> or X-API-Key. Authorized scopes are listed per operation under x-required-scopes.
Body
External system pass ID (used for idempotency)
1 - 255Pass holder display name
1 - 255Template to use for this pass
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Variables to store as pass input data
Show child attributes
Show child attributes
Response
OK
Pass identifier
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$External system pass ID
1 - 255Pass holder display name
1 - 255QUEUED, ISSUING, ISSUED, VOID, FAILED, EXPIRED "QUEUED"
Optimistic locking version
x <= 9007199254740991Template version the pass currently renders with. Pinned at issue time; only changes via an explicit template upgrade to a newer published version of the same template.
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Template identifier this pass was issued from
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Project the pass lives in
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Stored pass variables
Show child attributes
Show child attributes
Resolved redemption policy enforced at scan time
Show child attributes
Show child attributes
Pass expiration timestamp
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$ISO 8601 timestamp
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$ISO 8601 timestamp
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$Hosted add-to-wallet links
Show child attributes
Show child attributes