cURL
curl -X POST "https://api.fitsociety.io/public/v1/booking-requests/{bookingRequestId}/approve" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.fitsociety.io/public/v1/booking-requests/{bookingRequestId}/approve', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/booking-requests/{bookingRequestId}/approve"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text){
"data": {
"bookingRequest": {
"bookingRequestId": "66f7b8b1e13c8d25f4d3d90a",
"client": {
"clientId": "66f7b8b1e13c8d25f4d3d90a",
"name": "Example name"
},
"calendarEventId": "66f7b8b1e13c8d25f4d3d90a",
"lessonId": "66f7b8b1e13c8d25f4d3d90a",
"bookingId": "66f7b8b1e13c8d25f4d3d90a",
"instanceDate": "2026-07-14T10:00:00.000Z",
"status": "active",
"capacity": {
"booked": 1,
"waiting": 1,
"total": 1,
"available": 1,
"hasWaitingList": true,
"waitingListCapacity": 1
},
"lesson": {
"name": "Example name",
"type": "string",
"enforceGroupSizeLimit": true
},
"createdAt": "2026-07-14T10:00:00.000Z",
"updatedAt": "2026-07-14T10:00:00.000Z"
},
"action": {
"status": "active",
"appliedAt": "2026-07-14T10:00:00.000Z"
}
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Bookings
Approve booking request
Requires booking_requests:write. Approves a pending booking request and returns the redacted booking request DTO. Empty request bodies are accepted.
POST
/
public
/
v1
/
booking-requests
/
{bookingRequestId}
/
approve
cURL
curl -X POST "https://api.fitsociety.io/public/v1/booking-requests/{bookingRequestId}/approve" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.fitsociety.io/public/v1/booking-requests/{bookingRequestId}/approve', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/booking-requests/{bookingRequestId}/approve"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text){
"data": {
"bookingRequest": {
"bookingRequestId": "66f7b8b1e13c8d25f4d3d90a",
"client": {
"clientId": "66f7b8b1e13c8d25f4d3d90a",
"name": "Example name"
},
"calendarEventId": "66f7b8b1e13c8d25f4d3d90a",
"lessonId": "66f7b8b1e13c8d25f4d3d90a",
"bookingId": "66f7b8b1e13c8d25f4d3d90a",
"instanceDate": "2026-07-14T10:00:00.000Z",
"status": "active",
"capacity": {
"booked": 1,
"waiting": 1,
"total": 1,
"available": 1,
"hasWaitingList": true,
"waitingListCapacity": 1
},
"lesson": {
"name": "Example name",
"type": "string",
"enforceGroupSizeLimit": true
},
"createdAt": "2026-07-14T10:00:00.000Z",
"updatedAt": "2026-07-14T10:00:00.000Z"
},
"action": {
"status": "active",
"appliedAt": "2026-07-14T10:00:00.000Z"
}
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
Required string length:
1 - 200Example:
"booking-create-20260714-001"
Path Parameters
Example:
"66f7b8b1e13c8d25f4d3d90a"