Business Box Start free

API reference

All 12 operations, generated from the OpenAPI document so it cannot fall behind the API.

In shortBase URL https://api.marubox.jp/v1, bearer authentication on everything except /openapi.json. This page is generated from the OpenAPI document; that file is the authority, and a code generator will do better with it than with this table.

Account#

Who the token belongs to

Get the authenticated account#

GEThttps://api.marubox.jp/v1/me

Returns the account the token belongs to, and the scopes the token carries. Integration platforms call this to test a connection and to label it.

Operation id getMe · Errors: 400, 401, 403, 404, 409, 429

Returns 200

FieldTypeNotes
idstringalways
namestringalways
emailstringalways
handlestring | nullalways
localeen | jaalways
timezonestringalways
bookingPageUrlstring | nullalways
planfree | standardalways
scopesarray of event_types:read | bookings:read | bookings:write | webhooks:managealways

Event types#

What people can book, and when

List event types#

GEThttps://api.marubox.jp/v1/event-types

The things people can book. Use this to populate an event type dropdown. Ordered as they appear in the app.

Operation id listEventTypes · Errors: 400, 401, 403, 404, 409, 429

Query parameters

NameTypeNotes
limitintegeroptional Defaults to 50.
cursorstringoptional
activetrue | falseoptional Defaults to "true".

Returns 200

FieldTypeNotes
itemsarray of objectalways
fields
items.idstringalways
items.namestringalways
items.nameI18nobjectalways
items.descriptionstring | nullalways
items.slugstringalways
items.durationMinutesintegeralways
items.visibilitypublic | invite_onlyalways
items.activebooleanalways
items.bookingUrlstring | nullalways
items.priceobject or nullalways
items.payOnArrivalbooleanalways
items.locationKindstringalways
items.createdAtstringalways
items.updatedAtstringalways
nextCursorstring | nullalways

List available start times#

GEThttps://api.marubox.jp/v1/event-types/{id}/slots

Available start times for an event type, as UTC instants, after availability, calendar conflicts, buffers, notice and daily limits have been applied. The range may span at most 31 days. Invite-only event types are included, because the caller owns them.

Operation id listAvailableSlots · Errors: 400, 401, 403, 404, 409, 429

Query parameters

NameTypeNotes
fromstringrequired
tostringrequired
idstringrequired

Returns 200

FieldTypeNotes
slotsarray of string (date-time)always
calendarBlockedbooleanalways

Bookings#

Read, create and cancel bookings

List bookings#

GEThttps://api.marubox.jp/v1/bookings

Bookings, newest first by default. Held and awaiting-payment bookings are excluded unless asked for by status: they are in-flight states, not bookings anyone should act on. Items are full booking objects, so a polling trigger can emit them directly.

Operation id listBookings · Errors: 400, 401, 403, 404, 409, 429

Query parameters

NameTypeNotes
limitintegeroptional Defaults to 50.
cursorstringoptional
statusstringoptional
eventTypeIdstringoptional
emailstring (email)optional
startFromstring (date-time)optional
startTostring (date-time)optional
updatedSincestring (date-time)optional
sort-createdAt | start | -start | -updatedAtoptional Defaults to "-createdAt".

Returns 200

FieldTypeNotes
itemsarray of objectalways
fields
items.idstringalways
items.statusheld | awaiting_payment | confirmed | cancelled | completed | no_showalways
items.startstringalways
items.endstringalways
items.hostTimezonestringalways
items.eventTypeobjectalways
items.bookerobjectalways
items.answersarray of objectalways
items.bookerNotesstring | nullalways
items.locationobject | object | object | object | objectalways
items.joinUrlstring | nullalways
items.sourcepublic | manual | reschedulealways
items.paymentobject or nullalways
items.cancellationobject or nullalways
items.manageUrlstringalways
items.createdAtstringalways
items.updatedAtstringalways
nextCursorstring | nullalways

Create a booking#

POSThttps://api.marubox.jp/v1/bookings

Books a time on behalf of a customer, exactly as adding one by hand in the app does. The customer is emailed a confirmation unless notify is false. No card payment is taken, even for a paid event type. A time that is no longer free returns 409 slot_unavailable: the API never double-books.

Operation id createBooking · Errors: 400, 401, 403, 404, 409, 429

Request body

FieldTypeNotes
eventTypeIdstringrequired
startstring (date-time)required
bookerobjectrequired
fields
booker.namestringrequired
booker.emailstring (email)required
booker.phonestringoptional
booker.localeen | jaoptional Defaults to "en".
booker.timezonestringrequired
notesstringoptional
notifybooleanoptional Defaults to true.

Returns 201

FieldTypeNotes
idstringalways
statusheld | awaiting_payment | confirmed | cancelled | completed | no_showalways
startstringalways
endstringalways
hostTimezonestringalways
eventTypeobjectalways
fields
eventType.idstringalways
eventType.namestringalways
eventType.nameI18nobjectalways
eventType.slugstringalways
bookerobjectalways
fields
booker.namestringalways
booker.emailstringalways
booker.phonestring | nullalways
booker.localeen | jaalways
booker.timezonestringalways
answersarray of objectalways
fields
answers.questionIdstringalways
answers.labelstringalways
answers.labelI18nobjectalways
answers.valuestring | booleanalways
bookerNotesstring | nullalways
locationobject | object | object | object | objectalways
joinUrlstring | nullalways
sourcepublic | manual | reschedulealways
paymentobject or nullalways
cancellationobject or nullalways
manageUrlstringalways
createdAtstringalways
updatedAtstringalways

Get a booking#

GEThttps://api.marubox.jp/v1/bookings/{id}

Operation id getBooking · Errors: 400, 401, 403, 404, 409, 429

Query parameters

NameTypeNotes
idstringrequired

Returns 200

FieldTypeNotes
idstringalways
statusheld | awaiting_payment | confirmed | cancelled | completed | no_showalways
startstringalways
endstringalways
hostTimezonestringalways
eventTypeobjectalways
fields
eventType.idstringalways
eventType.namestringalways
eventType.nameI18nobjectalways
eventType.slugstringalways
bookerobjectalways
fields
booker.namestringalways
booker.emailstringalways
booker.phonestring | nullalways
booker.localeen | jaalways
booker.timezonestringalways
answersarray of objectalways
fields
answers.questionIdstringalways
answers.labelstringalways
answers.labelI18nobjectalways
answers.valuestring | booleanalways
bookerNotesstring | nullalways
locationobject | object | object | object | objectalways
joinUrlstring | nullalways
sourcepublic | manual | reschedulealways
paymentobject or nullalways
cancellationobject or nullalways
manageUrlstringalways
createdAtstringalways
updatedAtstringalways

Cancel a booking#

POSThttps://api.marubox.jp/v1/bookings/{id}/cancel

Cancels a booking exactly as the app does: the customer is emailed, and a paid booking is refunded in full. Idempotent — cancelling an already-cancelled booking returns it unchanged.

Operation id cancelBooking · Errors: 400, 401, 403, 404, 409, 429

Query parameters

NameTypeNotes
idstringrequired

Request body

FieldTypeNotes
messagestringoptional

Returns 200

FieldTypeNotes
idstringalways
statusheld | awaiting_payment | confirmed | cancelled | completed | no_showalways
startstringalways
endstringalways
hostTimezonestringalways
eventTypeobjectalways
fields
eventType.idstringalways
eventType.namestringalways
eventType.nameI18nobjectalways
eventType.slugstringalways
bookerobjectalways
fields
booker.namestringalways
booker.emailstringalways
booker.phonestring | nullalways
booker.localeen | jaalways
booker.timezonestringalways
answersarray of objectalways
fields
answers.questionIdstringalways
answers.labelstringalways
answers.labelI18nobjectalways
answers.valuestring | booleanalways
bookerNotesstring | nullalways
locationobject | object | object | object | objectalways
joinUrlstring | nullalways
sourcepublic | manual | reschedulealways
paymentobject or nullalways
cancellationobject or nullalways
manageUrlstringalways
createdAtstringalways
updatedAtstringalways

Invites#

Single-use booking links

POSThttps://api.marubox.jp/v1/invites

Mints a booking link that works once and then stops. Use it to reply to an enquiry. Works for public and invite-only event types, and the invitee skips the anti-spam checks because the link already proves you meant them. The url is returned only here.

Operation id createInviteLink · Errors: 400, 401, 403, 404, 409, 429

Request body

FieldTypeNotes
eventTypeIdstringrequired
namestringoptional
emailstring (email)optional
expiresInDaysintegeroptional Defaults to 14.

Returns 201

FieldTypeNotes
idstringalways
eventTypeIdstringalways
urlstring | nullalways
namestring | nullalways
emailstring | nullalways
expiresAtstring (date-time)always
usedAtstring (date-time) or nullalways
bookingIdstring | nullalways
createdAtstring (date-time)always

Webhooks#

Subscribe to events

List webhook subscriptions#

GEThttps://api.marubox.jp/v1/webhooks

Secrets are never returned here.

Operation id listWebhooks · Errors: 400, 401, 403, 404, 409, 429

Query parameters

NameTypeNotes
limitintegeroptional Defaults to 50.
cursorstringoptional

Returns 200

FieldTypeNotes
itemsarray of objectalways
fields
items.idstringalways
items.urlstringalways
items.eventsarray of stringalways
items.descriptionstring | nullalways
items.statusactive | disabledalways
items.createdViastringalways
items.lastSuccessAtstring | nullalways
items.consecutiveFailuresintegeralways
items.createdAtstringalways
nextCursorstring | nullalways

Subscribe to events#

POSThttps://api.marubox.jp/v1/webhooks

Registers an endpoint to receive events. The secret is returned only here: store it, and verify the BB-Signature header on every delivery. Returns a Location header pointing at the subscription.

Operation id createWebhook · Errors: 400, 401, 403, 404, 409, 429

Request body

FieldTypeNotes
urlstring (uri)required
eventsarray of booking.created | booking.rescheduled | booking.cancelled | booking.no_show | *required
descriptionstringoptional

Returns 201

FieldTypeNotes
idstringalways
urlstringalways
eventsarray of stringalways
descriptionstring | nullalways
statusactive | disabledalways
createdViastringalways
lastSuccessAtstring | nullalways
consecutiveFailuresintegeralways
createdAtstringalways
secretstringalways

Get a webhook subscription#

GEThttps://api.marubox.jp/v1/webhooks/{id}

Used by trigger nodes to check that a subscription still exists.

Operation id getWebhook · Errors: 400, 401, 403, 404, 409, 429

Query parameters

NameTypeNotes
idstringrequired

Returns 200

FieldTypeNotes
idstringalways
urlstringalways
eventsarray of stringalways
descriptionstring | nullalways
statusactive | disabledalways
createdViastringalways
lastSuccessAtstring | nullalways
consecutiveFailuresintegeralways
createdAtstringalways

Delete a webhook subscription#

DELETEhttps://api.marubox.jp/v1/webhooks/{id}

Idempotent: an unknown id also returns 204, so an unsubscribe never fails on a retry.

Operation id deleteWebhook · Errors: 400, 401, 403, 404, 409, 429

Query parameters

NameTypeNotes
idstringrequired

Webhook payloads#

These are requests we send to you. Each arrives as JSON with a BB-Signature header — see Webhooks for verification.

booking.created#

A booking became confirmed for the first time. Paid bookings fire only once payment succeeds.

FieldTypeNotes
idstringalways
typebooking.createdalways
createdAtstring (date-time)always
apiVersionv1always
dataobjectalways
fields
data.bookingapiBookingalways

booking.rescheduled#

A booking moved. Exactly one event: no cancelled/created pair.

FieldTypeNotes
idstringalways
typebooking.rescheduledalways
createdAtstring (date-time)always
apiVersionv1always
dataobjectalways
fields
data.bookingapiBookingalways
data.previousobjectsometimes

booking.cancelled#

A booking was cancelled by the booker, the host or the system.

FieldTypeNotes
idstringalways
typebooking.cancelledalways
createdAtstring (date-time)always
apiVersionv1always
dataobjectalways
fields
data.bookingapiBookingalways

booking.no_show#

A booking was marked as a no-show.

FieldTypeNotes
idstringalways
typebooking.no_showalways
createdAtstring (date-time)always
apiVersionv1always
dataobjectalways
fields
data.bookingapiBookingalways

Last reviewed 28 September 2026.