Auth Ticket API
POST /api/v1/auth/ticket
Overview
Obtain a one-time ticket for establishing a WebSocket connection. Because the browser's native WebSocket API does not support custom HTTP headers, VAS uses a ticket mechanism: you first exchange your API key for a one-time ticket, then establish the WebSocket connection through Sec-WebSocket-Protocol.
Authentication
Header: X-API-Key (see Authentication)
Request Parameters
This endpoint does not require any request parameters.
Request Example
curl -X POST "https://vas-poc.vurbo.ai/api/v1/auth/ticket" \
-H "X-API-Key: vas_aB3dE5fG7hI9jK1lM3nO5pQ7rS9tU1vW"
Success Response
HTTP 200
{
"ticket": "aBcDeFgHiJkLmNoPqRsTuVwXyZ012345",
"expires_in": 60
}
Response Fields
| Field | Type | Description |
|---|---|---|
ticket | string | One-time ticket (32-character random string) |
expires_in | integer | Validity period (seconds), fixed at 60 |
Ticket Characteristics
| Characteristic | Description |
|---|---|
| Validity period | Must be used within 60 seconds |
| One-time use | Deleted immediately after use; cannot be reused |
| Usage | Passed through Sec-WebSocket-Protocol in the format ticket.{ticket_value} |
Usage Example
After obtaining the ticket, establish the WebSocket connection as follows:
const ws = new WebSocket('wss://vas-poc.vurbo.ai/ws', [`ticket.${ticket}`]);
Specific Error Codes
| Error Code | HTTP Status | Description | Recommended Action |
|---|---|---|---|
plan_daily_limit_reached | 402 | Plan daily usage limit reached (unlimited plans, v1.9.0) | Obtain a ticket again after the limit resets (next day); check usage and recovery time via GET /api/v1/me/plan |
ticket_*are not error codes of this endpoint: tickets are validated when the WebSocket connection is established, and these codes are returned as WebSocket messages at that stage — they never appear in this REST endpoint's HTTP response.In practice you will only see two of them. Tickets are validated with a single read-and-delete, so invalid, expired and already-used all return
ticket_invalid;ticket_expiredandticket_already_usedare not emitted. If the validation procedure itself fails,ticket_validation_failedis returned (401, not 500).
Version: V1.24.1 Last Updated: 2026-09-28