REST API

Auth Ticket API

POST /api/v1/auth/ticket

Overview

Obtain a one-time ticket for establishing a WebSocket connection. Because the browser's native WebSocket API does not support custom HTTP headers, VAS uses a ticket mechanism: you first exchange your API key for a one-time ticket, then establish the WebSocket connection through Sec-WebSocket-Protocol.

Authentication

Header: X-API-Key (see Authentication)

Request Parameters

This endpoint does not require any request parameters.

Request Example

curl -X POST "https://vas-poc.vurbo.ai/api/v1/auth/ticket" \
  -H "X-API-Key: vas_aB3dE5fG7hI9jK1lM3nO5pQ7rS9tU1vW"

Success Response

HTTP 200

{
  "ticket": "aBcDeFgHiJkLmNoPqRsTuVwXyZ012345",
  "expires_in": 60
}

Response Fields

FieldTypeDescription
ticketstringOne-time ticket (32-character random string)
expires_inintegerValidity period (seconds), fixed at 60

Ticket Characteristics

CharacteristicDescription
Validity periodMust be used within 60 seconds
One-time useDeleted immediately after use; cannot be reused
UsagePassed through Sec-WebSocket-Protocol in the format ticket.{ticket_value}

Usage Example

After obtaining the ticket, establish the WebSocket connection as follows:

const ws = new WebSocket('wss://vas-poc.vurbo.ai/ws', [`ticket.${ticket}`]);

Specific Error Codes

Error CodeHTTP StatusDescriptionRecommended Action
plan_daily_limit_reached402Plan daily usage limit reached (unlimited plans, v1.9.0)Obtain a ticket again after the limit resets (next day); check usage and recovery time via GET /api/v1/me/plan

ticket_* are not error codes of this endpoint: tickets are validated when the WebSocket connection is established, and these codes are returned as WebSocket messages at that stage — they never appear in this REST endpoint's HTTP response.

In practice you will only see two of them. Tickets are validated with a single read-and-delete, so invalid, expired and already-used all return ticket_invalid; ticket_expired and ticket_already_used are not emitted. If the validation procedure itself fails, ticket_validation_failed is returned (401, not 500).


Version: V1.24.1 Last Updated: 2026-09-28

Copyright © 2026