Public Gigs API

Pull your band's upcoming gigs straight onto your own website.

The Public Gigs API is a read-only, key-authenticated endpoint that returns a band's upcoming Gig events as JSON — the same events shown on the "Public Gig Publishing" side of Band Manager, but fetched directly by your own site instead of copy-pasted by hand. It's a paid add-on, separate from a band's normal subscription plan.

1. Get a key

An admin buys API access from Billing inside Band Manager (£9.99, one-time and non-refundable). Once the purchase completes, your API key appears on that page. Treat it like a password — anyone with it can read your band's upcoming gigs, though nothing more sensitive than that. If a key leaks, regenerate it from Billing; the old one stops working immediately.

2. Make a request

GET https://your-band-manager-domain/api/public-gigs.php

Authenticate with your key using either of these — not both:

Optional query parameters

ParameterMeaning
limitMax events to return. Default 20, maximum 50.

cURL

curl "https://your-band-manager-domain/api/public-gigs.php?limit=10" \
  -H "X-API-Key: bmapi_your_key_here"

Browser fetch (client-side)

const res = await fetch(
  "https://your-band-manager-domain/api/public-gigs.php?api_key=bmapi_your_key_here"
);
const data = await res.json();

3. Response

A successful request returns 200 OK with a JSON object:

{
  "band": "The Sample Band",
  "gigs": [
    {
      "title": "The Marlowe",
      "date": "2026-09-16",
      "time": "20:00",
      "location": "The Marlowe, Bristol",
      "venueUrl": "https://www.themarlowebristol.co.uk"
    },
    {
      "title": "Harbourside Festival",
      "date": "2026-09-28",
      "time": "17:30",
      "location": "Harbourside, Bristol",
      "venueUrl": null
    }
  ]
}

Field reference

FieldTypeNotes
bandstringThe band's display name.
gigs[].titlestringEvent title.
gigs[].datestringYYYY-MM-DD.
gigs[].timestringHH:MM, 24-hour.
gigs[].locationstring or nullFree-text venue/location.
gigs[].venueUrlstring or nullLink to the venue's own page, if one was set.

Only upcoming, non-cancelled events of type "Gig" are ever returned, ordered soonest first. Nothing about attendees, RSVPs, documents, or rehearsals is exposed by this endpoint.

4. Errors

StatusMeaning
401Missing or invalid API key.
403The key is valid but its licence has been revoked.
429Rate limit exceeded — see below.

Error responses are JSON: {"error": "..."}.

5. Rate limits

60 requests per minute per key. This is a small, slow-changing list — cache the response on your side (even a few minutes is plenty) rather than fetching on every page view. A static site generator or a scheduled job that fetches once and writes a file is a good fit; so is fetching client-side with a short in-browser cache.

6. CORS

The endpoint sends Access-Control-Allow-Origin: *, so it can be called directly from browser JavaScript on any domain — no server-side proxy required. Only the API key gates access; no cookies or credentials are ever involved.

Example: render a gig list

A minimal drop-in for a static site — a container element plus a script tag:

<div id="upcoming-gigs">Loading gigs…</div>

<script>
fetch("https://your-band-manager-domain/api/public-gigs.php?api_key=bmapi_your_key_here")
  .then(function (res) {
    if (!res.ok) throw new Error("Gigs API error " + res.status);
    return res.json();
  })
  .then(function (data) {
    const el = document.getElementById("upcoming-gigs");
    if (data.gigs.length === 0) {
      el.textContent = "No upcoming gigs.";
      return;
    }
    el.innerHTML = data.gigs.map(function (g) {
      const date = new Date(g.date + "T" + g.time);
      const when = date.toLocaleDateString(undefined, { day: "numeric", month: "long" })
        + " — " + g.time;
      const venue = g.venueUrl
        ? '<a href="' + g.venueUrl + '">' + g.location + "</a>"
        : g.location;
      return "<div><strong>" + g.title + "</strong><br>"
        + when + (venue ? " · " + venue : "") + "</div>";
    }).join("");
  })
  .catch(function () {
    document.getElementById("upcoming-gigs").textContent = "Couldn't load gigs right now.";
  });
</script>

Escape or sanitise title/location as you would any external text before inserting it into your own page — this example keeps it short, but production code should not build HTML with plain string concatenation.

Example: server-side (PHP)

$ch = curl_init("https://your-band-manager-domain/api/public-gigs.php?limit=10");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, ["X-API-Key: bmapi_your_key_here"]);
$response = curl_exec($ch);
curl_close($ch);

$data = json_decode($response, true);
foreach ($data["gigs"] as $gig) {
    echo $gig["title"] . " on " . $gig["date"] . "\n";
}

Support

Questions about the API, or a bug to report? See Support, or email Support. Your API key is shown any time from Billing inside Band Manager. This is a one-time, non-refundable purchase — there's no subscription to manage or cancel.