Public Gigs API
Pull your band's upcoming gigs straight onto your own website.
The Public Gigs API is a read-only, key-authenticated endpoint that returns a band's upcoming Gig events as JSON — the same events shown on the "Public Gig Publishing" side of Band Manager, but fetched directly by your own site instead of copy-pasted by hand. It's a paid add-on, separate from a band's normal subscription plan.
1. Get a key
An admin buys API access from Billing inside Band Manager (£9.99, one-time and non-refundable). Once the purchase completes, your API key appears on that page. Treat it like a password — anyone with it can read your band's upcoming gigs, though nothing more sensitive than that. If a key leaks, regenerate it from Billing; the old one stops working immediately.
2. Make a request
GET https://your-band-manager-domain/api/public-gigs.php
Authenticate with your key using either of these — not both:
- An
X-API-Keyheader (recommended for server-side calls) - An
?api_key=query parameter (simplest for client-sidefetch, since it avoids a CORS preflight request)
Optional query parameters
| Parameter | Meaning |
|---|---|
limit | Max events to return. Default 20, maximum 50. |
cURL
curl "https://your-band-manager-domain/api/public-gigs.php?limit=10" \
-H "X-API-Key: bmapi_your_key_here"
Browser fetch (client-side)
const res = await fetch(
"https://your-band-manager-domain/api/public-gigs.php?api_key=bmapi_your_key_here"
);
const data = await res.json();
3. Response
A successful request returns 200 OK with a JSON object:
{
"band": "The Sample Band",
"gigs": [
{
"title": "The Marlowe",
"date": "2026-09-16",
"time": "20:00",
"location": "The Marlowe, Bristol",
"venueUrl": "https://www.themarlowebristol.co.uk"
},
{
"title": "Harbourside Festival",
"date": "2026-09-28",
"time": "17:30",
"location": "Harbourside, Bristol",
"venueUrl": null
}
]
}
Field reference
| Field | Type | Notes |
|---|---|---|
band | string | The band's display name. |
gigs[].title | string | Event title. |
gigs[].date | string | YYYY-MM-DD. |
gigs[].time | string | HH:MM, 24-hour. |
gigs[].location | string or null | Free-text venue/location. |
gigs[].venueUrl | string or null | Link to the venue's own page, if one was set. |
Only upcoming, non-cancelled events of type "Gig" are ever returned, ordered soonest first. Nothing about attendees, RSVPs, documents, or rehearsals is exposed by this endpoint.
4. Errors
| Status | Meaning |
|---|---|
401 | Missing or invalid API key. |
403 | The key is valid but its licence has been revoked. |
429 | Rate limit exceeded — see below. |
Error responses are JSON: {"error": "..."}.
5. Rate limits
60 requests per minute per key. This is a small, slow-changing list — cache the response on your side (even a few minutes is plenty) rather than fetching on every page view. A static site generator or a scheduled job that fetches once and writes a file is a good fit; so is fetching client-side with a short in-browser cache.
6. CORS
The endpoint sends Access-Control-Allow-Origin: *, so it can be called
directly from browser JavaScript on any domain — no server-side proxy required.
Only the API key gates access; no cookies or credentials are ever involved.
Example: render a gig list
A minimal drop-in for a static site — a container element plus a script tag:
<div id="upcoming-gigs">Loading gigs…</div>
<script>
fetch("https://your-band-manager-domain/api/public-gigs.php?api_key=bmapi_your_key_here")
.then(function (res) {
if (!res.ok) throw new Error("Gigs API error " + res.status);
return res.json();
})
.then(function (data) {
const el = document.getElementById("upcoming-gigs");
if (data.gigs.length === 0) {
el.textContent = "No upcoming gigs.";
return;
}
el.innerHTML = data.gigs.map(function (g) {
const date = new Date(g.date + "T" + g.time);
const when = date.toLocaleDateString(undefined, { day: "numeric", month: "long" })
+ " — " + g.time;
const venue = g.venueUrl
? '<a href="' + g.venueUrl + '">' + g.location + "</a>"
: g.location;
return "<div><strong>" + g.title + "</strong><br>"
+ when + (venue ? " · " + venue : "") + "</div>";
}).join("");
})
.catch(function () {
document.getElementById("upcoming-gigs").textContent = "Couldn't load gigs right now.";
});
</script>
Escape or sanitise title/location as you would any external
text before inserting it into your own page — this example keeps it short, but
production code should not build HTML with plain string concatenation.
Example: server-side (PHP)
$ch = curl_init("https://your-band-manager-domain/api/public-gigs.php?limit=10");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, ["X-API-Key: bmapi_your_key_here"]);
$response = curl_exec($ch);
curl_close($ch);
$data = json_decode($response, true);
foreach ($data["gigs"] as $gig) {
echo $gig["title"] . " on " . $gig["date"] . "\n";
}
Support
Questions about the API, or a bug to report? See Support, or email Support. Your API key is shown any time from Billing inside Band Manager. This is a one-time, non-refundable purchase — there's no subscription to manage or cancel.