Support & Troubleshooting
Resources to help you diagnose integration issues and contact the Vendora sandbox team.
Contact
Integration Support
For technical API questions, sandbox access and credential issues.
Contact your Vendora integration manager.
Credential Compromise
If you believe a sandbox API key has been exposed:
- Stop using the key immediately.
- Do not attempt to rotate it yourself.
- Contact your integration manager and provide the
tracing_idfrom any suspicious requests. - Never share the key value in your report.
Using Tracing IDs
Every Vendora API response includes a tracing_id. Always include this when reporting issues — it allows the Vendora team to locate the exact request in server logs.
// Every Vendora response envelope:
{
"tracing_id": "trace-abc12345", ← include this in support requests
"code": "...",
"errors": [...]
}X-Request-ID header value from the Nitro response instead. Common Issues
503 / "Portal authentication is not configured"
The server is running in hosted mode (NODE_ENV != development) but NUXT_PORTAL_USERNAME and NUXT_PORTAL_PASSWORD_HASH are not set.
- Set NUXT_PORTAL_USERNAME and NUXT_PORTAL_PASSWORD_HASH in your environment.
- Generate a bcrypt hash with: node -e "const b=require('bcryptjs');b.hash('yourpassword',12).then(console.log)"
- Restart the server.
401 / "Dashboard authentication required" on every request
The portal session has expired or the session cookie is missing. Sessions expire after 1 hour of inactivity.
- Log in again at /vendor-dashboard.
- Ensure cookies are not blocked by the browser.
- Check that the server was not restarted (in-memory sessions are cleared on restart).
409 / "TICKET_SELECTION_UNAVAILABLE"
One or more tickets you selected were reserved by another session between your availability check and hold creation.
- The UI will refresh the availability grid automatically.
- Re-select from the updated availability.
- This is normal in a concurrent sandbox environment.
410 / "HOLD_EXPIRED"
The Vendora hold expired before the sale was submitted. Holds have a limited validity window.
- Create a new hold.
- Complete checkout before the hold expiry countdown reaches zero.
- The authoritative expiry is shown in the storefront cart.
502 / "The e-ticket could not be downloaded"
The Vendora API returned a non-PDF response or an error. The e-ticket may not be ready yet.
- Check the e_ticket.status field on the transaction — it should be "SENT" before downloading.
- If status is "QUEUED", wait a moment and try again.
- If status is "FAILED", this is a backend dependency — see Known Limitations.
Products list is empty
The Vendora sandbox backend has no active draws configured for the configured store/POS.
- Confirm NUXT_VENDORA_STORE_CODE and NUXT_VENDORA_POS_CODE are correct.
- Verify that draws have been seeded in the sandbox backend.
- Contact your integration manager if the backend has no test products.
CSRF error on form submissions
The X-CSRF-Token header is missing or stale. The CSRF token is issued on the first GET request to the storefront.
- Reload the page to receive a fresh CSRF token.
- Ensure your client reads the vendora_csrf cookie and sends it as X-CSRF-Token on all POST/DELETE requests.
Known Backend Dependencies
The following capabilities require Vendora backend changes that are not yet available in Phase 1A. They are recorded here as backend dependencies and are not simulated in the sandbox.
| Feature | Status | Notes |
|---|---|---|
| GET /ticket-holds/{reference} | Backend dependency | Not available in Phase 1A. Hold state is tracked client-side by expiry time. |
| PATCH /ticket-holds/{reference} | Backend dependency | Not available. Cannot mutate an existing hold. |
| PDF sandbox watermark | Backend dependency | Vendora does not currently watermark sandbox PDFs. Production PDFs are authoritative. |
| E-ticket resend | Backend dependency | Not in Phase 1A scope. E-ticket delivery status is read-only. |
| SMS delivery status | Backend dependency | Vectramind/SMS integration not available in Phase 1A. |
| Aggregate financial reports | Backend dependency | reports:read scope not in Phase 1A. |
| Redis-backed rate limiting | Backend dependency | In-process rate limiter used for local dev. Requires hosted Redis for shared sandbox. |