Contact

✉️

Integration Support

For technical API questions, sandbox access and credential issues.

Contact your Vendora integration manager.

🔑

Credential Compromise

If you believe a sandbox API key has been exposed:

  1. Stop using the key immediately.
  2. Do not attempt to rotate it yourself.
  3. Contact your integration manager and provide the tracing_id from any suspicious requests.
  4. Never share the key value in your report.

Using Tracing IDs

Every Vendora API response includes a tracing_id. Always include this when reporting issues — it allows the Vendora team to locate the exact request in server logs.

// Every Vendora response envelope:
{
  "tracing_id": "trace-abc12345",  ← include this in support requests
  "code":       "...",
  "errors":     [...]
}
ℹ️ If the request failed before reaching Vendora, include the X-Request-ID header value from the Nitro response instead.

Common Issues

503 / "Portal authentication is not configured"

The server is running in hosted mode (NODE_ENV != development) but NUXT_PORTAL_USERNAME and NUXT_PORTAL_PASSWORD_HASH are not set.

  • Set NUXT_PORTAL_USERNAME and NUXT_PORTAL_PASSWORD_HASH in your environment.
  • Generate a bcrypt hash with: node -e "const b=require('bcryptjs');b.hash('yourpassword',12).then(console.log)"
  • Restart the server.
401 / "Dashboard authentication required" on every request

The portal session has expired or the session cookie is missing. Sessions expire after 1 hour of inactivity.

  • Log in again at /vendor-dashboard.
  • Ensure cookies are not blocked by the browser.
  • Check that the server was not restarted (in-memory sessions are cleared on restart).
409 / "TICKET_SELECTION_UNAVAILABLE"

One or more tickets you selected were reserved by another session between your availability check and hold creation.

  • The UI will refresh the availability grid automatically.
  • Re-select from the updated availability.
  • This is normal in a concurrent sandbox environment.
410 / "HOLD_EXPIRED"

The Vendora hold expired before the sale was submitted. Holds have a limited validity window.

  • Create a new hold.
  • Complete checkout before the hold expiry countdown reaches zero.
  • The authoritative expiry is shown in the storefront cart.
502 / "The e-ticket could not be downloaded"

The Vendora API returned a non-PDF response or an error. The e-ticket may not be ready yet.

  • Check the e_ticket.status field on the transaction — it should be "SENT" before downloading.
  • If status is "QUEUED", wait a moment and try again.
  • If status is "FAILED", this is a backend dependency — see Known Limitations.
Products list is empty

The Vendora sandbox backend has no active draws configured for the configured store/POS.

  • Confirm NUXT_VENDORA_STORE_CODE and NUXT_VENDORA_POS_CODE are correct.
  • Verify that draws have been seeded in the sandbox backend.
  • Contact your integration manager if the backend has no test products.
CSRF error on form submissions

The X-CSRF-Token header is missing or stale. The CSRF token is issued on the first GET request to the storefront.

  • Reload the page to receive a fresh CSRF token.
  • Ensure your client reads the vendora_csrf cookie and sends it as X-CSRF-Token on all POST/DELETE requests.

Known Backend Dependencies

The following capabilities require Vendora backend changes that are not yet available in Phase 1A. They are recorded here as backend dependencies and are not simulated in the sandbox.

FeatureStatusNotes
GET /ticket-holds/{reference}Backend dependencyNot available in Phase 1A. Hold state is tracked client-side by expiry time.
PATCH /ticket-holds/{reference}Backend dependencyNot available. Cannot mutate an existing hold.
PDF sandbox watermarkBackend dependencyVendora does not currently watermark sandbox PDFs. Production PDFs are authoritative.
E-ticket resendBackend dependencyNot in Phase 1A scope. E-ticket delivery status is read-only.
SMS delivery statusBackend dependencyVectramind/SMS integration not available in Phase 1A.
Aggregate financial reportsBackend dependencyreports:read scope not in Phase 1A.
Redis-backed rate limitingBackend dependencyIn-process rate limiter used for local dev. Requires hosted Redis for shared sandbox.