> ## Documentation Index
> Fetch the complete documentation index at: https://docs.way.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate access code

> Validates an access code that unlocks gated listings.



## OpenAPI

````yaml post /v1/brands/{brandId}/access-codes/{accessCode}/validate
openapi: 3.0.0
info:
  title: Way Partner API
  description: >-
    REST API for Way partners: list experiences, check availability, run
    checkout, and manage bookings.
  version: '1.0'
servers:
  - url: https://api.letsway.com
    description: Production.
  - url: https://api.staging.letsway.com
    description: Staging.
security: []
tags:
  - name: Listings
    description: 'Retrieve the listings a brand offers: experiences, events, and resources.'
  - name: Availability
    description: Dates, sessions, and price tiers for scheduling a booking.
  - name: Carts & Checkout
    description: >-
      Payment intents and booking creation. The cart ID is a client-generated
      UUID; there is no create-cart endpoint.
  - name: Bookings
    description: Retrieve, cancel, and reschedule bookings.
  - name: Experiences
    description: Experience details, settings, custom questions, reviews, and hosts.
  - name: Brand Configuration
    description: Brand settings, taxonomy, terms, and promotion code validation.
  - name: Waitlists
    description: Waitlists for sold-out sessions and invitation handling.
  - name: Integrations
    description: Configured integrations, analytics, and room-charge validation.
  - name: Organizations
    description: Organization-level access across brands.
paths:
  /v1/brands/{brandId}/access-codes/{accessCode}/validate:
    post:
      tags:
        - Brand Configuration
      summary: Validate access code
      description: Validates an access code that unlocks gated listings.
      operationId: AccessCodePublicController_validateAccessCode
      parameters:
        - $ref: '#/components/parameters/brandIdPath_65'
        - $ref: '#/components/parameters/accessCodePath'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AccessCodeValidateRequest'
      responses:
        '201':
          description: Validate access code.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidAccessCodeDetailsDto'
      security:
        - Brand-API-Key: []
        - Organization-API-Key: []
components:
  parameters:
    brandIdPath_65:
      name: brandId
      in: path
      schema:
        type: string
      required: true
      description: >-
        The brand's ID - must match the brand your API key identifies (or the
        Way-Brand-Id header when one is sent).
    accessCodePath:
      name: accessCode
      in: path
      schema:
        type: string
      required: true
      description: The access code to validate, as entered by the guest.
  schemas:
    AccessCodeValidateRequest:
      type: object
      properties: {}
    ValidAccessCodeDetailsDto:
      type: object
      properties:
        id:
          type: string
          description: Unique identifier for the access code.
          example: access-code-123e4567-e89b-12d3-a456-426614174000
        name:
          type: string
          description: Name of the access code.
          example: Awesome Access Code
        code:
          type: string
          description: Code of the access code.
          example: '12345'
      required:
        - id
        - name
        - code
  securitySchemes:
    Brand-API-Key:
      type: http
      scheme: bearer
      description: >-
        Your brand's secret API key, e.g. `Bearer
        way_sk_live_bhEqcn0i1fRoUEHBPjJkQA`. Older `Way-Brand-Id` +
        `Way-Secret-Key` credentials still work: see [Legacy
        authentication](/legacy-authentication).
    Organization-API-Key:
      type: http
      scheme: bearer
      description: >-
        Your organization's secret API key, e.g. `Bearer
        way_sk_live_ohEqcn0i1fRoUEHBPjJkQA`. Older `Way-Organization-Id` +
        `Way-Secret-Key` credentials still work: see [Legacy
        authentication](/legacy-authentication).

````