> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gomry.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Credentials

> Return the admission barcodes for an order, as values Gomry renders in its own ticket

# Credentials

Returns the admission credentials for an order: the barcode values a venue scans. This is the only endpoint in the contract that carries a credential, and it is kept separate from [Fulfilment](/vendor-api/fulfilment) on purpose: fulfilment is polled and logged, this is called **once**, at delivery.

## The value, not a document

Gomry shows the buyer their barcode inside Gomry's own ticket design, and never names or implies where the ticket came from. A seller-branded PDF, or a link to one, cannot be used. Return the **barcode value itself**, decrypted if your system encrypts it, as a short opaque string.

<Warning>
  **Do not cache or log what this endpoint returns.** A barcode is the ticket. Neither Retail nor your integration keeps a copy; Retail passes it straight to the buyer's Gomry ticket. Fetch it from your system when asked, and let it go.
</Warning>

## Query Parameters

<ParamField query="vendorKey" type="string" required>
  Your supplier identifier.
</ParamField>

<ParamField query="vendorOrderId" type="string" required>
  Your order id, from [Place order](/vendor-api/place-order).
</ParamField>

Answer `404` if you do not know this order.

## Response

<ResponseField name="vendorOrderId" type="string" required>
  The order asked about.
</ResponseField>

<ResponseField name="credentials" type="array" default="[]">
  One entry per admission.

  **An empty array means "not yet", never "none".** Barcodes are often assigned only when a seller accepts, so an order can legitimately answer `[]` for hours. Retail keeps asking.

  <Expandable title="Credential object">
    <ResponseField name="barcode" type="string" required>
      The scan value itself, at most 4,096 characters. Opaque to Gomry: rendered, never parsed. Anything near that size almost certainly means the wrong field was decoded.
    </ResponseField>

    <ResponseField name="symbology" type="string" default="unknown">
      How to draw it: `qr`, `pdf417`, `aztec`, `code128`, `datamatrix`, or `unknown`. **Send `unknown` rather than guess.** A wrong guess renders a code no scanner reads, and looks perfectly fine doing it.
    </ResponseField>

    <ResponseField name="seat" type="string">
      The seat this credential admits, when your system assigns it.
    </ResponseField>
  </Expandable>
</ResponseField>

<RequestExample>
  ```bash cURL theme={null}
  curl -H "X-API-Key: $GOMRY_RETAIL_API_KEY" \
    "https://integration.example.com/api/vendor/v1/credentials?vendorKey=acme&vendorOrderId=ord_551204"
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  {
    "vendorOrderId": "ord_551204",
    "credentials": [
      { "barcode": "4417820093315502", "symbology": "pdf417", "seat": "118-12-7" },
      { "barcode": "4417820093315519", "symbology": "pdf417", "seat": "118-12-8" }
    ]
  }
  ```

  ```json 200 (not yet) theme={null}
  { "vendorOrderId": "ord_551204", "credentials": [] }
  ```
</ResponseExample>
