Dragonpass API Developer Platform
v2
  • v2
  • v1
API Doc
PlaygroundShare FeedbackDragonPassContact Us
API Doc
PlaygroundShare FeedbackDragonPassContact Us
API Version
v2
  • v2
  • v1
v2
  • v2
  • v1
  1. Development Guide
  • Implementation Guide
    • Get Started
    • Our API Solution
    • Dragonpass Modules
  • Development Guide
    • Authentication
    • Response Format
    • Error Codes
    • Order Lifecycle
    • Multiple Language Support and Fallback
    • Sandbox Order Simulation
    • UI Design Guidelines
  • Using the API
    • Search for Resources
      • Search for Resources
      • Check Prebooking Resource & Option Availability
      • Pricing Query
      • Image Parameters
    • E-pass
      • Issuing, Querying, and Cancelling an E-pass
      • Querying E-pass Usage Orders and Details
      • Utilizing The E-pass
        • Cross Module
        • Lounge
        • Fast Track
        • Dining
        • Fitness
        • eSIM
        • Local Offer
    • Membership
      • Manage Memberships & Entitlements
      • Querying Membership Usage Orders and Details
      • Utilizing Dragonpass Membership
        • Lounge
        • Dining
        • Fast Track
        • Fitness
        • eSIM
    • User
      • User Management
  • Push Event
    • Instructions
    • Lounge/Dining Walk-in Redemption Event
    • Prebooking Order Status Change Event
    • Resource Update Push Service
  • Release Notes
    • 2026
    • 2025
  • Migration Guide
    • From V1 to V2
  • API Reference
    • Authentication
      • Generate Access Token
    • Search
      • Aggregated Search by Keyword
      • Retrieve Available Modules by Location
    • Transport Hubs
      • Retrieve Transport Hub
      • Retrieve Transport Hub Details
    • Resources
      • Resource List
        • Retrieve Resources List
      • Resource Details
        • Retrieve Resource Details
      • Check Resource Availability
        • Check Prebooking Resource Availability
        • Check Prebooking Option Availability
      • Fitness
        • Retrieve Fitness Resource Option Details
        • Retrieve Fitness Resources Schedule
      • eSIM
        • Retrieve eSIM Resources Options
        • Retrieve eSIM Resource Option Details
      • Local Offer
        • Retrieve Local Offer Resouces Options
        • Retrieve Local Offer Resource Option Details
    • Pricing
      • Retrieve Resource Pricing Information
      • Retrieve Prebooking Option Pricing Information
    • User Management
      • User Creation
      • Update User Information
      • Delete a User
      • Retrieve User Information
      • Retrieve User Memberships List
      • Retrieve User E-passes List
    • E-pass
      • E-pass Management
        • Create E-pass Order
        • Retrieve E-pass Details
        • Cancel an E-pass
      • Orders & Usage
        • Create Orders
          • Lounge Prebooking
            • Create E-pass Prebooking Order - Lounge
            • Create E-pass with Prebooking Order - Lounge
          • Fast Track
            • Create E-pass Prebooking Order - Fast Track
            • Create E-pass with Prebooking Order - Fast Track
          • Fitness
            • Create E-pass Prebooking Order - Fitness
            • Create E-pass with Prebooking Order - Fitness
          • Local Offer
            • Create E-pass Prebooking Order - Local Offer
            • Create E-pass with Prebooking Order - Local Offer
          • eSIM
            • Create E-pass Prebooking Order - eSIM
            • Top up eSIM Data package - E-pass
            • Create E-pass with Prebooking Order - eSIM
        • Retrieve Order List
          • Retrieve E-pass Order List
        • Usage Details
          • Retrieve E-pass Usage Order Details
        • Cancel Orders
          • Cancel an Order
        • Module Specific APIs
          • Fitness
            • Fitness Order Check-In
          • eSIM
            • Retrieve eSIM Data Packages
            • Check eSIM Top-up Availability
            • Retrieve eSIM Order Live Extended Details
    • Membership & Entitlement
      • Membership Lifecycle
        • Membership Registration
        • Update a Membership
        • Retrieve Membership Information
        • Generate Membership Dynamic QR Codes
      • Entitlement Management
        • Update Membership Entitlements
        • Retrieve Membership Entitlement Information
      • Orders & Usage
        • Preview Orders
          • Preview Membership Prebooking Order
        • Create Orders
          • Create Membership Prebooking Order - Lounge
          • Create Membership Prebooking Order - Fast Track
          • Create Membership Prebooking Order - Fitness
          • Create Membership Prebooking Order - eSIM
          • Top up eSIM Data package - Membership
          • Create Membership Prebooking Order - Local Offer
        • Cancel Orders
          • Cancel an Order
        • Retrieve Order List
          • Retrieve Membership Order List
        • Usage Details
          • Retrieve Membership Usage Order Details
        • Module Specific APIs
          • Fitness
            • Fitness Order Check-In
          • eSIM
            • Retrieve eSIM Order Live Extended Details
            • Check eSIM Top-up Availability
            • Retrieve eSIM Data Packages
    • Push Event Recovery
      • Push Event Recovery
    • [Sandbox Only] Simulation
      • Lounge
        • Simulate Lounge Redemption - Walk in
        • Simulate Lounge Redemption - Prebooking
        • Simulate Lounge Order Cancellation
      • Fast Track
        • Simulate Fast Track Redemption - Prebooking
        • Simulate Fast Track Order Cancellation
      • Set Meal
        • Simulate Set Meal Redemption - Walk in
        • Simulate Set Meal Order Cancellation
      • Coupon
        • Simulate Dining Coupon Redemption - Walk in
        • Simulate Dining Coupon Order Cancellation
    • SSO
      • Create SSO Link
    • Payment
      • Order Payment
  • FAQ
  • Our Team
  1. Development Guide

Authentication

Our API uses JSON Web Tokens (JWT) for secure authentication, providing efficient and reliable access while maintaining strong security standards.
To generate a JWT, you'll need to use a library that supports JWT creation and validation. You can visit jwt.io to find libraries and examples specific to your programming environment.
Please ensure that you securely store the secret key and do not expose it in your client-side code.
We recommend transitioning from HS256 to RS256 for enhanced security. We also suggest that clients provide their public key for verification purposes.

Credential Management and Rotation#

Credentials are managed at the permission-group level. Each permission group supports a maximum of two credentials at the same time.
For E-Pass, one permission group maps to one Program ID.
For Membership, one permission group may map to multiple Program IDs.
The two credentials may use different algorithms. For example, one credential may use HS256 while the other uses RS256.

Credential Validity and Rotation#

Each credential has a configurable validity period. The Dragonpass API platform supports seamless credential rotation without service interruption.
Customers that rotate credentials regularly can activate a new credential before the current credential expires. During the transition period, both credentials remain valid in parallel, allowing traffic to be migrated to the new credential before the previous credential is retired.
Rotation.png
Do not use a credential after its validity period has ended.

JWT Payload#

Every JWT must include iss, keyid, and exp.
{
  "iss": "YOUR_ISSUER",
  "keyid": "key_0001_20260101_20261231_a",
  "exp": 1718236800
}
iss: The issuer value provided during account setup.
keyid: Identifies the credential used to sign the JWT.
exp: A Unix timestamp indicating when the JWT expires.
Key ID Format
key_{projectId}_{validFrom}_{validUntil}_{credentialSlot}
key_0001_20260101_20261231_a
Where:
{tenantId} is the project identifier.
{validFrom} is the start of the credential validity period.
{validUntil} is the end of the credential validity period.
{credentialSlot} is a or b, identifying one of the two credentials available to the permission group.

RS256 (Recommended)#

Account Setup and Credential Generation#

Once you're ready to connect to our sandbox environment, you will be required to generate an RSA key pair and share the public key with Dragonpass.
Once Dragonpass receives the public key, we will configure the necessary endpoint permissions and issue the issuer value for the client to use when generating JWTs.

Key Exchange Flow#

Example: Generate RSA Key Pair Using OpenSSL#

Here is an example of generating an RSA key pair
Note: iss (issuer) will be provided by Dragonpass. exp (expiration) should be a Unix timestamp indicating when the token expires.

HS256#

Clients currently utilizing HS256 for JWT authentication may continue using this algorithm without service interruption. Dragonpass will engage with each client to coordinate an update plan and timeline for transitioning to the RS256 algorithm, in alignment with enhanced security standards.

JWT Self-Generation#

Once your JWT library is set up, you can generate your own token by including the required claims and signing it using your secret key.
The payload typically includes the following claims:
{
  "iss": "YOUR_ISSUER",
  "keyid": "key_0001_20260101_20261231_a",
  "exp": 1718236800
}

Example Snippet (Java)#

Token Generation via API#

Alternatively, you can request a token directly from our API using your credentials.
Call the Generate Access Token endpoint and include your clientId (issuer) and secret in the request body.
Request
{
    "clientId": "Dragonpass", // issuer
    "secret": "dpSecretKey12345"
}
Response
{
  "code": 0,
  "data": {
    "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
    "tokenType": "Bearer",
    "validUntil": 1923263999
  }
}
The returned token is valid for 1 hour.
Modified at 2026-09-01 08:18:27
Previous
Dragonpass Modules
Next
Response Format