A multi-tenant ticketing and access-control platform — online sales, a published partner API, and door validation that cannot let the same ticket through twice.
Client
Mr. Polatidis
Type
Internal Platform
Sector
Event Management
Status
Live
Combat sports events sell thousands of tickets, and the door is where a ticketing system either works or embarrasses everyone. The original requirement was narrow: no double-scans, no counterfeit entry, live visibility for management. What the platform grew into is broader — selling the ticket as well as checking it, for more than one promoter at a time.
Venue Pass now runs as a hierarchy of tenants: the platform operator, resellers, and the promoters beneath them, each seeing only their own events. It sells tickets online under a merchant-of-record model, issues them in batches, validates them at the door from either a scanner app or a paired phone browser, and publishes a partner API for customers who want to drive it from their own systems.




A ticketing API, the surfaces that sell, the surfaces that scan, and a published contract for everyone else.
One system serving two audiences: the organiser's own dashboard, and a documented service other companies can connect their systems to, with their own keys, their own usage figures and a verified feed of what happened. Every significant decision behind it is written down.
A dashboard for organisers to create events, issue ticket batches, watch scan activity live over a streaming feed, and revoke a scanner device instantly.
A React Native scanner app paired to an admin-created device slot by a short-lived QR code — plus a browser gate, so staff on a phone with no app installed can still work the door.
The moment a ticket is scanned it is held exclusively, so two doors scanning the same code at the same instant cannot both let someone in. Reversing a scan is possible, but only for an administrator, and it is recorded.
A public ticket page and a hosted card payment, with tickets issued only once the payment is confirmed — and checked twice over, so a payment notification that arrives late or twice cannot hand out a second set of tickets.
A documented service for partners, with keys that can be scoped and revoked, per-partner usage figures, and a verified notification whenever something changes — plus a small block of code a customer can paste into their own site to list upcoming events.
Every component exists to serve one goal: valid tickets in, invalid tickets out, zero exceptions. Ten formal decision records document every significant architectural choice — the system is built to be understood, audited, and extended.
Platform Components
Security Principles
Counts from the platform repository, September 2026. Online sales run through a single payment provider.
0
Possible double-scans — by design
3
Purpose-built applications
10
Formal architecture decisions recorded
Real-time
Live gate analytics and alerts
We build systems where correctness is non-negotiable. Let's talk about your next event platform.