Skip to main content

Access Control Integration

Connect your venue access control system with SECUTIX to manage ticket validation at entry points. The integration follows a list-based pattern: your access control backend periodically downloads ticket lists (whitelists and blacklists) from SECUTIX, pushes them to your gate devices, and after events, reports scan results back to SECUTIX for business intelligence, attendance tracking, and real-time venue filling monitoring.

This architecture covers the full lifecycle — from initial setup, through periodic ticket list synchronization, to scan result reporting. Scan results are typically reported in real time to enable live venue filling tracking on the seatmap, though batch reporting after events is also supported.

Example use cases​

  • Keep access control systems up to date with last-minute sales, cancellations, and transfers as the event approaches.
  • Report scan results in real time to drive live venue-filling tracking on the seatmap, onsite support processes and to allow to apply business rules to avoid ticket misuse (transfers, reprints, etc.).

Architecture Overview​

Access Control Integration Architecture

[UPCOMING] Integration Steps​

The endpoints described below are under active development and not yet available for production use. To integrate today, follow the same flow with the currently available APIs described further down.

The numbered steps below correspond to the flows shown in the architecture diagram.

  1. Setup — Before any data flows, configure the integration between your access control system and the SECUTIX platform. This includes:

  2. Export Ticket Lists (Whitelist / Blacklist) — Your access control backend periodically calls POST /s360/v3/tickets/access/ticketlists to download the list of valid (allowed) and/or invalid (denied) tickets with their barcodes and additional details.

    • Polling frequency: Adjust the synchronization frequency based on the proximity to the event date. Far from the event, once per day or once per hour is sufficient. As the event approaches, increase to every few minutes or even every minute to capture last-minute sales, cancellations, and transfers. See Rate Limits for details.
    • See the Export Ticket List API Reference for the full request/response specification.
  3. Synchronize to Devices — After downloading the ticket lists from SECUTIX, your access control backend pushes the whitelists and blacklists to your physical gate devices (turnstiles, handheld scanners, etc.). The format and protocol for this step depend on your device vendor — SECUTIX is not involved in this internal synchronization. All tickets — including dematerialized ones (RFID cards) — are identified by barcode.

  4. Scan & Collect — At event time, your devices scan ticket barcodes and make local access decisions based on the downloaded whitelists/blacklists. Scan results (accepted, rejected, failure reason) are collected by your access control backend. Devices that operate offline store scan results locally until connectivity is restored.

  5. Report Scan Results (Import Ticket Checks) — Your access control backend calls POST /s360/v3/tickets/access/controls to report scan results back to SECUTIX. Each scan record includes the barcode, timestamp, flow direction (IN/OUT), and the control outcome. — it enables live venue filling tracking on the seatmap and ticket status update in TIXNGO App. See the Import Ticket Checks API Reference for the full request/response specification.


Integrating Today — Current Access Control APIs​

Until the endpoints above are released, the same list-based flow is already available through the current SECUTIX Access Control APIs:

👉 Access Control API documentation

The architecture is identical — only the transport and message format differ.


Usage Plan​

This integration pattern maps to the ACCESS_CONTROL usage plan (BASIC tier only: 2 req/s, 10K daily quota). See Rate Limits for full details.