> ## Documentation Index
> Fetch the complete documentation index at: https://cal.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Check in a guest by scanned QR token

> Redeems a scanned check-in QR token. The token is carried in the request body, never the URL, since URLs land in history and access logs. Same access as the by-id check-in; an external co-host may also work the door. PBAC permission for team events: `calEvent.update`. If accessed using an OAuth access token, the `EVENT_WRITE` scope is required.



## OpenAPI

````yaml /api-reference/v2/openapi.json post /v2/events/{uuid}/check-ins
openapi: 3.0.0
info:
  title: Cal.com API v2
  description: ''
  version: 1.0.0
  contact: {}
servers: []
security: []
tags: []
paths:
  /v2/events/{uuid}/check-ins:
    post:
      tags:
        - Events
      summary: Check in a guest by scanned QR token
      description: >-
        Redeems a scanned check-in QR token. The token is carried in the request
        body, never the URL, since URLs land in history and access logs. Same
        access as the by-id check-in; an external co-host may also work the
        door. PBAC permission for team events: `calEvent.update`. If accessed
        using an OAuth access token, the `EVENT_WRITE` scope is required.
      operationId: EventRegistrationsController_checkInByToken
      parameters:
        - name: uuid
          required: true
          in: path
          description: >-
            Event UUID. Accepts the canonical UUID (e.g.
            `018ff5cd-6dc4-7d57-bcbc-374702ca8b38`) or its short-uuid (Flickr
            Base58) form (e.g. `1cbZYoAFoJdwqN4tixezd5`).
          schema:
            format: uuid
            type: string
        - name: Authorization
          in: header
          description: >-
            value must be `Bearer <token>` where `<token>` is api key prefixed
            with cal_, managed user access token, or OAuth access token
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CheckInByTokenInput'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CheckInOutcomeOutputResponseDto'
        '400':
          description: Invalid Event UUID, invalid token, or check-in is closed
        '401':
          description: Unauthenticated
        '403':
          description: Insufficient permissions
        '404':
          description: Event or registration not found
        '429':
          description: Rate limit exceeded
components:
  schemas:
    CheckInByTokenInput:
      type: object
      properties:
        checkInToken:
          type: string
          minLength: 1
          maxLength: 256
          description: The signed check-in token scanned from the guest's QR code.
      required:
        - checkInToken
    CheckInOutcomeOutputResponseDto:
      type: object
      properties:
        status:
          enum:
            - success
            - error
          type: string
          example: success
        data:
          $ref: '#/components/schemas/CheckInOutcomeOutputDto'
      required:
        - status
        - data
    CheckInOutcomeOutputDto:
      type: object
      properties:
        kind:
          enum:
            - checked_in
            - already_checked_in
            - not_confirmed
          type: string
        registration:
          $ref: '#/components/schemas/RegistrationOutputDto'
        checkedInAt:
          format: date-time
          type: string
          description: Set only when `kind` is `already_checked_in`.
        status:
          enum:
            - PENDING_APPROVAL
            - WAITLISTED
            - PENDING_PAYMENT
            - OFFER_EXPIRED
            - CONFIRMED
            - DECLINED
            - CANCELLED
          type: string
          description: Set only when `kind` is `not_confirmed`.
      required:
        - kind
    RegistrationOutputDto:
      type: object
      properties:
        id:
          type: string
          description: Unique identifier of the registration.
        name:
          type: string
        email:
          type: string
        phoneNumber:
          type: string
          nullable: true
        status:
          enum:
            - PENDING_APPROVAL
            - WAITLISTED
            - PENDING_PAYMENT
            - OFFER_EXPIRED
            - CONFIRMED
            - DECLINED
            - CANCELLED
          type: string
        rsvpResponse:
          enum:
            - 'YES'
            - 'NO'
            - MAYBE
          type: string
        responses:
          type: object
          nullable: true
          description: Registration-form answers.
        locationId:
          type: string
          nullable: true
        createdAt:
          format: date-time
          type: string
        checkedInAt:
          format: date-time
          type: string
          nullable: true
          description: When a door check-in was recorded.
        checkedInByUserId:
          type: number
          nullable: true
          description: Host who recorded the door check-in.
      required:
        - id
        - name
        - email
        - status
        - rsvpResponse
        - createdAt

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.