Get a visitor
/visitors/{visitor_id}Returns one visitor record. To see their visits, call GET /visits?visitor_id=….
In live mode, a visitor whose visits are all hidden by your plan's visitor history returns plan_required.
Scope: visitors:read · Plan: Pro and Enterprise in live mode; every plan in test mode.
Send Authorization: Bearer <token> on every request. The token is one of:
| Prefix | What it is | Where it may be used |
|---|---|---|
agoo_sk_live_ | Secret key, live mode | Your servers only |
agoo_sk_test_ | Secret key, test mode | Your servers only |
agoo_pk_live_ | Publishable key, live mode | Browsers and apps: create pre-registrations and bookings, read public booking types (with their intake questions) and their free slots, read the visit types open for pre-registration with their public forms. Never lists people. |
agoo_pk_test_ | Publishable key, test mode | As above, in test mode |
Admins create keys in Console → Developers → API keys and choose each key's scopes. A key is shown once. Never put a secret key in a URL, a browser or a mobile app.
In: header
Scope: visitors:read
Path Parameters
The visitor's ID.
^visitor_[0-7][0-9a-hjkmnp-tv-z]{25}$"visitor_01krdtb870fxj8t6ntdtcxwdk5"Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/visitors/visitor_01krdtb870fxj8t6ntdtcxwdk5"{ "id": "visitor_01krdtb870fxj8t6ntdtcxwdk5", "name": "Ama Owusu", "phone": "+233241234567", "email": "ama@coastline.example", "company": "Coastline Consult", "id_document": { "type": "ghana_card", "last4": "7253" }, "visit_count": 6, "first_visit_at": "2026-05-12T10:05:00Z", "last_visit_at": "2026-10-14T09:31:02Z", "created_at": "2026-05-12T10:05:00Z", "updated_at": "2026-10-14T09:31:02Z"}List visitors GET
Returns visitor records, newest first. A visitor record holds one person's details across all their visits; Agoo matches returning visitors by phone number. ID document numbers are never returned in full. In live mode, a visitor whose visits are all hidden by your plan's visitor history is left out. The record is kept, not deleted, and comes back if you move to a plan with a longer history. **Scope:** `visitors:read` · **Plan:** Pro and Enterprise in live mode; every plan in test mode.
Erase a visitor DELETE
Permanently erases a visitor's personal data, for example to act on an erasure request under the Data Protection Act, 2012 (Act 843). This can't be undone. - Agoo removes the visitor's name, contact details, photo, ID document details and custom field answers from the visitor record and all their visits. The visits stay, without personal data, so your counts and the audit trail remain whole. - Fires `visitor.erased`. Later calls for this visitor return `not_found`. - Works on visitors and visits hidden by your plan's visitor history too, so an erasure request is always complete. - Returns `invalid_state` if the visitor is checked in right now or their data is under a legal hold. **Scope:** `visitors:delete` · **Plan:** Pro and Enterprise in live mode; every plan in test mode.