# konfetti > konfetti (Konfetti GmbH, Berlin) operates a marketplace for bookable experiences — cooking classes, pottery and ceramics workshops, cocktail courses, tastings, boat tours, creative and craft workshops, DIY kits and team events — across Germany and Austria. More than 7,600 experiences are listed, covering Berlin, Munich, Cologne, Hamburg, Frankfurt, Stuttgart, Dusseldorf, Leipzig, Dresden, Hannover, Nuremberg, Muenster, Heidelberg and Vienna. Alongside the consumer storefront, konfetti sells an all-in-one booking-management product to partner hosts: a back-office for managing experiences, dates, tickets, gift cards, invoicing and payouts, plus an embeddable booking solution and marketing widgets. konfetti is backed by Speedinvest. Generated: 2026-07-19 Method: generated by API Evangelist from apis.yml and the artifacts in this repository. konfetti publishes no llms.txt of its own (https://gokonfetti.com/llms.txt returns 404). ## Important context for agents konfetti publishes **no developer portal, no API reference and no OpenAPI document**. A JSON API does exist at `https://api.gokonfetti.com/v1` and its public catalog endpoints answer without credentials, but it is an internal interface serving konfetti's own storefront. There are no published terms of use covering programmatic access, no rate limits, no versioning policy beyond a `/v1` path prefix, no deprecation policy, no status page and no developer support channel. The specification in this repository is an honest reconstruction from live probing, not a provider-published contract. Treat it as research material and contact hallo@gokonfetti.com before building anything on it. ## Company - [konfetti storefront](https://gokonfetti.com): The consumer marketplace; browse experiences by city, category and occasion. - [Partner page](https://gokonfetti.com/de-de/partner/): What konfetti sells to hosts — booking management, ticket and gift-card sales, marketing reach, automated invoicing and monthly payouts, the embeddable booking solution, and the pricing tiers. - [Partner back-office](https://backoffice.gokonfetti.com): Where partner hosts sign in to manage their experiences and bookings. - [Help centre](https://help.gokonfetti.com): Consumer support — courses, vouchers, rebooking, payment, cancellations. No developer content. - [Magazine](https://gokonfetti.com/de-de/magazine/): Content marketing — gift guides, how-tos, occasion planning. - [FAQ](https://gokonfetti.com/de-de/faq/) - [Legal notice / Impressum](https://gokonfetti.com/de-de/impressum/): Konfetti GmbH, Wrangelstrasse 100, 10997 Berlin. Amtsgericht Charlottenburg HRB 229242 B. VAT DE344165820. Managing directors Tobias Fezer and Wolfgang Mauer. - [Terms and conditions](https://gokonfetti.com/de-de/terms-and-conditions/) - [Privacy policy](https://gokonfetti.com/de-de/privacy-policy/) - [Accessibility declaration](https://gokonfetti.com/de-de/b2c/accessibility-declaration/) - [Careers](https://join.com/companies/gokonfetti) - [Press](https://konfetti.notion.site/Pressebereich-konfetti-8ba576a989014ac9a6976509ab633332) ## API (observational) - [OpenAPI specification](openapi/konfetti-store-openapi.yml): 21 paths reconstructed from live probes of api.gokonfetti.com and from konfetti's own published frontend bundles. Every status code recorded was observed. - [Overlay](overlays/konfetti-store-overlay.yaml): API Evangelist annotations — provenance warnings, per-operation stability flags, and the integration traps. - [Authentication](authentication/konfetti-authentication.yml): Public unauthenticated catalog reads; Bearer tokens for checkout and profile; an OAuth 2.0 token endpoint at `/v1/oauth/token` with no documented client-registration path for third parties. - [Conventions](conventions/konfetti-conventions.yml): Pagination, relation includes, the l5-repository filter grammar, locale negotiation, money representation, request tracing, and the absence of idempotency and rate-limit signalling. - [Error catalog](errors/konfetti-problem-types.yml): The bespoke Apiato error envelopes. Not RFC 9457. Authentication failure arrives as a 302 redirect, not a 401. - [Data model](data-model/konfetti-data-model.yml): The entity graph — suppliers publish experience descriptions, which have scheduled instances, categories, addresses, reviews and photos; customers place orders and redeem coupons and gift cards. - [Conformance](conformance/konfetti-conformance.yml): Which standards the API actually meets. Pagination and ISO 8601/4217 yes; RFC 9457, RFC 8414, OpenID Connect, security.txt, idempotency and rate-limit headers no. - [Lifecycle](lifecycle/konfetti-lifecycle.yml): No versioning policy, no deprecation policy, no changelog, no status page, no SLA — each checked, not assumed. ## Integration surfaces - [Components](components/konfetti-components.yml): The embeddable booking solution and five widgets (badge, general banner, partner banner, reviews by partner, reviews by event), served as konfetti-hosted pages under `/{locale}/widgets/{widget}/{id}/`. - [Widget index](https://gokonfetti.com/en-us/widgets/all-widgets/): konfetti's own listing of the embeddable widgets. - [Packages](packages/konfetti-packages.yml): None. konfetti ships no SDK in any language and operates no public GitHub organization — recorded after checking npm, PyPI, Maven Central, NuGet, pkg.go.dev, RubyGems, Packagist and crates.io. ## Agent surfaces - [Agent skills index](skills/_index.yml): Two read-only skills over the public catalog. - [Search experiences](skills/konfetti-search-experiences.md): Browse and filter the catalog, page through results, read an experience in full. - [Supplier catalog](skills/konfetti-supplier-catalog.md): Pivot from one experience to a partner host's whole catalog, pricing range, review standing and competitive neighbourhood. - [MCP server design](mcp/konfetti-mcp.yml): konfetti operates no MCP server; this is a candidate tool surface covering only the safe read operations. ## Security - [Domain security](security/konfetti-domain-security.yml): TLS 1.3 across all hosts; SPF and DMARC present (policy: quarantine); no HSTS, no DNSSEC, no CAA records. - [Well-known URIs](well-known/konfetti-well-known.yml): None published. No security.txt, no OpenID discovery, no OAuth authorization-server metadata despite a live OAuth token endpoint, no api-catalog, no ai-plugin.json. - No vulnerability disclosure programme, bug bounty, trust centre or published certification (SOC 2, ISO 27001, PCI DSS) was found. ## Optional - [Speedinvest](https://www.speedinvest.com): konfetti's investor. - [LinkedIn](https://www.linkedin.com/company/72680824/) - [Instagram](https://www.instagram.com/gokonfetti/) - [Facebook](https://www.facebook.com/gokonfetti/) - [Pinterest](https://de.pinterest.com/gokonfetti/)