developer

Event Ticketing: Build a Custom Ticket Portal with Direct UPI Confirmation

Learn how to build a custom event ticketing portal with direct UPI payments, QR entry passes, zero gateway fees, and automated sub-500ms webhook confirmations.

GS Gaurav Sharma Event Tech & Systems Architect 2 min read
Event Ticketing: Build a Custom Ticket Portal with Direct UPI Confirmation guide
event ticketing upi payment gateway sell event tickets upi zero fee custom ticket portal webhook event tech architecture dynamic qr passes

From music festivals and tech conferences to regional comedy shows and sports tournaments, live events are thriving across Indian metros.

However, event producers and independent creators face a major financial penalty: centralized ticketing platforms (like BookMyShow and Paytm Insider) extract 8% to 15% in platform commissions, levy heavy “internet handling fees” that irritate fans, and hold all ticket revenue in escrow until the show concludes.

Building your own custom event ticketing portal with direct UPI payments eliminates intermediary platform cuts, delivers real-time ticket revenue to your bank account, and preserves direct relationships with your attendees.


The High Cost of Traditional Ticketing Platforms

When selling out a 2,000-person concert or conference, the fees paid to ticketing aggregators are substantial:

Economics of a 2,000-Attendee Music Festival:
Ticket Price:                                  ₹ 1,500
Total Gross Box Office (2,000 Tickets):        ₹ 30,00,000 (30 Lakhs)
Platform Commission (10%):                   - ₹  3,00,000
18% GST on Commission:                       - ₹    54,000
Payment Processing Cut (2% + GST):           - ₹    70,800
------------------------------------------------------
TOTAL REVENUE LOST TO TICKETING PLATFORM:     ₹  4,24,800

Losing over ₹4.2 Lakhs on a single show reduces the budget available for venue acoustics, artist riders, and stage lighting.


High-Concurrency Ticket Sales Architecture

When a popular artist announces tickets, thousands of buyers rush to checkout within the first 10 minutes. Monolithic databases often deadlock under the load.

To prevent overselling and eliminate gateway fees, use a Redis Seat Lock + Direct UPI Intent architecture:

[User selects VIP Ticket] ──► [Redis locks seat for 8 minutes: `SETNX lock:VIP:user123`]
                                      │
                                      ▼
             [VyaparGateway Engine creates Dynamic UPI Order]
                                      │
       ┌──────────────────────────────┴──────────────────────────────┐
       │ Mobile: Launches GPay / PhonePe / Paytm directly via Intent │
       │ Desktop: In-Page Dynamic QR Code                            │
       └──────────────────────────────┬──────────────────────────────┘
                                      │ (User approves payment)
             [Bank Account Credited in Real-Time (Instant T+0)]
                                      │
                                      ▼
             [Bank Webhook confirms UTR: Seat converted from "LOCKED" to "SOLD"]
                                      │
             [Signed QR Pass generated and WhatsApped to attendee in 2 secs]

Generating Cryptographic QR Entry Passes

To ensure that attendees cannot duplicate or photoshop tickets, encode ticket data using HMAC SHA-256 or asymmetric ED25519 signatures:

Ticket Payload:
{
  "ticketId": "TKT-8904",
  "eventId": "FEST-2026",
  "attendee": "Kabir Mehta",
  "tier": "VIP_ALL_ACCESS",
  "utr": "609415892014",
  "sig": "e7b9...8a12"
}

The resulting JSON payload is converted into a standard QR code and rendered onto the PDF ticket pass.


Ticket Engine & Webhook Implementation (Node.js)

Here is the server implementation that validates the incoming bank payment and issues a verified digital ticket pass:

import { Request, Response } from "express";
import crypto from "crypto";
import QRCode from "qrcode";

export async function handleTicketPaymentWebhook(req: Request, res: Response) {
  const signature = req.headers["x-vyapar-signature"] as string;
  const rawBody = JSON.stringify(req.body);

  // 1. Verify Webhook Signature
  const expectedSig = crypto
    .createHmac("sha256", process.env.VYAPAR_SECRET!)
    .update(rawBody)
    .digest("hex");

  if (signature !== expectedSig) {
    return res.status(401).json({ error: "Invalid signature" });
  }

  const { status, orderId, utr, amount, metadata } = req.body;

  if (status === "SUCCESS") {
    const { eventId, attendeeName, attendeeEmail, tier } = metadata;

    // 2. Generate Cryptographically Signed Pass Token
    const ticketPayload = JSON.stringify({
      orderId,
      eventId,
      attendeeName,
      tier,
      utr,
      issuedAt: Date.now()
    });

    const ticketSignature = crypto
      .createHmac("sha256", process.env.TICKET_SIGNING_KEY!)
      .update(ticketPayload)
      .digest("hex");

    const signedTicketData = JSON.stringify({
      payload: JSON.parse(ticketPayload),
      signature: ticketSignature
    });

    // 3. Generate QR Code Image Buffer for Entry Pass
    const qrDataUrl = await QRCode.toDataURL(signedTicketData, { width: 320 });

    console.log(`Ticket #${orderId} generated for ${attendeeName} (UTR: ${utr})`);

    // Dispatch Email / WhatsApp Ticket Pass with embedded QR
    // await sendTicketPass({ email: attendeeEmail, qrDataUrl, attendeeName });

    return res.status(200).json({ status: "TICKET_ISSUED", orderId });
  }

  res.sendStatus(200);
}

Gate Scanning & Fraud Prevention at Venues

At the venue entrance gate, volunteer scanners run an offline-capable Progressive Web App (PWA):

  1. Camera Scans QR Pass: Reads the payload and validates the cryptographic signature locally without needing internet connectivity.
  2. Local Redis / SQLite Check: Flags whether the ticketId has already been scanned.
  3. Green Light / Red Buzzer: Displays attendee name and tier, immediately invalidating the pass for subsequent entries.

By taking ownership of your ticketing infrastructure with VyaparGateway, you eliminate third-party commission cuts, receive ticket revenues instantly into your operating account, and build a permanent direct audience list for future tours.

Direct answers

Frequently asked questions

Why do event organizers build custom ticketing portals instead of using BookMyShow or Paytm Insider?
Ticketing aggregators charge 8% to 15% platform commissions plus 'convenience fees', retain attendee email lists for competitor promotions, and withhold ticket revenue until days after the event concludes.
How does direct UPI handle high-concurrency ticket drops (flash sales)?
By using temporary Redis seat locks and direct banking rails via VyaparGateway, thousands of concurrent buyers receive unique Dynamic UPI intent links without crashing checkout databases or triggering third-party rate limits.
How are tickets verified at the venue gate to prevent duplicate entries?
Each issued ticket contains a signed JWT payload rendered as a high-density QR code. Volunteer gate scanners verify the cryptographic signature offline or against an on-premise local server, marking each pass 'SCANNED' instantly.

Build your payment flow

Explore the API and browser-only merchant tools.

Create UPI checkout orders, verify signed events, or test the free calculators and generators without exposing credentials.