How Hot Project Detection Influences the Ticket Buying Strategy in biliTickerBuy

biliTickerBuy detects high-demand events by monitoring the hotProject field in the project payload, then dynamically switches to an enhanced ticket buying strategy that generates additional security tokens (ctoken) to satisfy stricter anti-bot checks imposed by Bilibili on popular concerts.

biliTickerBuy is an open-source automation tool designed to purchase tickets on Bilibili (B站) for concerts and live events. When the system identifies a hot project—a high-traffic event with elevated anti-scraping protections—it modifies the ticket buying strategy to improve success rates against the platform's stricter rate-limiting measures.

Detecting Hot Projects in Real-Time

The detection logic resides in task/buy.py within the refresh_hot_and_warm() function. When the buy stream initializes, the code fetches the latest project payload and inspects the hotProject field.


# task/buy.py – hot-project detection

payload = fetch_project_payload(request=_request,
                                project_id=int(tickets_info["project_id"]))
if bool(payload["hotProject"]) and not is_hot_project:
    is_hot_project = True                              # ← turn on hot mode

    tickets_info["is_hot_project"] = True
    logger.info("预热/复检:检测到 hotProject=True,已升级为 hot 抢票策略")

If payload["hotProject"] evaluates to True and the internal flag is_hot_project is currently False, the system upgrades the session to hot mode. This boolean is then stored in the tickets_info dictionary, ensuring the remainder of the buying run recognizes the elevated security context.

Propagating the Hot Project Flag

Once detected, the is_hot_project boolean propagates through the call stack to the request builder. In task/buy_helpers.py, the _prepare_create_request() function receives this flag as a parameter to determine payload construction.


# task/buy_helpers.py – _prepare_create_request receives the flag

url, payload = _prepare_create_request(
    tickets_info, order_token,
    is_hot_project=is_hot_project,   # ← hot flag

    request_result, ticket_state)

This propagation ensures that low-level HTTP request generators can access the hot project state when building the final purchase request.

Adjusting the Request Payload for Hot Events

The core strategy difference lies in token generation. For hot projects, the client must embed a freshly generated ctoken (and associated ptoken) to satisfy Bilibili's enhanced anti-bot verification. While the implementation currently generates tokens for all requests, the source code contains commented logic showing the intended branching behavior.


# task/buy_helpers.py – payload preparation (comment shows the intended branching)

# if not is_hot_project:

#     return url, payload          # ← simple path for normal projects

create_state = sim_ctoken_state(...)
payload["ctoken"] = create_state.generate_create_ctoken()

Normal projects could theoretically use a simplified payload without the additional ctoken. Hot projects require the full token generation sequence to bypass the stricter security layers that Bilibili applies to high-demand events.

Persisting State for UI Synchronization

The hot project flag persists beyond the immediate buying session to keep the user interface synchronized. In interface/project.py, the flag is stored within each ticket option, while tab/settings.py reflects the state in the Settings tab.


# tab/settings.py – keep UI in sync

ticket["is_hot_project"] = is_hot_project

Users can also manually override the hot project status through the Settings UI, forcing the application to adopt the enhanced strategy regardless of the API response.


# In the Settings UI (tab/settings.py) you can toggle hotProject manually

data = {"hotProject": True}

# The UI updates the global flag

global is_hot_project
is_hot_project = data["hotProject"]

Summary

  • Detection occurs in task/buy.py via refresh_hot_and_warm(), which checks the hotProject field from fetch_project_payload().
  • State management stores the boolean in tickets_info["is_hot_project"] for runtime awareness.
  • Request adaptation passes the flag to _prepare_create_request() in task/buy_helpers.py to trigger enhanced token generation.
  • Security tokens (ctoken) are required for hot projects to bypass stricter anti-bot measures.
  • UI synchronization keeps the user informed via interface/project.py and tab/settings.py.

Frequently Asked Questions

How does biliTickerBuy detect if a project is "hot"?

The system calls refresh_hot_and_warm() in task/buy.py to fetch the project payload via fetch_project_payload(). It checks the boolean field hotProject in the returned JSON. If True, the internal is_hot_project flag is set to True and logged as an upgrade to the hot buying strategy.

What is the difference between hot and normal project ticket buying?

For normal projects, the client could theoretically send a simpler order request without additional security tokens. For hot projects, the strategy requires generating a fresh ctoken using sim_ctoken_state() and embedding it in the payload to satisfy Bilibili's enhanced anti-scraping verification for high-demand events.

Can I manually mark a project as hot in the UI?

Yes. The Settings tab (tab/settings.py) allows manual toggling of the hotProject flag. When you set data["hotProject"] to True, the UI updates the global is_hot_project variable, forcing the application to use the enhanced request strategy regardless of the API's hot status.

Why do hot projects require additional tokens like ctoken?

Bilibili applies stricter rate-limiting and anti-bot measures to popular concerts and high-traffic events. The ctoken acts as a cryptographic proof-of-work or session validation token that demonstrates the client is a legitimate browser rather than a simple scraping script, significantly improving the chances of successfully creating an order.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →