Post, edit or retract the donor's note
Writes the note a donor leaves on their receipt, which appears in the campaign's comments. The receipt id is the authorisation — guest donors have no session — and the donation must be paid and to a campaign. A missing, unpaid or person-targeted donation gets the same 404.
Each donation allows 3 writes in total (post, edits and retract combined); after that every write is 429. Read the current note with the GET first so a reload does not spend one. The note is attributed to an account only when the caller is signed in as the donor.
Authentication is optional. Behind features.comments. Rate limited at 5 requests/minute per IP.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Parameters
Path Parameters
The receipt id, or the donation's Stripe PaymentIntent id.
Request Body
Responses
Note retracted