Postman Collection
Import the complete FundlyHub API into your HTTP client in one click.
Download
⬇ Download Postman CollectionImport Instructions
Postman
- Open Postman and click Import in the sidebar
- Select the downloaded
.jsonfile - The collection appears under Collections with all endpoints organized by tag
Insomnia
- Open Insomnia → Application → Import
- Choose From File and select the
.jsonfile - All requests are imported with example bodies pre-filled
Bruno
- Open Bruno → Collection → Import Collection
- Select Postman Collection as the format
- Browse to the downloaded file and import
Thunder Client (VS Code)
- Open Thunder Client sidebar in VS Code
- Click Collections → Import
- Select the downloaded
.jsonfile
Environment Variables
The collection includes two variables you should configure:
| Variable | Default Value | Description |
|---|---|---|
baseUrl | https://api.fundlyhub.org/api/v1 | API base URL. Use https://api.staging.fundlyhub.org/api/v1 for staging. |
bearerToken | (empty) | Sent as Authorization: Bearer {{bearerToken}} on every authenticated request |
Setting Up Authentication
POST /cognito/signin returns its tokens only as httpOnly cookies, never in the body, so there is nothing to copy from its response. Use an API key:
- Call
POST /cognito/signinwith your email and password from Postman. Its cookie jar keeps the session cookies the response sets. - Call
POST /api-keyswith{ "name": "postman" }and copyapi_key(fh_live_…) from the201response. It is shown once. - Set it as
bearerToken. Every authenticated request then uses it.
A key acts as its owner with the owner's full permissions — see Authentication. Revoke it with DELETE /api-keys/:id when you are done. A Cognito ID token works in bearerToken too (an access token does not).
Cookies win over the header
If Postman's cookie jar still holds FundlyHub session cookies, the API authenticates as the cookie and ignores bearerToken. Clear the cookies for the API host when you want the key to be what counts.
What's Included
The collection is generated from the OpenAPI spec, so it contains exactly what that spec documents: all 272 public operations, one folder per tag (33 folders). Five translation endpoints carry two tags and so appear in two folders, which makes 277 request entries in all.
Endpoints that need a permission answer 403 unless the key's owner holds the permission named on each one — see Roles & Permissions.
Request bodies and parameters are filled from the spec's examples, or faked from its schemas where there is no example, so replace ids and values before sending.
Auto-generated
The collection is regenerated from the spec with npm run generate:postman in docs/public-docs, and published at https://docs.fundlyhub.org/fundlyhub-api.postman_collection.json. The spec itself is at /openapi.json and /openapi.yaml.