API Reference Sections
The generated reference, one section per OpenAPI tag. Every public endpoint is in at least one of these sections (a few translation endpoints sit under two), built from the published spec (/openapi.json, /openapi.yaml) on every build.
| Reference section | Operations | About |
|---|---|---|
| Authentication | 13 | User registration, login, and session management via AWS Cognito |
| Fundraisers | 20 | Create and manage fundraising campaigns |
| Donations | 8 | Process and track donations |
| Categories | 4 | Browse fundraiser categories |
| Organizations | 11 | Manage nonprofit organizations |
| Users | 24 | User profiles and preferences |
| Search | 2 | Full-text search and autocomplete |
| Payouts | 13 | Earnings and payout management |
| Milestones | 6 | Campaign milestones and progress tracking |
| Payments | 2 | Stripe payment processing |
| App Attest | 2 | Apple App Attest for the FundlyHub iOS app. A request carrying a valid assertion may skip reCAPTCHA on `POST /payments/create-intent` and `POST /donations`, guest or signed in. See the Native Clients guide for the byte-level protocol. |
| AI | 5 | AI-powered content tools |
| RBAC | 1 | The signed-in caller's own roles and permissions |
| Platform | 14 | Platform stats and health |
| Donors | 3 | A donor's own giving history, summary, and annual statements |
| Notifications | 9 | In-app notifications for the authenticated user. Which events also generate email is governed by the toggles on `/users/{id}/preferences`, not by anything under `/notifications`. |
| Social | 6 | Following users and organizations |
| Comments | 7 | Fundraiser comments and replies |
| Updates | 12 | Project updates, milestones, and funding stats |
| Shares | 7 | Social-share event tracking |
| Organization Admin | 34 | The org-scoped admin panel at `/org-admin/{slug}/*`. Every operation needs a bearer session, resolves `{slug}` to an organization (an unknown or malformed slug answers `404 Organization not found`, never `403`), and then checks an **org-scoped permission** held through the caller's `org_owner`, `org_admin` or `org_viewer` role on that organization. A caller without the permission gets `403` with `message: "Requires permission: <name>"`. |
| Translations | 11 | The owner-side Translations tab: a campaign's, its milestones' and its updates' rows in the other supported locales (`en`, `ru`, `uk`, `es`), hand-edited or regenerated. The public read paths already serve the translated text; these endpoints are for authors. |
| Endorsements | 5 | Ambassadors publicly vouching for other people's campaigns, and creators asking ambassadors to promote theirs. |
| Media | 6 | A campaign's photo and video gallery. Behind the `features.fundraiser_video` flag. |
| Images | 7 | Stock-photo search, AI cover generation and server-side image copying for the campaign builder, plus an allowlisted image proxy. |
| Storage | 2 | Direct uploads of campaign images to the platform's CDN bucket. |
| Achievements | 17 | The public badge catalogue, single badges, the "just earned" feed, and individual earned cards with their share pictures and verify QR codes. |
| API Keys | 3 | Long-lived `fh_live_…` keys for CLI and agent access. A key is sent as `Authorization: Bearer fh_live_…` and authenticates as the user who created it, on every endpoint that accepts a bearer session. |
| Creator Subscriptions | 10 | Creator monetisation tiers (each mirrored to a Stripe Product and Prices) and the fan-side recurring subscriptions to them. |
| Ambassadors | 14 | The ambassador programme: the public directory, invitations and applications, referral links and click tracking, and the ambassador portal under `/me/referrals/*`. |
| Email Preferences | 4 | Public, token-authorised unsubscribe and resubscribe for any address FundlyHub mails, including guest donors with no account. |
| Meta | 4 | Crawler-facing discovery files (`llms.txt`, sitemaps), generated from live data and proxied by the frontend at the site's public paths. |
| DMCA | 2 | DMCA §512 takedown notices and counter-notices. Currently dark behind the `features.dmca_workflow` flag. |
| Support | 1 | Live-chat (Chatwoot) identity for the signed-in user. |
For an overview of an area before its endpoint list, start from the API overview.