Skip to content

API Reference Sections ​

The generated reference, one section per OpenAPI tag. Every public endpoint is in at least one of these sections (a few translation endpoints sit under two), built from the published spec (/openapi.json, /openapi.yaml) on every build.

Reference sectionOperationsAbout
Authentication13User registration, login, and session management via AWS Cognito
Fundraisers20Create and manage fundraising campaigns
Donations8Process and track donations
Categories4Browse fundraiser categories
Organizations11Manage nonprofit organizations
Users24User profiles and preferences
Search2Full-text search and autocomplete
Payouts13Earnings and payout management
Milestones6Campaign milestones and progress tracking
Payments2Stripe payment processing
App Attest2Apple App Attest for the FundlyHub iOS app. A request carrying a valid assertion may skip reCAPTCHA on `POST /payments/create-intent` and `POST /donations`, guest or signed in. See the Native Clients guide for the byte-level protocol.
AI5AI-powered content tools
RBAC1The signed-in caller's own roles and permissions
Platform14Platform stats and health
Donors3A donor's own giving history, summary, and annual statements
Notifications9In-app notifications for the authenticated user. Which events also generate email is governed by the toggles on `/users/{id}/preferences`, not by anything under `/notifications`.
Social6Following users and organizations
Comments7Fundraiser comments and replies
Updates12Project updates, milestones, and funding stats
Shares7Social-share event tracking
Organization Admin34The org-scoped admin panel at `/org-admin/{slug}/*`. Every operation needs a bearer session, resolves `{slug}` to an organization (an unknown or malformed slug answers `404 Organization not found`, never `403`), and then checks an **org-scoped permission** held through the caller's `org_owner`, `org_admin` or `org_viewer` role on that organization. A caller without the permission gets `403` with `message: "Requires permission: <name>"`.
Translations11The owner-side Translations tab: a campaign's, its milestones' and its updates' rows in the other supported locales (`en`, `ru`, `uk`, `es`), hand-edited or regenerated. The public read paths already serve the translated text; these endpoints are for authors.
Endorsements5Ambassadors publicly vouching for other people's campaigns, and creators asking ambassadors to promote theirs.
Media6A campaign's photo and video gallery. Behind the `features.fundraiser_video` flag.
Images7Stock-photo search, AI cover generation and server-side image copying for the campaign builder, plus an allowlisted image proxy.
Storage2Direct uploads of campaign images to the platform's CDN bucket.
Achievements17The public badge catalogue, single badges, the "just earned" feed, and individual earned cards with their share pictures and verify QR codes.
API Keys3Long-lived `fh_live_…` keys for CLI and agent access. A key is sent as `Authorization: Bearer fh_live_…` and authenticates as the user who created it, on every endpoint that accepts a bearer session.
Creator Subscriptions10Creator monetisation tiers (each mirrored to a Stripe Product and Prices) and the fan-side recurring subscriptions to them.
Ambassadors14The ambassador programme: the public directory, invitations and applications, referral links and click tracking, and the ambassador portal under `/me/referrals/*`.
Email Preferences4Public, token-authorised unsubscribe and resubscribe for any address FundlyHub mails, including guest donors with no account.
Meta4Crawler-facing discovery files (`llms.txt`, sitemaps), generated from live data and proxied by the frontend at the site's public paths.
DMCA2DMCA §512 takedown notices and counter-notices. Currently dark behind the `features.dmca_workflow` flag.
Support1Live-chat (Chatwoot) identity for the signed-in user.

For an overview of an area before its endpoint list, start from the API overview.

Built with VitePress