Skip to content

Images​

Stock-photo search, AI cover generation and server-side image copying for the campaign builder, plus an allowlisted image proxy.


Proxy an allowlisted image​

GET
/images/proxy

Streams an image from the platform's CDN or images.unsplash.com, for local development. Public. The upstream body and Content-Type are passed through with a 24-hour cache header; the upstream status code is not, so an upstream error page also arrives as 200.

Parameters​

Query Parameters

url*
Type
string
Required
Format
"uri"

Responses​

The upstream image

image/*

Playground​

Server
Variables
Key
Value

Samples​


Which image features are available​

GET
/images/features

Whether stock-photo search and AI image generation are configured on this deployment. Public.

Responses​

Feature availability

application/json
JSON
{
"stockPhotos": true,
"aiGeneration": true
}

Playground​

Samples​


Search stock photos​

GET
/images/search

Searches Unsplash for landscape photos. Requires a bearer session. When a photo is chosen, call POST /images/track-download with its downloadLocation, as Unsplash's terms require.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Parameters​

Query Parameters

q*
Type
string
Required
page
Type
integer
Minimum
1
Default
1
per_page
Type
integer
Minimum
1
Maximum
30
Default
20

Responses​

Search results

application/json
JSON
{
"results": [
],
"total": 0,
"totalPages": 0,
"page": 0
}

Playground​

Server
Authorization
Variables
Key
Value

Samples​


Generate a cover image with AI​

POST
/images/generate

Generates a landscape campaign cover from a prompt (the first 500 characters are used, wrapped in a fixed style prompt). Requires a bearer session.
With the default gpt-image-* model the image is stored on the platform CDN immediately and persisted is true; that path is also gated by features.image_uploads and answers 403 when the flag is off. With a dall-e-* model the URL is OpenAI's temporary one (persisted: false) and should be copied with POST /images/save-from-url.
Limited to 10 generations an hour and 30 a day per user; past either limit the answer is 429 with Retry-After. Errors from the image provider are not passed through: a prompt the provider refuses answers 400, a temporarily unavailable provider 503, and any other provider failure 502, each with a generic message.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
"prompt": "string"
}

Responses​

Generated image

application/json
JSON
{
"url": "string",
"revisedPrompt": "string",
"persisted": true
}

Playground​

Server
Authorization
Body

Samples​


Make a photo square with AI​

POST
/images/fit-square

Re-renders a photo as a square without cutting anyone out of it: the people and the setting are kept and the rest of the frame is composed to fill the square. A photo that is already square is rendered again, so calling twice gives a second rendering. Requires a bearer session.
The square comes back as base64 and nothing is stored. Upload it through the normal image upload to use it as a cover.
Shares the limits of POST /images/generate: 10 an hour and 30 a day per user; past either limit the answer is 429 with Retry-After. Errors from the image provider are not passed through: a photo the provider refuses answers 400, a temporarily unavailable provider 503, and any other provider failure 502, each with a generic message.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
"imageBase64": "string"
}

Responses​

The square photo

application/json
JSON
{
"imageBase64": "string",
"contentType": "image/png",
"changed": true
}

Playground​

Server
Authorization
Body

Samples​


Record a stock-photo selection​

POST
/images/track-download

Tells Unsplash a photo was chosen, as its API guidelines require. Pass the downloadLocation from GET /images/search. Never fails the caller's action: a failed ping answers 200 with tracked: false. Requires a bearer session.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
"downloadLocation": "string"
}

Responses​

Tracking outcome

application/json
JSON
{
"tracked": true
}

Playground​

Server
Authorization
Body

Samples​


Copy a generated image to the CDN​

POST
/images/save-from-url

Downloads an AI-generated image from OpenAI's image storage and stores it on the platform CDN, returning the permanent URL. A URL already on the platform CDN is returned unchanged. Requires a bearer session and the features.image_uploads flag.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
"url": "string",
"bucket": "fundraiser-images"
}

Responses​

Stored image

application/json
JSON
{
"success": true,
"url": "string",
"fileName": "string"
}

Playground​

Server
Authorization
Body

Samples​


Powered by VitePress OpenAPI

Built with VitePress