Skip to content

Platform​

Platform stats and health


Public leaderboard​

GET
/leaderboard

One ranked list on impact = raised + given + driven, in integer cents, over the chosen period.
Raised is the sum of the person's counted campaign cards — settled gifts to public fundraisers they organize, net of processor fees, their own gifts included;
Given is every settled gift they made under their name; Driven is other people's settled gifts through
their share or ambassador link to fundraisers they do not organize. Every dollar counts once.
Anonymous donors appear as alias rows keyed on an opaque anonymousKey; guest and anonymous rows link to their donor page under /d/{kind}/{key}.
When the request carries a session, standing describes where the caller ranks on the full view.
q searches the ranked board by name without renumbering it: a match keeps the rank it has on the full view.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)
or

Parameters​

Query Parameters

period
Type
string
Valid values
"all""30d""7d"
Default
"all"
role

Everyone; people organizing a public fundraiser; ambassador role holders; or donors — everyone with a settled gift under their name, whatever their role, anonymous identities included. Everyone, creators and ambassadors rank on impact; donors rank on given (see metric). A filtered view is ranked within itself.

Type
string
Valid values
"all""creators""ambassadors""donors"
Default
"all"
offset
Type
integer
Minimum
0
Default
0
limit
Type
integer
Minimum
1
Maximum
100
Default
25
q

Name search over this view. Trimmed and cut to 100 characters.

Type
string
Max Length
100
lang

Language for badge titles and anonymous aliases (en, ru, uk, es). Defaults from Accept-Language.

Type
string

Responses​

One page of the ranked view

application/json
JSON
{
"entries": [
{
"rank": 0,
"tied": true,
"id": "string",
"kind": "string",
"name": "string",
"avatar": "string",
"href": "string",
"anonymousKey": "string",
"isCreator": true,
"isAmbassador": true,
"raised": 0,
"given": 0,
"driven": 0,
"impact": 0,
"score": 0,
"impressions": 0,
"gifts": 0,
"badges": [
{
"slug": "string",
"artKey": "string",
"artUrl": "string",
"tier": "string",
"title": "string"
}
],
"badgeCount": 0
}
],
"qualified": 0,
"hasMore": true,
"standing": {
"rank": 0,
"tied": true,
"score": 0,
"impact": 0,
"raised": 0,
"given": 0,
"driven": 0,
"gap": 0,
"above": "string"
},
"period": "string",
"role": "string",
"metric": "string",
"offset": 0,
"limit": 0,
"query": "string",
"executionTimeMs": 0,
"cached": true
}

Playground​

Server
Authorization
Variables
Key
Value

Samples​


Public donor page​

GET
/donors/{kind}/{key}

The public page behind a guest or anonymous donor row on the leaderboard.

A donor identity is addressed ONLY by an opaque public key of 20 hex characters. The key is
one-way: no email, no identity id and no account reference ever leaves the server, and the
guest key and the anonymous key of one person cannot be related to each other.

given and gifts cover every settled gift of the identity — the same figures the
leaderboard row shows — including gifts to campaigns that are not public. The campaigns
list is public campaigns only, and campaignsHidden counts the gifts the list cannot show.

An anonymous identity is never named: name is null and anonymousKey carries the key, from
which the client derives the same localized alias the donor wall shows.

No authentication: the page is viewer-independent. Money is in integer cents.

Parameters​

Path Parameters

kind*
Type
string
Required
Valid values
"guest""anon"
key*

The opaque public key from a leaderboard row or a search result.

Type
string
Required
Pattern
"^[0-9a-f]{20}$"

Responses​

The donor page

application/json
JSON
{
"kind": "string",
"key": "string",
"name": "string",
"anonymousKey": "string",
"given": 0,
"gifts": 0,
"currency": "string",
"firstGiftAt": "string",
"lastGiftAt": "string",
"rank": 0,
"score": 0,
"href": "string",
"campaigns": [
{
"id": "string",
"slug": "string",
"title": "string",
"coverImage": "string",
"isProject": true,
"givenCents": 0,
"gifts": 0,
"lastGiftAt": "string"
}
],
"campaignsHidden": 0,
"hasMoreCampaigns": true
}

Playground​

Server
Variables
Key
Value

Samples​


Get platform statistics​

GET
/stats

Public endpoint returning aggregate platform stats. A bare object, not wrapped in data.

Responses​

Platform statistics

application/json
JSON
{
"totalRaisedCents": 1234560000,
"activeCampaigns": 0,
"totalSupporters": 0,
"totalCreators": 0,
"totalGoalCents": 5000000000
}

Playground​

Samples​


Get trust center status​

GET
/trust/status

Live security and compliance status for the Trust Center. Public; cached for up to 15 minutes.

Responses​

Trust status

application/json
JSON
{
"success": true,
"data": {
"overallStatus": "string",
"lastChecked": "string",
"controls": [
{
"id": "string",
"label": "string",
"icon": "string",
"status": "string",
"lastChecked": "string",
"details": "string"
}
]
}
}

Playground​

Samples​


ZIP code lookup​

GET
/location/zip/{zipCode}

Look up city and state from a 5-digit US ZIP code. Public; answers are cached.

Parameters​

Path Parameters

zipCode*
Type
string
Required
Example"95630"

Responses​

Location data

application/json
JSON
{
"zipCode": "string",
"city": "string",
"state": "string",
"stateAbbreviation": "string"
}

Playground​

Server
Variables
Key
Value

Samples​


Get feature flags​

GET
/system-settings/features

The features.* flags, read-only, for the signed-in caller — so the client can hide what the server will refuse. Flags that only concern FundlyHub's own operations are omitted. Each value is reduced to the three gating fields.

The server treats a flag that has no row as enabled, so a flag absent from this list is not necessarily off.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Responses​

The flags

application/json
JSON
{
"data": [
{
"setting_key": "features.comments",
"setting_value": {
"enabled": true,
"allowed_roles": [
"string"
],
"disabled_message": "string"
},
"category": "string"
}
]
}

Playground​

Server
Authorization

Samples​


Get the platform's published numbers​

GET
/platform/numbers

The figures FundlyHub publishes about itself on /@fundlyhub. The same answer for every reader, cached for five minutes; computed_at says how old it is. GET /stats is unchanged and still served.

No authentication. Rate limited at 300 requests/minute per IP.

Responses​

The numbers (bare object)

application/json
JSON
"string"

Playground​

Samples​


List the FundlyHub team​

GET
/platform/team

The FundlyHub team members shown on /@fundlyhub: staff with a public, slugged profile and an account in good standing — at most 48, ordered by role then name. An empty list is a normal 200.

No authentication. Rate limited at 300 requests/minute per IP.

Parameters​

Query Parameters

lang

Cache key for future localised fields. Anything else is treated as en.

Type
string
Valid values
"en""ru""uk""es"
Default
"en"

Responses​

The roster

application/json
JSON
{
"members": [
]
}

Playground​

Server
Variables
Key
Value

Samples​


List platform ambassadors with impact​

GET
/platform/ambassadors

Every holder of the ambassador role who is not banned (at most 100), ranked by impact. total counts all of them; members lists only those with a public, slugged profile, so total can exceed members.length.

No authentication. Rate limited at 300 requests/minute per IP.

Parameters​

Query Parameters

lang
Type
string
Valid values
"en""ru""uk""es"
Default
"en"

Responses​

The ambassador rail

application/json
JSON
{
"members": [
],
"total": 0
}

Playground​

Server
Variables
Key
Value

Samples​


Tip FundlyHub​

POST
/platform/tips

Starts a tip to FundlyHub itself — not a donation to a cause, and not tax-deductible. Creates a pending tip row and a Stripe Checkout Session (payment mode for one_time, monthly subscription mode for recurring) and returns its url; send the browser there. Stripe returns the payer to /tip/{tip_id} on the site. The tip is settled by the Stripe webhook, not by this call.

Authentication is optional. With a session the tip is attributed to the account, and the account's name and email are used when the body does not give them. Currency is always USD.

Rate limited at 10 requests/minute per IP (authentication bucket).

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)
or

Request Body​

application/json
JSON
{
"amount_cents": 0,
"kind": "string",
"donor_email": "string",
"donor_name": "string",
"is_anonymous": false
}

Responses​

Checkout started

application/json
JSON
{
"tip_id": "string",
"kind": "string",
"amount_cents": 0,
"currency": "usd",
"url": "string"
}

Playground​

Server
Authorization
Body

Samples​


Get a tip receipt​

GET
/platform/tips/{id}

The public receipt for one tip: amount, cadence, status and dates, and the signed-in tipper's profile name unless they tipped anonymously. Never an email or a Stripe identifier.

A tip that has not settled yet is a 200 with status: pending — the payer often arrives from Stripe before the webhook does. A monthly tip also carries subscription; its next charge date is read from Stripe once the tip is paid.

No authentication: the tip id is the capability. Rate limited at 300 requests/minute per IP.

Parameters​

Path Parameters

id*
Type
string
Required
Format
"uuid"

Responses​

The receipt (bare object)

application/json
JSON
"string"

Playground​

Server
Variables
Key
Value

Samples​


Email a tip receipt​

POST
/platform/tips/{id}/receipt/email

Emails the receipt for one paid tip to any address — every figure comes from the tip row, so the caller controls only the recipient. Capped at 5 sends per tip, after which this answers 429 for that tip permanently. A missing and an unpaid tip get the same 404.

The mail queue is processed immediately; message says whether the email was sent or only queued.

Authentication is optional. Rate limited at 5 requests/minute per IP.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)
or

Parameters​

Path Parameters

id*
Type
string
Required
Format
"uuid"

Request Body​

application/json
JSON
{
"recipient_email": "string"
}

Responses​

Sent or queued

application/json
JSON
{
"success": true,
"message": "string"
}

Playground​

Server
Authorization
Variables
Key
Value
Body

Samples​


Get the homepage live-activity feed​

GET
/home/activity

The homepage hero's live chips, newest first: gifts, referral-link views and clicks, people viewing a campaign right now, campaigns submitted for review (never named), and achievements earned. Every event passes the same public gates as the surface it comes from — only public, active or ended campaigns are named, and anonymous donors are not.

events is a discriminated union on kind. The same answer for every reader of a language; publicly cached for 15 seconds.

No authentication. Rate limited at 300 requests/minute per IP.

Parameters​

Query Parameters

limit
Type
integer
Minimum
1
Maximum
40
Default
24
lang

Campaign titles in this language when translated.

Type
string
Valid values
"en""ru""uk""es"

Responses​

The feed

application/json
JSON
{
"data": {
"events": [
],
"generated_at": "string"
}
}

Playground​

Server
Variables
Key
Value

Samples​


Send a campaign-page presence heartbeat​

POST
/presence/fundraisers/{id}

Records that a visitor has a campaign page open; feeds the "N people viewing" chip in GET /home/activity. Designed for navigator.sendBeacon — no body. The visitor is the visitor_id cookie, or the per-tab v query parameter when there is no cookie; only a one-way hash of it is stored, and it expires on its own.

No authentication. Rate limited at 4 requests/minute per IP and campaign, then the 300/minute public bucket.

Parameters​

Path Parameters

id*

Fundraiser UUID.

Type
string
Required
Format
"uuid"

Query Parameters

v

Per-tab visitor id, used only when there is no visitor_id cookie.

Type
string
Pattern
"^[A-Za-z0-9_-]{8,64}$"

Responses​

Recorded (no body)

Playground​

Server
Variables
Key
Value

Samples​


Powered by VitePress OpenAPI

Built with VitePress