Public leaderboard
One ranked list on impact = raised + given + driven, in integer cents, over the chosen period.
Raised is the sum of the person's counted campaign cards — settled gifts to public fundraisers they organize, net of processor fees, their own gifts included;
Given is every settled gift they made under their name; Driven is other people's settled gifts through
their share or ambassador link to fundraisers they do not organize. Every dollar counts once.
Anonymous donors appear as alias rows keyed on an opaque anonymousKey; guest and anonymous rows link to their donor page under /d/{kind}/{key}.
When the request carries a session, standing describes where the caller ranks on the full view.
q searches the ranked board by name without renumbering it: a match keeps the rank it has on the full view.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Parameters
Query Parameters
"all""30d""7d""all"Everyone; people organizing a public fundraiser; ambassador role holders; or donors — everyone with a settled gift under their name, whatever their role, anonymous identities included. Everyone, creators and ambassadors rank on impact; donors rank on given (see metric). A filtered view is ranked within itself.
"all""creators""ambassadors""donors""all"00110025Name search over this view. Trimmed and cut to 100 characters.
100Language for badge titles and anonymous aliases (en, ru, uk, es). Defaults from Accept-Language.
Responses
One page of the ranked view
Public donor page
The public page behind a guest or anonymous donor row on the leaderboard.
A donor identity is addressed ONLY by an opaque public key of 20 hex characters. The key is
one-way: no email, no identity id and no account reference ever leaves the server, and the
guest key and the anonymous key of one person cannot be related to each other.
given and gifts cover every settled gift of the identity — the same figures the
leaderboard row shows — including gifts to campaigns that are not public. The campaigns
list is public campaigns only, and campaignsHidden counts the gifts the list cannot show.
An anonymous identity is never named: name is null and anonymousKey carries the key, from
which the client derives the same localized alias the donor wall shows.
No authentication: the page is viewer-independent. Money is in integer cents.
Parameters
Path Parameters
"guest""anon"The opaque public key from a leaderboard row or a search result.
"^[0-9a-f]{20}$"Responses
The donor page
Get platform statistics
Get trust center status
Live security and compliance status for the Trust Center. Public; cached for up to 15 minutes.
Responses
Trust status
ZIP code lookup
Look up city and state from a 5-digit US ZIP code. Public; answers are cached.
Parameters
Path Parameters
"95630"Responses
Location data
Get feature flags
The features.* flags, read-only, for the signed-in caller — so the client can hide what the server will refuse. Flags that only concern FundlyHub's own operations are omitted. Each value is reduced to the three gating fields.
The server treats a flag that has no row as enabled, so a flag absent from this list is not necessarily off.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Responses
The flags
Get the platform's published numbers
The figures FundlyHub publishes about itself on /@fundlyhub. The same answer for every reader, cached for five minutes; computed_at says how old it is. GET /stats is unchanged and still served.
No authentication. Rate limited at 300 requests/minute per IP.
Responses
The numbers (bare object)
List the FundlyHub team
The FundlyHub team members shown on /@fundlyhub: staff with a public, slugged profile and an account in good standing — at most 48, ordered by role then name. An empty list is a normal 200.
No authentication. Rate limited at 300 requests/minute per IP.
Parameters
Query Parameters
Cache key for future localised fields. Anything else is treated as en.
"en""ru""uk""es""en"Responses
The roster
List platform ambassadors with impact
Every holder of the ambassador role who is not banned (at most 100), ranked by impact. total counts all of them; members lists only those with a public, slugged profile, so total can exceed members.length.
No authentication. Rate limited at 300 requests/minute per IP.
Parameters
Query Parameters
"en""ru""uk""es""en"Responses
The ambassador rail
Tip FundlyHub
Starts a tip to FundlyHub itself — not a donation to a cause, and not tax-deductible. Creates a pending tip row and a Stripe Checkout Session (payment mode for one_time, monthly subscription mode for recurring) and returns its url; send the browser there. Stripe returns the payer to /tip/{tip_id} on the site. The tip is settled by the Stripe webhook, not by this call.
Authentication is optional. With a session the tip is attributed to the account, and the account's name and email are used when the body does not give them. Currency is always USD.
Rate limited at 10 requests/minute per IP (authentication bucket).
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Request Body
Responses
Checkout started
Get a tip receipt
The public receipt for one tip: amount, cadence, status and dates, and the signed-in tipper's profile name unless they tipped anonymously. Never an email or a Stripe identifier.
A tip that has not settled yet is a 200 with status: pending — the payer often arrives from Stripe before the webhook does. A monthly tip also carries subscription; its next charge date is read from Stripe once the tip is paid.
No authentication: the tip id is the capability. Rate limited at 300 requests/minute per IP.
Parameters
Path Parameters
"uuid"Responses
The receipt (bare object)
Email a tip receipt
Emails the receipt for one paid tip to any address — every figure comes from the tip row, so the caller controls only the recipient. Capped at 5 sends per tip, after which this answers 429 for that tip permanently. A missing and an unpaid tip get the same 404.
The mail queue is processed immediately; message says whether the email was sent or only queued.
Authentication is optional. Rate limited at 5 requests/minute per IP.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Parameters
Path Parameters
"uuid"Request Body
Responses
Sent or queued
Get the homepage live-activity feed
The homepage hero's live chips, newest first: gifts, referral-link views and clicks, people viewing a campaign right now, campaigns submitted for review (never named), and achievements earned. Every event passes the same public gates as the surface it comes from — only public, active or ended campaigns are named, and anonymous donors are not.
events is a discriminated union on kind. The same answer for every reader of a language; publicly cached for 15 seconds.
No authentication. Rate limited at 300 requests/minute per IP.
Parameters
Query Parameters
14024Campaign titles in this language when translated.
"en""ru""uk""es"Responses
The feed
Send a campaign-page presence heartbeat
Records that a visitor has a campaign page open; feeds the "N people viewing" chip in GET /home/activity. Designed for navigator.sendBeacon — no body. The visitor is the visitor_id cookie, or the per-tab v query parameter when there is no cookie; only a one-way hash of it is stored, and it expires on its own.
No authentication. Rate limited at 4 requests/minute per IP and campaign, then the 300/minute public bucket.
Parameters
Path Parameters
Fundraiser UUID.
"uuid"Query Parameters
Per-tab visitor id, used only when there is no visitor_id cookie.
"^[A-Za-z0-9_-]{8,64}$"Responses
Recorded (no body)