API product

Public Embed API

Audited public and embed-safe routes.

Audited route registry

The endpoint list below is generated from the existing typed documentation registry and validated against implemented server sources.

Product-specific contract

Authentication, route prefix, request fields, response shape, and permissions remain separate from the other API products.

Endpoint reference

Base URL: https://api.sparkglim.net

Unauthenticated public routes with validation, forwarding, caching, and gateway protections where implemented. Do not place secret keys in browser embeds.

POST/api/public/vote

Initialize public vote

Initializes a public vote payment through the existing public payment flow.

Authentication: Unauthenticated public route with server-side validation and forwarding

Request fields
FieldLocation / typeRequirement
campaign_id

Public voting campaign identifier.

body
UUID
Required
participant_id

Nominee identifier within the campaign.

body
UUID
Required
phone_number

Participant phone number.

body
string
Required
vote_count

Quantity from 1 to 100.

body
integer
Required
email

Participant contact email.

body
email
Optional
payment_channel

Accepted channel value. card is the default; actual availability follows provider configuration.

body
card | mobile_money | apple_pay
Optional

Success · HTTP 200

{
  "success": true,
  "data": {}
}

Error response shape

{
  "success": false,
  "error": "Unable to complete request"
}
POST/api/public/tickets/purchase

Initialize public ticket purchase

Initializes a public ticket purchase.

Authentication: Unauthenticated public route with server-side validation and forwarding

Request fields
FieldLocation / typeRequirement
campaign_id

Ticketing campaign identifier.

body
UUID
Required
ticket_id

Ticket type identifier.

body
UUID
Required
quantity

Ticket quantity from 1 to 100.

body
integer
Required
phone_number

Buyer phone number.

body
string
Required
email

Buyer contact email; campaign or provider requirements may require it.

body
email
Optional
discount_code

Discount code validated against the campaign.

body
string
Optional
invite_code

Invitation code for restricted access where configured.

body
string
Optional
attendee_information

Information matching the configured attendee fields.

body
object of string values
Optional
luggage_quantity

Configured luggage quantity where the event supports it.

body
nonnegative integer
Optional
payment_channel

Accepted channel value; provider availability still applies.

body
card | mobile_money | apple_pay
Optional

Success · HTTP 200

{
  "success": true,
  "data": {}
}

Error response shape

{
  "success": false,
  "error": "Unable to complete request"
}
POST/api/public/donate

Initialize public donation

Starts a donation payment using the campaign and configured provider. Initialization does not confirm the donation.

Authentication: Unauthenticated public route with validation and abuse controls

Request fields
FieldLocation / typeRequirement
campaign_id

Donation campaign identifier.

body
UUID
Required
amount

From 1 to 1000000, in increments of 0.01. The campaign currency applies.

body
number
Required
email

Donor contact email.

body
email
Optional
phone_number

Donor phone number; needed for mobile money prompting.

body
string
Optional
donor_name

Donor display name.

body
string
Optional
anonymous

Requests the supported anonymous donation behavior.

body
boolean
Optional
is_anonymous

Accepted anonymity field used by existing clients; avoid conflicting anonymity values.

body
boolean
Optional
custom_data

Additional configured campaign information.

body
object
Optional
payment_channel

Accepted channel value; provider availability still applies.

body
card | mobile_money | apple_pay
Optional

Success · HTTP 200

{
  "success": true,
  "data": {}
}

Error response shape

{
  "success": false,
  "error": "Unable to complete request"
}

Payment data is provider-dependent. Retain the returned reference. Handle validation (400), unavailable resources (404), campaign conflicts (409), temporary abuse controls (429), and gateway failures (502).

GET/api/public/tickets/public-verify

Public ticket verification

Verifies publicly verifiable ticket codes through the existing public verification flow.

Authentication: Unauthenticated public verification route

Request fields
FieldLocation / typeRequirement
code

Ticket code.

query
string
Required

Success · HTTP 200

{
  "success": true,
  "data": {}
}

Error response shape

{
  "success": false,
  "error": "Unable to complete request"
}
GET/api/public/blog

List public blog posts

Lists published public blog posts with search, category, featured, limit, and offset filters.

Authentication: Unauthenticated public route

Request fields
FieldLocation / typeRequirement
category

Category slug.

query
string
Optional
search

Search text.

query
string
Optional
limit

1 to 30.

query
number
Optional
offset

Offset.

query
number
Optional

Success · HTTP 200

{
  "success": true,
  "data": [],
  "count": 0,
  "limit": 10,
  "offset": 0
}

Error response shape

{
  "success": false,
  "error": "Unable to complete request"
}
GET/api/public/donation-summary/:campaignId

Get public donation summary

Returns public fundraising summary data for a campaign.

Authentication: Unauthenticated public route with short cache

Request fields
FieldLocation / typeRequirement
campaignId

Campaign ID.

path
string
Required

Success · HTTP 200

{
  "success": true,
  "data": {}
}

Error response shape

{
  "success": false,
  "error": "Unable to complete request"
}
GET/api/public/vote-counts/:campaignId

Get public vote counts

Returns public vote counts for a campaign.

Authentication: Unauthenticated public route

Request fields
FieldLocation / typeRequirement
campaignId

Campaign ID.

path
string
Required

Success · HTTP 200

{
  "success": true,
  "data": {
    "voteCounts": {}
  }
}

Error response shape

{
  "success": false,
  "error": "Unable to complete request"
}