API product
Public Embed API
Audited public and embed-safe routes.
Audited route registry
The endpoint list below is generated from the existing typed documentation registry and validated against implemented server sources.
Product-specific contract
Authentication, route prefix, request fields, response shape, and permissions remain separate from the other API products.
Endpoint reference
Base URL: https://api.sparkglim.net
Unauthenticated public routes with validation, forwarding, caching, and gateway protections where implemented. Do not place secret keys in browser embeds.
/api/public/voteInitialize public vote
Initializes a public vote payment through the existing public payment flow.
Authentication: Unauthenticated public route with server-side validation and forwarding
| Field | Location / type | Requirement |
|---|---|---|
campaign_idPublic voting campaign identifier. | body UUID | Required |
participant_idNominee identifier within the campaign. | body UUID | Required |
phone_numberParticipant phone number. | body string | Required |
vote_countQuantity from 1 to 100. | body integer | Required |
emailParticipant contact email. | body | Optional |
payment_channelAccepted channel value. card is the default; actual availability follows provider configuration. | body card | mobile_money | apple_pay | Optional |
Success · HTTP 200
{
"success": true,
"data": {}
}Error response shape
{
"success": false,
"error": "Unable to complete request"
}/api/public/tickets/purchaseInitialize public ticket purchase
Initializes a public ticket purchase.
Authentication: Unauthenticated public route with server-side validation and forwarding
| Field | Location / type | Requirement |
|---|---|---|
campaign_idTicketing campaign identifier. | body UUID | Required |
ticket_idTicket type identifier. | body UUID | Required |
quantityTicket quantity from 1 to 100. | body integer | Required |
phone_numberBuyer phone number. | body string | Required |
emailBuyer contact email; campaign or provider requirements may require it. | body | Optional |
discount_codeDiscount code validated against the campaign. | body string | Optional |
invite_codeInvitation code for restricted access where configured. | body string | Optional |
attendee_informationInformation matching the configured attendee fields. | body object of string values | Optional |
luggage_quantityConfigured luggage quantity where the event supports it. | body nonnegative integer | Optional |
payment_channelAccepted channel value; provider availability still applies. | body card | mobile_money | apple_pay | Optional |
Success · HTTP 200
{
"success": true,
"data": {}
}Error response shape
{
"success": false,
"error": "Unable to complete request"
}/api/public/donateInitialize public donation
Starts a donation payment using the campaign and configured provider. Initialization does not confirm the donation.
Authentication: Unauthenticated public route with validation and abuse controls
| Field | Location / type | Requirement |
|---|---|---|
campaign_idDonation campaign identifier. | body UUID | Required |
amountFrom 1 to 1000000, in increments of 0.01. The campaign currency applies. | body number | Required |
emailDonor contact email. | body | Optional |
phone_numberDonor phone number; needed for mobile money prompting. | body string | Optional |
donor_nameDonor display name. | body string | Optional |
anonymousRequests the supported anonymous donation behavior. | body boolean | Optional |
is_anonymousAccepted anonymity field used by existing clients; avoid conflicting anonymity values. | body boolean | Optional |
custom_dataAdditional configured campaign information. | body object | Optional |
payment_channelAccepted channel value; provider availability still applies. | body card | mobile_money | apple_pay | Optional |
Success · HTTP 200
{
"success": true,
"data": {}
}Error response shape
{
"success": false,
"error": "Unable to complete request"
}Payment data is provider-dependent. Retain the returned reference. Handle validation (400), unavailable resources (404), campaign conflicts (409), temporary abuse controls (429), and gateway failures (502).
/api/public/tickets/public-verifyPublic ticket verification
Verifies publicly verifiable ticket codes through the existing public verification flow.
Authentication: Unauthenticated public verification route
| Field | Location / type | Requirement |
|---|---|---|
codeTicket code. | query string | Required |
Success · HTTP 200
{
"success": true,
"data": {}
}Error response shape
{
"success": false,
"error": "Unable to complete request"
}/api/public/blogList public blog posts
Lists published public blog posts with search, category, featured, limit, and offset filters.
Authentication: Unauthenticated public route
| Field | Location / type | Requirement |
|---|---|---|
categoryCategory slug. | query string | Optional |
searchSearch text. | query string | Optional |
limit1 to 30. | query number | Optional |
offsetOffset. | query number | Optional |
Success · HTTP 200
{
"success": true,
"data": [],
"count": 0,
"limit": 10,
"offset": 0
}Error response shape
{
"success": false,
"error": "Unable to complete request"
}/api/public/donation-summary/:campaignIdGet public donation summary
Returns public fundraising summary data for a campaign.
Authentication: Unauthenticated public route with short cache
| Field | Location / type | Requirement |
|---|---|---|
campaignIdCampaign ID. | path string | Required |
Success · HTTP 200
{
"success": true,
"data": {}
}Error response shape
{
"success": false,
"error": "Unable to complete request"
}/api/public/vote-counts/:campaignIdGet public vote counts
Returns public vote counts for a campaign.
Authentication: Unauthenticated public route
| Field | Location / type | Requirement |
|---|---|---|
campaignIdCampaign ID. | path string | Required |
Success · HTTP 200
{
"success": true,
"data": {
"voteCounts": {}
}
}Error response shape
{
"success": false,
"error": "Unable to complete request"
}