API product
White Label Organization API
Version 1 routes for approved white-label organizations.
Audited route registry
The endpoint list below is generated from the existing typed documentation registry and validated against implemented server sources.
Product-specific contract
Authentication, route prefix, request fields, response shape, and permissions remain separate from the other API products.
Endpoint reference
Base URL: https://api.sparkglim.net
Approved HTTPS domain plus public/campaign credential for safe reads; private operations use a version 2 domain-bound HMAC signature and fresh nonce.
/api/white-label/v1/contextGet account context
Loads the current white-label account context for an enabled account.
Authentication: White-label HMAC authentication
Permissions: settings:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
Success · HTTP 200
{
"success": true,
"data": { "account": {}, "branding": {}, "settings": {} },
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/campaignsList campaigns
Lists campaigns visible to the authenticated white-label account.
Authentication: Approved domain plus public, campaign or private key
Permissions: campaigns:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-domainVerified organization website. | header HTTPS hostname | Required |
x-white-label-keyThe one complete Public or Campaign Key copied from Creator settings. | header keyId:secret | Required |
searchOptional campaign search text. | query string | Optional |
statusOptional campaign status filter. | query string | Optional |
Success · HTTP 200
{
"success": true,
"data": [{ "id": "campaign_id", "title": "Campaign title" }],
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/campaignsCreate campaign
Creates a white-label campaign. Supported campaign_type values are voting, donation, and ticketing.
Authentication: White-label HMAC authentication
Permissions: campaigns:write
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
title3 to 255 characters. | body string | Required |
description10 to 5000 characters. | body string | Required |
campaign_typeImplemented campaign types. | body voting | donation | ticketing | Required |
start_dateCampaign start date. | body ISO datetime | Required |
end_dateCampaign end date. | body ISO datetime | Required |
Success · HTTP 201
{
"success": true,
"data": { "id": "campaign_id", "status": "draft" },
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/campaigns/:campaignIdUpdate campaign
Partially updates an existing campaign owned by the white-label account.
Authentication: White-label HMAC authentication
Permissions: campaigns:write
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
campaignIdCampaign identifier. | path string | Required |
Success · HTTP 200
{
"success": true,
"data": { "id": "campaign_id" },
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/ticket-typesList ticket types
Lists ticket types, optionally filtered by campaignId.
Authentication: Approved domain plus public, campaign or private key
Permissions: tickets:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-domainVerified organization website. | header HTTPS hostname | Required |
x-white-label-keyThe one complete Public or Campaign Key copied from Creator settings. | header keyId:secret | Required |
campaignIdOptional campaign filter. | query uuid | Optional |
Success · HTTP 200
{
"success": true,
"data": [{ "id": "ticket_type_id", "name": "VIP" }],
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/ticket-typesCreate ticket type
Creates a ticket type for a ticketing campaign.
Authentication: White-label HMAC authentication
Permissions: tickets:write
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
campaignIdCampaign ID. | body uuid | Required |
nameTicket type name. | body string | Required |
priceTicket price. | body number | Required |
quantity_availableAvailable quantity. | body number | Required |
Success · HTTP 201
{
"success": true,
"data": { "id": "ticket_type_id" },
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/participantsList participants
Lists voting participants/nominees for white-label campaigns.
Authentication: White-label HMAC authentication
Permissions: campaigns:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
campaignIdOptional campaign filter. | query uuid | Optional |
searchOptional search text. | query string | Optional |
statusOptional participant status. | query string | Optional |
Success · HTTP 200
{
"success": true,
"data": [{ "id": "participant_id", "name": "Nominee" }],
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/payments/initializeInitialize payment
Starts a server-priced ticket checkout; vote and donation initialization use their dedicated routes.
Authentication: White-label HMAC authentication
Permissions: payments:write
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
campaign_idApproved ticketing campaign. | body uuid | Required |
ticket_idConfigured ticket type. Server calculates price and fees. | body uuid | Required |
emailCustomer email. | body | Required |
quantityRequested quantity. | body integer | Required |
Success · HTTP 200
{
"success": true,
"data": { "reference": "payment_reference" },
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/withdrawalsCreate withdrawal request
Creates a withdrawal request. This route requires a secret key, withdrawal-enabled API key, and idempotency key.
Authentication: White-label HMAC authentication with secret key only
Permissions: withdrawals:write, withdrawal capability, X-Idempotency-Key header
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
X-Idempotency-KeyRequired duplicate-prevention key. | header string | Required |
amountPositive amount. | body number | Required |
bank_nameBank/channel name. | body string | Required |
bank_codeBank/channel code. | body string | Required |
account_numberRecipient account number. | body string | Required |
account_nameRecipient account name. | body string | Required |
Success · HTTP 201
{
"success": true,
"data": { "id": "withdrawal_id", "status": "pending" },
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/settingsRead settings
Returns white-label settings, optionally filtered by categories.
Authentication: White-label HMAC authentication
Permissions: settings:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
categoriesOptional category filter. | query string | string[] | Optional |
Success · HTTP 200
{
"success": true,
"data": { "branding": {}, "security": {} },
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/tickets/verifyPublic ticket verification
Confirm usable status without holder or purchase data.
Authentication: Approved domain and public/campaign key
Permissions: tickets:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-domainVerified organization website. | header HTTPS hostname | Required |
x-white-label-keyThe one complete Public or Campaign Key copied from Creator settings. | header keyId:secret | Required |
Success · HTTP 200
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/storefrontStorefront
Public campaign and ticket types in one response.
Authentication: Approved domain and public/campaign key
Permissions: campaigns:read, tickets:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-domainVerified organization website. | header HTTPS hostname | Required |
x-white-label-keyThe one complete Public or Campaign Key copied from Creator settings. | header keyId:secret | Required |
Success · HTTP 200
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/configPublic configuration
Approved domain, campaign scope and enabled modules.
Authentication: Approved domain and public/campaign key
Permissions: settings:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-domainVerified organization website. | header HTTPS hostname | Required |
x-white-label-keyThe one complete Public or Campaign Key copied from Creator settings. | header keyId:secret | Required |
Success · HTTP 200
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/ticket-types/bootstrapBootstrap ticket types
One-time creator-enabled ticket definitions for an empty campaign.
Authentication: Approved domain and private HMAC key
Permissions: tickets:write
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
Success · HTTP 201
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/payments/verifyVerify ticket payment
Receipt-bound provider verification and fulfillment.
Authentication: Approved domain and private HMAC key
Permissions: payments:write
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
Success · HTTP 200
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/my-tickets/request-otpRequest OTP
Send OTP only if the scoped campaign has a completed ticket.
Authentication: Approved domain and private HMAC key
Permissions: my-tickets:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
Success · HTTP 200
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/my-tickets/verify-otpVerify OTP
Verify challenge and create a customer session.
Authentication: Approved domain and private HMAC key
Permissions: my-tickets:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
Success · HTTP 200
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/my-tickets/listList authenticated tickets
List tickets in the verified session and campaign.
Authentication: Approved domain and private HMAC key
Permissions: my-tickets:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
Success · HTTP 200
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/my-tickets/qrGet ticket QR
Get a QR only for a ticket in the verified session.
Authentication: Approved domain and private HMAC key
Permissions: my-tickets:read
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
Success · HTTP 200
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}/api/white-label/v1/submissionsCreate application
Create volunteer, vendor or partner application.
Authentication: Approved domain and private HMAC key
Permissions: submissions:write
| Field | Location / type | Requirement |
|---|---|---|
x-white-label-key-idInternal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you. | header string | Required |
x-white-label-signatureVersion 2 HMAC signature generated by your backend using the private key. | header string | Required |
x-white-label-timestampRequest timestamp in milliseconds. | header number string | Required |
x-white-label-nonceUnique nonce for replay protection. | header string | Required |
Success · HTTP 201
{
"success": true,
"data": {},
"requestId": "wlapi_..."
}Error response shape
{
"success": false,
"error": "Invalid campaign query",
"requestId": "wlapi_..."
}