API product

White Label Organization API

Version 1 routes for approved white-label organizations.

Audited route registry

The endpoint list below is generated from the existing typed documentation registry and validated against implemented server sources.

Product-specific contract

Authentication, route prefix, request fields, response shape, and permissions remain separate from the other API products.

Endpoint reference

Base URL: https://api.sparkglim.net

Approved HTTPS domain plus public/campaign credential for safe reads; private operations use a version 2 domain-bound HMAC signature and fresh nonce.

GET/api/white-label/v1/context

Get account context

Loads the current white-label account context for an enabled account.

Authentication: White-label HMAC authentication

Permissions: settings:read

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required

Success · HTTP 200

{
  "success": true,
  "data": { "account": {}, "branding": {}, "settings": {} },
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
GET/api/white-label/v1/campaigns

List campaigns

Lists campaigns visible to the authenticated white-label account.

Authentication: Approved domain plus public, campaign or private key

Permissions: campaigns:read

Request fields
FieldLocation / typeRequirement
x-white-label-domain

Verified organization website.

header
HTTPS hostname
Required
x-white-label-key

The one complete Public or Campaign Key copied from Creator settings.

header
keyId:secret
Required
search

Optional campaign search text.

query
string
Optional
status

Optional campaign status filter.

query
string
Optional

Success · HTTP 200

{
  "success": true,
  "data": [{ "id": "campaign_id", "title": "Campaign title" }],
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/campaigns

Create campaign

Creates a white-label campaign. Supported campaign_type values are voting, donation, and ticketing.

Authentication: White-label HMAC authentication

Permissions: campaigns:write

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required
title

3 to 255 characters.

body
string
Required
description

10 to 5000 characters.

body
string
Required
campaign_type

Implemented campaign types.

body
voting | donation | ticketing
Required
start_date

Campaign start date.

body
ISO datetime
Required
end_date

Campaign end date.

body
ISO datetime
Required

Success · HTTP 201

{
  "success": true,
  "data": { "id": "campaign_id", "status": "draft" },
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
PATCH/api/white-label/v1/campaigns/:campaignId

Update campaign

Partially updates an existing campaign owned by the white-label account.

Authentication: White-label HMAC authentication

Permissions: campaigns:write

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required
campaignId

Campaign identifier.

path
string
Required

Success · HTTP 200

{
  "success": true,
  "data": { "id": "campaign_id" },
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
GET/api/white-label/v1/ticket-types

List ticket types

Lists ticket types, optionally filtered by campaignId.

Authentication: Approved domain plus public, campaign or private key

Permissions: tickets:read

Request fields
FieldLocation / typeRequirement
x-white-label-domain

Verified organization website.

header
HTTPS hostname
Required
x-white-label-key

The one complete Public or Campaign Key copied from Creator settings.

header
keyId:secret
Required
campaignId

Optional campaign filter.

query
uuid
Optional

Success · HTTP 200

{
  "success": true,
  "data": [{ "id": "ticket_type_id", "name": "VIP" }],
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/ticket-types

Create ticket type

Creates a ticket type for a ticketing campaign.

Authentication: White-label HMAC authentication

Permissions: tickets:write

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required
campaignId

Campaign ID.

body
uuid
Required
name

Ticket type name.

body
string
Required
price

Ticket price.

body
number
Required
quantity_available

Available quantity.

body
number
Required

Success · HTTP 201

{
  "success": true,
  "data": { "id": "ticket_type_id" },
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
GET/api/white-label/v1/participants

List participants

Lists voting participants/nominees for white-label campaigns.

Authentication: White-label HMAC authentication

Permissions: campaigns:read

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required
campaignId

Optional campaign filter.

query
uuid
Optional
search

Optional search text.

query
string
Optional
status

Optional participant status.

query
string
Optional

Success · HTTP 200

{
  "success": true,
  "data": [{ "id": "participant_id", "name": "Nominee" }],
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/payments/initialize

Initialize payment

Starts a server-priced ticket checkout; vote and donation initialization use their dedicated routes.

Authentication: White-label HMAC authentication

Permissions: payments:write

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required
campaign_id

Approved ticketing campaign.

body
uuid
Required
ticket_id

Configured ticket type. Server calculates price and fees.

body
uuid
Required
email

Customer email.

body
email
Required
quantity

Requested quantity.

body
integer
Required

Success · HTTP 200

{
  "success": true,
  "data": { "reference": "payment_reference" },
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/withdrawals

Create withdrawal request

Creates a withdrawal request. This route requires a secret key, withdrawal-enabled API key, and idempotency key.

Authentication: White-label HMAC authentication with secret key only

Permissions: withdrawals:write, withdrawal capability, X-Idempotency-Key header

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required
X-Idempotency-Key

Required duplicate-prevention key.

header
string
Required
amount

Positive amount.

body
number
Required
bank_name

Bank/channel name.

body
string
Required
bank_code

Bank/channel code.

body
string
Required
account_number

Recipient account number.

body
string
Required
account_name

Recipient account name.

body
string
Required

Success · HTTP 201

{
  "success": true,
  "data": { "id": "withdrawal_id", "status": "pending" },
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
GET/api/white-label/v1/settings

Read settings

Returns white-label settings, optionally filtered by categories.

Authentication: White-label HMAC authentication

Permissions: settings:read

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required
categories

Optional category filter.

query
string | string[]
Optional

Success · HTTP 200

{
  "success": true,
  "data": { "branding": {}, "security": {} },
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/tickets/verify

Public ticket verification

Confirm usable status without holder or purchase data.

Authentication: Approved domain and public/campaign key

Permissions: tickets:read

Request fields
FieldLocation / typeRequirement
x-white-label-domain

Verified organization website.

header
HTTPS hostname
Required
x-white-label-key

The one complete Public or Campaign Key copied from Creator settings.

header
keyId:secret
Required

Success · HTTP 200

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
GET/api/white-label/v1/storefront

Storefront

Public campaign and ticket types in one response.

Authentication: Approved domain and public/campaign key

Permissions: campaigns:read, tickets:read

Request fields
FieldLocation / typeRequirement
x-white-label-domain

Verified organization website.

header
HTTPS hostname
Required
x-white-label-key

The one complete Public or Campaign Key copied from Creator settings.

header
keyId:secret
Required

Success · HTTP 200

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
GET/api/white-label/v1/config

Public configuration

Approved domain, campaign scope and enabled modules.

Authentication: Approved domain and public/campaign key

Permissions: settings:read

Request fields
FieldLocation / typeRequirement
x-white-label-domain

Verified organization website.

header
HTTPS hostname
Required
x-white-label-key

The one complete Public or Campaign Key copied from Creator settings.

header
keyId:secret
Required

Success · HTTP 200

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/ticket-types/bootstrap

Bootstrap ticket types

One-time creator-enabled ticket definitions for an empty campaign.

Authentication: Approved domain and private HMAC key

Permissions: tickets:write

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required

Success · HTTP 201

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/payments/verify

Verify ticket payment

Receipt-bound provider verification and fulfillment.

Authentication: Approved domain and private HMAC key

Permissions: payments:write

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required

Success · HTTP 200

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/my-tickets/request-otp

Request OTP

Send OTP only if the scoped campaign has a completed ticket.

Authentication: Approved domain and private HMAC key

Permissions: my-tickets:read

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required

Success · HTTP 200

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/my-tickets/verify-otp

Verify OTP

Verify challenge and create a customer session.

Authentication: Approved domain and private HMAC key

Permissions: my-tickets:read

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required

Success · HTTP 200

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/my-tickets/list

List authenticated tickets

List tickets in the verified session and campaign.

Authentication: Approved domain and private HMAC key

Permissions: my-tickets:read

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required

Success · HTTP 200

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/my-tickets/qr

Get ticket QR

Get a QR only for a ticket in the verified session.

Authentication: Approved domain and private HMAC key

Permissions: my-tickets:read

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required

Success · HTTP 200

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}
POST/api/white-label/v1/submissions

Create application

Create volunteer, vendor or partner application.

Authentication: Approved domain and private HMAC key

Permissions: submissions:write

Request fields
FieldLocation / typeRequirement
x-white-label-key-id

Internal ID extracted from the one Private Key value (keyId:secret). The SDK sets this header for you.

header
string
Required
x-white-label-signature

Version 2 HMAC signature generated by your backend using the private key.

header
string
Required
x-white-label-timestamp

Request timestamp in milliseconds.

header
number string
Required
x-white-label-nonce

Unique nonce for replay protection.

header
string
Required

Success · HTTP 201

{
  "success": true,
  "data": {},
  "requestId": "wlapi_..."
}

Error response shape

{
  "success": false,
  "error": "Invalid campaign query",
  "requestId": "wlapi_..."
}