Skip to main content
Must know
  • Webhooks and API keys are behind the webhooks module. It ships off; a superadmin enables it per club. Until then Settings → Webhooks & API says “Webhooks & API are not enabled for this club”.
  • The API is read-only. Today it has one endpoint, GET /api/v1/programs, which returns what the club’s public site already shows.
  • A key or a signing secret is shown once, when it is created or rotated. Copy it then.

Where it lives

Settings → Webhooks & API — “Push club events to Zapier, n8n or your own server, and read club data with an API key.” Two tabs: Webhooks and API keys.

API keys

1

Create a key

On the API keys tab, create a key and pick its scopes. The full key is shown once; the table afterwards shows only its prefix, scopes, Last used, and whether it is active or revoked.
2

Call the API

Send the key as a bearer token:
3

Revoke when done

Revoking a key is immediate and permanent. A missing, unknown or revoked key — or a club whose module is off — answers 401; a key without the needed scope answers 403.

Scopes

The last three scopes can be granted to a key so it is ready when their endpoints ship, but no /api/v1 route reads them today.

GET /api/v1/programs

Returns the club’s active, non-private programs (leagues, bonspiels and other programs), ordered by start date then name — never more than an anonymous visitor to the storefront can see.

Webhooks

An endpoint is an https:// URL plus the list of events it wants. “Every subscribed event is POSTed as JSON, signed with the endpoint’s secret (X-Uplifter-Signature). Failed deliveries retry after 1 min, 5 min, 30 min, 2 h and 12 h; five dead deliveries in a row switch the endpoint off.” Re-enabling the endpoint in Settings resets the count.

Events

Every delivery is an envelope: { id, event, createdAt, organizationId, data }. The id (evt_…) is the same on every endpoint the event fans out to, so receivers can de-duplicate. Payloads carry no personal data beyond the registrant’s name and email.

Verifying the signature

Header: X-Uplifter-Signature: t=<unix seconds>,v1=<hex> where v1 is HMAC-SHA256 over "<t>.<raw body>" with the endpoint’s secret. Reject deliveries whose t is more than 300 seconds from now. The scheme is the same as Stripe’s, so a Zapier or n8n “verify a Stripe signature” recipe works after renaming the header. Other headers: X-Uplifter-Event, X-Uplifter-Delivery, User-Agent: Uplifter-Webhooks/1.0.

Managing endpoints

The Endpoints table shows URL, events, an Enabled switch, Last delivery with its HTTP code and Dead in a row. Per endpoint: edit events, Rotate secret (“The current secret stops verifying immediately — update your receiver first.”), delete, Send test, and a Recent deliveries panel with status, response code, attempt, next attempt and Retry. Related: Feature overview · Which pages exist only in the new look?