Must know
- Webhooks and API keys are behind the
webhooksmodule. It ships off; a superadmin enables it per club. Until then Settings → Webhooks & API says “Webhooks & API are not enabled for this club”. - The API is read-only. Today it has one endpoint,
GET /api/v1/programs, which returns what the club’s public site already shows. - A key or a signing secret is shown once, when it is created or rotated. Copy it then.
Where it lives
Settings → Webhooks & API — “Push club events to Zapier, n8n or your own server, and read club data with an API key.” Two tabs: Webhooks and API keys.API keys
1
Create a key
On the API keys tab, create a key and pick its scopes. The full key is shown once; the table afterwards shows only its prefix, scopes, Last used, and whether it is active or revoked.
2
Call the API
Send the key as a bearer token:
3
Revoke when done
Revoking a key is immediate and permanent. A missing, unknown or revoked key — or a club whose module is off — answers
401; a key without the needed scope answers 403.Scopes
The last three scopes can be granted to a key so it is ready when their endpoints ship, but no
/api/v1 route reads them today.
GET /api/v1/programs
Returns the club’s active, non-private programs (leagues, bonspiels and other programs), ordered by start date then name — never more than an anonymous visitor to the storefront can see.
Webhooks
An endpoint is anhttps:// URL plus the list of events it wants. “Every subscribed event is POSTed as JSON, signed with the endpoint’s secret (X-Uplifter-Signature). Failed deliveries retry after 1 min, 5 min, 30 min, 2 h and 12 h; five dead deliveries in a row switch the endpoint off.” Re-enabling the endpoint in Settings resets the count.
Events
Every delivery is an envelope:
{ id, event, createdAt, organizationId, data }. The id (evt_…) is the same on every endpoint the event fans out to, so receivers can de-duplicate. Payloads carry no personal data beyond the registrant’s name and email.
Verifying the signature
Header:X-Uplifter-Signature: t=<unix seconds>,v1=<hex> where v1 is HMAC-SHA256 over "<t>.<raw body>" with the endpoint’s secret. Reject deliveries whose t is more than 300 seconds from now. The scheme is the same as Stripe’s, so a Zapier or n8n “verify a Stripe signature” recipe works after renaming the header. Other headers: X-Uplifter-Event, X-Uplifter-Delivery, User-Agent: Uplifter-Webhooks/1.0.