Connect API
Changelog
Notable changes to the Connect API, webhooks, and the client library.
Notable changes to the Connect API, webhooks, and the @givebear/connect client. See versioning for what counts as a breaking change.
Events and registrations
- New read endpoints:
GET /events(withpublishedandupcomingfilters, ticket types embedded),GET /events/{id}, andGET /events/{id}/registrations(with astatusfilter). - Two new scopes:
events:readandregistrations:read. Registration payloads carry attendee names and emails; the check-in QR credential, Stripe ids, and tax fields are never exposed. - Two new webhook events:
registration.created(fires when a registration becomes confirmed, not at checkout start) andregistration.refunded. See the event catalog. @givebear/connect0.3.0 addsevents.list(),events.get(),events.listAll(),events.listRegistrations(), andevents.listAllRegistrations().
Embedded components, webhook rotation, and delivery logs
POST /component-sessionsmints a one-hour, read-only browser token for the new embedded components.@givebear/connect0.2.0 addscomponentSessions.create()and a@givebear/connect/componentsmodule with<givebear-donations>,<givebear-donors>, and<givebear-payouts>custom elements. See Embedded components.POST /webhooks/{id}/rotate-secretrotates an endpoint's signing secret with a 24-hour dual-signature grace window;verifyWebhooknow accepts headers carrying multiplev1signatures.GET /webhooks/{id}/deliverieslists an endpoint's recent delivery attempts. The same log appears in the dashboard, which can now also edit endpoints and rotate secrets.- Webhook endpoint URLs must use
httpsand resolve to a public host; registration now rejects anything else. - Rate-limited responses (
429) now include aRetry-Afterheader.
Embedded donations
POST /embed-sessionsmints a one-hour embedded-donation session (requires the existingpayments:writescope; no re-authorization needed). The session pins the fund or campaign target, preset or locked amounts, recurring default, and donor prefill server-side, and attributes donations to your app.@givebear/connectaddsembedSessions.create().- New
@givebear/reactpackage renders every widget as a React component, includingEmbeddedDonationfor sessions. - See Embedded donations.
v1
The first version of the Connect API.
Authentication
- Org API keys (
gb_live_...) and OAuth 2.0 with org-scoped access tokens (gba_...). - Per-credential scopes, bounded by what the granting admin can do.
Read API
donations,donors,payouts,campaigns,funds, andorganization.- Cursor pagination on every list endpoint (
limit,cursor,updated_since).
Collect
POST /payment-intentsto collect a donation on an organization's behalf, settling into its own Stripe account.
Webhooks
- Endpoint management (
GET/POST/PATCH/DELETE /webhooks). - Signed, thin event payloads. Verify them with
verifyWebhookfrom@givebear/connect.
Client
@givebear/connect: a typed, dependency-free TypeScript client for every endpoint above.
Was this page helpful?