Wishbone API
Let cardholders turn loyalty and credit card reward points into contributions to university athletic foundations. Server-to-server REST, one API key, one response envelope.
Base URL (sandbox)
https://sandbox.api.getwishbone.ioAuthentication
X-Wishbone-API-Key: wbk_test_…Schema
/openapi.jsonYour first call
curl "https://sandbox.api.getwishbone.io/v1/schools?state=TN" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"The hosted API environments are not serving yet, so the call above will not return data today. The reference and schema are generated from the shipped application code and are accurate — see environment status.
Bank / Issuer endpoints
The full surface your backend talks to. There is a separate cardholder portal API used by the Wishbone-hosted portal, which you do not need to implement.
Start here
Authentication
API keys for your backend, bearer tokens for the cardholder portal, and what never belongs in a mobile binary.
Errors & rate limits
Every error code, 400 vs 422, and why the HTTP status is always the real status.
Webhooks
Signature verification, the retry schedule, and deduplicating on a stable delivery ID.
Architecture
What happens between your 202 and the webhook, and how idempotency works end to end.
Mobile SDK
Put the donation flow in your app without shipping a Wishbone secret.
Compliance
Funds flow, tax receipts, and what cardholder data Wishbone does and does not store.