API Reference

Generated from the Wishbone OpenAPI schema (v1.0.0). Every endpoint below shows the exact request — method, URL, headers and body.

Base URLs

Sandboxhttps://sandbox.api.getwishbone.ioTest keys (wbk_test_…). No real money moves.
Productionhttps://api.getwishbone.ioLive keys (wbk_live_…). Issued at onboarding.

The machine-readable schema is at /openapi.json — point your codegen at it directly.

The hosted sandbox is not currently reachable. The reference below is generated from the shipped API schema and is accurate, but requests against sandbox.api.getwishbone.io will not succeed until the environment is live. See environment status.

Bank / Issuer API — contents

POST/v1/accounts/linkGET/v1/accounts/linkedGET/v1/accounts/{wishbone_user_id}DELETE/v1/accounts/{wishbone_user_id}POST/v1/donations/requestGET/v1/donations/{donation_id}GET/v1/schoolsGET/v1/schools/{school_id}POST/v1/embed/token

Cardholder Portal API — contents

POST/v1/portal/auth/forgot-passwordPOST/v1/portal/auth/loginPOST/v1/portal/auth/logoutPOST/v1/portal/auth/refreshGET/v1/portal/donationsPOST/v1/portal/donationsGET/v1/portal/donations/{donation_id}GET/v1/portal/donations/{donation_id}/receiptPOST/v1/portal/donations/{donation_id}/receipt/resendGET/v1/portal/mePATCH/v1/portal/meGET/v1/portal/me/loyalty-accountsGET/v1/portal/schoolsPOST/v1/portal/schools/{school_id}/followGET/v1/portal/preferencesPATCH/v1/portal/preferences

Bank / Issuer API

Server-to-server. Your backend authenticates with an API key and never exposes it to a client.

Accounts

Link and manage cardholder accounts.

Link a Cardholder

#
POSThttps://sandbox.api.getwishbone.io/v1/accounts/link

Authentication

X-Wishbone-API-Key

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/accounts/link" \
  -H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET" \
  -H "Content-Type: application/json" \
  -d '{
    "bank_user_id": "cust_884219",
    "display_name": "Jane Smith",
    "email": "jane@acmebank.com",
    "loyalty_program_id": "lp_chase_sapphire"
  }'

Body

bank_user_idstringREQUIREDmax 128 chars, min 1 chars
display_namestringREQUIREDmax 255 chars, min 1 chars
emailstring (email)REQUIRED
loyalty_program_idstringREQUIREDmax 64 chars, min 1 chars
fund_designationstring
metadataobject
phonestring
redirect_uristring
school_idstring
tax_receipt_emailstring (email)

Response

HTTP/1.1 201 Created
{
  "success": true,
  "data": {
    "wishbone_user_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34",
    "status": "active",
    "oauth_redirect_url": null,
    "linked_at": "2026-05-07T14:22:00Z"
  },
  "meta": { "request_id": "req_01HX..." }
}

List Linked Accounts

#
GEThttps://sandbox.api.getwishbone.io/v1/accounts/linked

Authentication

X-Wishbone-API-Key

Request

curl "https://sandbox.api.getwishbone.io/v1/accounts/linked" \
  -H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"

Query parameters

statusstring
limitinteger>= 1, <= 100
cursorstring
created_afterstring (date-time)
created_beforestring (date-time)

Response

HTTP/1.1 200 OK
{
  "success": true,
  "data": [
    {
      "wishbone_user_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34",
      "bank_user_id": "cust_884219",
      "email": "jane@acmebank.com",
      "display_name": "Jane Smith",
      "status": "active",
      "linked_at": "2026-03-01T09:00:00Z",
      "last_active_at": "2026-05-01T11:22:00Z",
      "loyalty_program_id": "lp_chase_sapphire",
      "preferred_school_id": "sch_tennessee",
      "preferred_fund": "annual_fund",
      "donation_count": 4,
      "lifetime_donated_usd": 200.0
    }
  ],
  "meta": {
    "total": 3842,
    "limit": 50,
    "next_cursor": "cur_abc123",
    "request_id": "req_01HX...",
    "timestamp": "2026-05-07T14:22:00Z"
  }
}

Get Single Linked Account

#
GEThttps://sandbox.api.getwishbone.io/v1/accounts/{wishbone_user_id}

Authentication

X-Wishbone-API-Key

Request

curl "https://sandbox.api.getwishbone.io/v1/accounts/b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34" \
  -H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"

Path parameters

wishbone_user_idstring (uuid)REQUIRED

Unlink a Cardholder

#
DELETEhttps://sandbox.api.getwishbone.io/v1/accounts/{wishbone_user_id}

Authentication

X-Wishbone-API-Key

Request

curl -X DELETE "https://sandbox.api.getwishbone.io/v1/accounts/b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34" \
  -H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET" \
  -H "Content-Type: application/json" \
  -d '{}'

Path parameters

wishbone_user_idstring (uuid)REQUIRED

Donations

Submit and track donation requests.

Submit Donation Request

#
POSThttps://sandbox.api.getwishbone.io/v1/donations/request

Authentication

X-Wishbone-API-Key

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/donations/request" \
  -H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET" \
  -H "Content-Type: application/json" \
  -d '{
    "bank_transaction_ref": "TXN-12345",
    "dollar_amount": 50,
    "fund_designation": "annual_fund",
    "school_id": "sch_tennessee"
  }'

Body

bank_transaction_refstringREQUIREDmax 255 chars, min 1 chars
dollar_amountnumberREQUIRED> 0

USD value after points conversion. Must be strictly positive.

fund_designationstringREQUIRED
school_idstringREQUIRED
cardholder_messagestringmax 500 chars
loyalty_program_idstring
metadataobject
notify_cardholderboolean
points_per_dollarnumber> 0
points_redeemedinteger>= 0
recurrence_cadence"monthly" | "quarterly"
recurringboolean
wishbone_user_idstring (uuid)

Response

HTTP/1.1 202 Accepted
{
  "success": true,
  "data": {
    "donation_id": "9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92",
    "status": "pending",
    "wishbone_user_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34",
    "school_id": "sch_tennessee",
    "fund_designation": "annual_fund",
    "dollar_amount": 50.0,
    "points_redeemed": 5000,
    "bank_transaction_ref": "TXN-12345",
    "created_at": "2026-05-07T14:22:00Z",
    "estimated_confirmation_at": "2026-05-07T14:27:00Z"
  },
  "meta": { "request_id": "req_01HX..." }
}

Get Donation Status

#
GEThttps://sandbox.api.getwishbone.io/v1/donations/{donation_id}

Authentication

X-Wishbone-API-Key

Request

curl "https://sandbox.api.getwishbone.io/v1/donations/9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92" \
  -H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"

Path parameters

donation_idstring (uuid)REQUIRED

Schools

Browse active schools and funds.

List Schools

#
GEThttps://sandbox.api.getwishbone.io/v1/schools

Authentication

X-Wishbone-API-Key

Request

curl "https://sandbox.api.getwishbone.io/v1/schools" \
  -H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"

Query parameters

searchstring
statestring
conferencestring
activeboolean
limitinteger>= 1, <= 100
cursorstring

Response

HTTP/1.1 200 OK
{
  "success": true,
  "data": [
    {
      "school_id": "sch_tennessee",
      "name": "Tennessee Fund",
      "university": "University of Tennessee",
      "nickname": "Volunteers",
      "city": "Knoxville",
      "state": "TN",
      "conference": "SEC",
      "logo_url": "https://cdn.getwishbone.io/schools/tennessee.svg",
      "minimum_donation_usd": 5.0,
      "active": true,
      "fund_count": 2,
      "total_raised_usd": 184250.0
    }
  ],
  "meta": {
    "total": 1,
    "limit": 50,
    "next_cursor": null,
    "request_id": "req_01HX..."
  }
}

Get School Detail

#
GEThttps://sandbox.api.getwishbone.io/v1/schools/{school_id}

Authentication

X-Wishbone-API-Key

Request

curl "https://sandbox.api.getwishbone.io/v1/schools/sch_tennessee" \
  -H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"

Path parameters

school_idstringREQUIRED

Embed

Tokens for iframe and app browser flows.

Generate Embed Token

#
POSThttps://sandbox.api.getwishbone.io/v1/embed/token

Authentication

X-Wishbone-API-Key

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/embed/token" \
  -H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET" \
  -H "Content-Type: application/json" \
  -d '{
    "wishbone_user_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34"
  }'

Body

wishbone_user_idstringREQUIRED
cancel_urlstring
dollar_amountnumber> 0
expires_ininteger>= 60, <= 900

Token TTL in seconds. Max 900 (15 min).

fund_designationstring
lock_amountboolean
lock_schoolboolean
return_urlstring
school_idstring
theme_overrideobject

Response

HTTP/1.1 200 OK
{
  "success": true,
  "data": {
    "embed_token": "wbt_gAAAAABm...",
    "embed_url": "https://embed.getwishbone.io/v1/session?token=wbt_gAAAAABm...",
    "expires_at": "2026-05-07T14:32:00Z"
  },
  "meta": { "request_id": "req_01HX..." }
}

Cardholder Portal API

Used by the Wishbone cardholder portal. Authenticates with a short-lived bearer token, not your bank API key.

Portal — Auth

Cardholder login, refresh, logout.

Forgot Password

#
POSThttps://sandbox.api.getwishbone.io/v1/portal/auth/forgot-password

Authentication

No authentication

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/auth/forgot-password" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "jane@acmebank.com"
  }'

Body

emailstring (email)REQUIRED

Cardholder Login

#
POSThttps://sandbox.api.getwishbone.io/v1/portal/auth/login

Authentication

No authentication

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/auth/login" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "jane@acmebank.com",
    "password": "••••••••"
  }'

Body

emailstring (email)REQUIRED
passwordstringREQUIRED
mfa_codestring

Response

HTTP/1.1 200 OK
{
  "success": true,
  "data": {
    "access_token": "eyJhbGciOiJIUzI1NiIs...",
    "refresh_token": "wbr_8f2c1d...",
    "token_type": "bearer",
    "expires_in": 3600
  },
  "meta": { "request_id": "req_01HX..." }
}

Logout

#
POSThttps://sandbox.api.getwishbone.io/v1/portal/auth/logout

Authentication

Authorization: Bearer <access_token>

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/auth/logout" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "refresh_token": "wbr_01HX..."
  }'

Body

refresh_tokenstringREQUIRED

Refresh Token

#
POSThttps://sandbox.api.getwishbone.io/v1/portal/auth/refresh

Authentication

No authentication

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/auth/refresh" \
  -H "Content-Type: application/json" \
  -d '{
    "refresh_token": "wbr_01HX..."
  }'

Body

refresh_tokenstringREQUIRED

Portal — Donations

Cardholder donation history and receipts.

List My Donations

#
GEThttps://sandbox.api.getwishbone.io/v1/portal/donations

Authentication

Authorization: Bearer <access_token>

Request

curl "https://sandbox.api.getwishbone.io/v1/portal/donations" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"

Query parameters

statusstring
school_idstring
fromstring (date-time)
tostring (date-time)
limitinteger>= 1, <= 100
cursorstring

Create Donation (Portal-Initiated)

#
POSThttps://sandbox.api.getwishbone.io/v1/portal/donations

Authentication

Authorization: Bearer <access_token>

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/donations" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "dollar_amount": 50,
    "fund_designation": "annual_fund",
    "loyalty_account_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34",
    "school_id": "sch_tennessee"
  }'

Body

dollar_amountnumberREQUIRED> 0
fund_designationstringREQUIRED
loyalty_account_idstring (uuid)REQUIRED
school_idstringREQUIRED
cardholder_messagestringmax 500 chars
notify_by_emailboolean

Get Donation Detail

#
GEThttps://sandbox.api.getwishbone.io/v1/portal/donations/{donation_id}

Authentication

Authorization: Bearer <access_token>

Request

curl "https://sandbox.api.getwishbone.io/v1/portal/donations/9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"

Path parameters

donation_idstring (uuid)REQUIRED

Get Tax Receipt

#
GEThttps://sandbox.api.getwishbone.io/v1/portal/donations/{donation_id}/receipt

Authentication

Authorization: Bearer <access_token>

Request

curl "https://sandbox.api.getwishbone.io/v1/portal/donations/9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92/receipt" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"

Path parameters

donation_idstring (uuid)REQUIRED

Resend Tax Receipt

#
POSThttps://sandbox.api.getwishbone.io/v1/portal/donations/{donation_id}/receipt/resend

Authentication

Authorization: Bearer <access_token>

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/donations/9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92/receipt/resend" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

Path parameters

donation_idstring (uuid)REQUIRED

Portal — Profile

Profile and loyalty accounts.

Get My Profile

#
GEThttps://sandbox.api.getwishbone.io/v1/portal/me

Authentication

Authorization: Bearer <access_token>

Request

curl "https://sandbox.api.getwishbone.io/v1/portal/me" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"

Update My Profile

#
PATCHhttps://sandbox.api.getwishbone.io/v1/portal/me

Authentication

Authorization: Bearer <access_token>

Request

curl -X PATCH "https://sandbox.api.getwishbone.io/v1/portal/me" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

Body

display_namestring
passwordany
phonestring
preferred_fundstring
preferred_school_idstring
tax_receipt_emailstring (email)

Get Linked Loyalty Accounts

#
GEThttps://sandbox.api.getwishbone.io/v1/portal/me/loyalty-accounts

Authentication

Authorization: Bearer <access_token>

Request

curl "https://sandbox.api.getwishbone.io/v1/portal/me/loyalty-accounts" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"

Portal — Schools

Cardholder-facing school discovery and follows.

Browse Schools (Portal)

#
GEThttps://sandbox.api.getwishbone.io/v1/portal/schools

Authentication

Authorization: Bearer <access_token>

Request

curl "https://sandbox.api.getwishbone.io/v1/portal/schools" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"

Query parameters

searchstring
statestring
conferencestring
followedboolean
limitinteger>= 1, <= 100
cursorstring

Follow / Unfollow a School

#
POSThttps://sandbox.api.getwishbone.io/v1/portal/schools/{school_id}/follow

Authentication

Authorization: Bearer <access_token>

Request

curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/schools/sch_tennessee/follow" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "follow": true
  }'

Path parameters

school_idstringREQUIRED

Body

followbooleanREQUIRED

Portal — Preferences

Communication preferences.

Get Communication Preferences

#
GEThttps://sandbox.api.getwishbone.io/v1/portal/preferences

Authentication

Authorization: Bearer <access_token>

Request

curl "https://sandbox.api.getwishbone.io/v1/portal/preferences" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"

Update Communication Preferences

#
PATCHhttps://sandbox.api.getwishbone.io/v1/portal/preferences

Authentication

Authorization: Bearer <access_token>

Request

curl -X PATCH "https://sandbox.api.getwishbone.io/v1/portal/preferences" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

Body

email_campaign_updatesboolean
email_donation_confirmationboolean
email_tax_receiptboolean
email_wishbone_newsletterboolean
marketing_opt_inboolean
push_donation_confirmationboolean
push_school_campaignsboolean
sms_campaign_alertsboolean
sms_donation_confirmationboolean