API Reference
Generated from the Wishbone OpenAPI schema (v1.0.0). Every endpoint below shows the exact request — method, URL, headers and body.
Base URLs
https://sandbox.api.getwishbone.ioTest keys (wbk_test_…). No real money moves.https://api.getwishbone.ioLive keys (wbk_live_…). Issued at onboarding.The machine-readable schema is at /openapi.json — point your codegen at it directly.
The hosted sandbox is not currently reachable. The reference below is generated from the shipped API schema and is accurate, but requests against sandbox.api.getwishbone.io will not succeed until the environment is live. See environment status.
Bank / Issuer API — contents
Cardholder Portal API — contents
Bank / Issuer API
Server-to-server. Your backend authenticates with an API key and never exposes it to a client.
Accounts
Link and manage cardholder accounts.
Link a Cardholder
#Authentication
X-Wishbone-API-KeyRequest
curl -X POST "https://sandbox.api.getwishbone.io/v1/accounts/link" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET" \
-H "Content-Type: application/json" \
-d '{
"bank_user_id": "cust_884219",
"display_name": "Jane Smith",
"email": "jane@acmebank.com",
"loyalty_program_id": "lp_chase_sapphire"
}'Body
bank_user_idstringREQUIREDmax 128 chars, min 1 charsdisplay_namestringREQUIREDmax 255 chars, min 1 charsemailstring (email)REQUIREDloyalty_program_idstringREQUIREDmax 64 chars, min 1 charsfund_designationstringmetadataobjectphonestringredirect_uristringschool_idstringtax_receipt_emailstring (email)Response
{
"success": true,
"data": {
"wishbone_user_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34",
"status": "active",
"oauth_redirect_url": null,
"linked_at": "2026-05-07T14:22:00Z"
},
"meta": { "request_id": "req_01HX..." }
}List Linked Accounts
#Authentication
X-Wishbone-API-KeyRequest
curl "https://sandbox.api.getwishbone.io/v1/accounts/linked" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"Query parameters
statusstringlimitinteger>= 1, <= 100cursorstringcreated_afterstring (date-time)created_beforestring (date-time)Response
{
"success": true,
"data": [
{
"wishbone_user_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34",
"bank_user_id": "cust_884219",
"email": "jane@acmebank.com",
"display_name": "Jane Smith",
"status": "active",
"linked_at": "2026-03-01T09:00:00Z",
"last_active_at": "2026-05-01T11:22:00Z",
"loyalty_program_id": "lp_chase_sapphire",
"preferred_school_id": "sch_tennessee",
"preferred_fund": "annual_fund",
"donation_count": 4,
"lifetime_donated_usd": 200.0
}
],
"meta": {
"total": 3842,
"limit": 50,
"next_cursor": "cur_abc123",
"request_id": "req_01HX...",
"timestamp": "2026-05-07T14:22:00Z"
}
}Get Single Linked Account
#Authentication
X-Wishbone-API-KeyRequest
curl "https://sandbox.api.getwishbone.io/v1/accounts/b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"Path parameters
wishbone_user_idstring (uuid)REQUIREDUnlink a Cardholder
#Authentication
X-Wishbone-API-KeyRequest
curl -X DELETE "https://sandbox.api.getwishbone.io/v1/accounts/b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET" \
-H "Content-Type: application/json" \
-d '{}'Path parameters
wishbone_user_idstring (uuid)REQUIREDDonations
Submit and track donation requests.
Submit Donation Request
#Authentication
X-Wishbone-API-KeyRequest
curl -X POST "https://sandbox.api.getwishbone.io/v1/donations/request" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET" \
-H "Content-Type: application/json" \
-d '{
"bank_transaction_ref": "TXN-12345",
"dollar_amount": 50,
"fund_designation": "annual_fund",
"school_id": "sch_tennessee"
}'Body
bank_transaction_refstringREQUIREDmax 255 chars, min 1 charsdollar_amountnumberREQUIRED> 0USD value after points conversion. Must be strictly positive.
fund_designationstringREQUIREDschool_idstringREQUIREDcardholder_messagestringmax 500 charsloyalty_program_idstringmetadataobjectnotify_cardholderbooleanpoints_per_dollarnumber> 0points_redeemedinteger>= 0recurrence_cadence"monthly" | "quarterly"recurringbooleanwishbone_user_idstring (uuid)Response
{
"success": true,
"data": {
"donation_id": "9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92",
"status": "pending",
"wishbone_user_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34",
"school_id": "sch_tennessee",
"fund_designation": "annual_fund",
"dollar_amount": 50.0,
"points_redeemed": 5000,
"bank_transaction_ref": "TXN-12345",
"created_at": "2026-05-07T14:22:00Z",
"estimated_confirmation_at": "2026-05-07T14:27:00Z"
},
"meta": { "request_id": "req_01HX..." }
}Get Donation Status
#Authentication
X-Wishbone-API-KeyRequest
curl "https://sandbox.api.getwishbone.io/v1/donations/9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"Path parameters
donation_idstring (uuid)REQUIREDSchools
Browse active schools and funds.
List Schools
#Authentication
X-Wishbone-API-KeyRequest
curl "https://sandbox.api.getwishbone.io/v1/schools" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"Query parameters
searchstringstatestringconferencestringactivebooleanlimitinteger>= 1, <= 100cursorstringResponse
{
"success": true,
"data": [
{
"school_id": "sch_tennessee",
"name": "Tennessee Fund",
"university": "University of Tennessee",
"nickname": "Volunteers",
"city": "Knoxville",
"state": "TN",
"conference": "SEC",
"logo_url": "https://cdn.getwishbone.io/schools/tennessee.svg",
"minimum_donation_usd": 5.0,
"active": true,
"fund_count": 2,
"total_raised_usd": 184250.0
}
],
"meta": {
"total": 1,
"limit": 50,
"next_cursor": null,
"request_id": "req_01HX..."
}
}Get School Detail
#Authentication
X-Wishbone-API-KeyRequest
curl "https://sandbox.api.getwishbone.io/v1/schools/sch_tennessee" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET"Path parameters
school_idstringREQUIREDEmbed
Tokens for iframe and app browser flows.
Generate Embed Token
#Authentication
X-Wishbone-API-KeyRequest
curl -X POST "https://sandbox.api.getwishbone.io/v1/embed/token" \
-H "X-Wishbone-API-Key: wbk_test_YOUR_KEY_ID:YOUR_SECRET" \
-H "Content-Type: application/json" \
-d '{
"wishbone_user_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34"
}'Body
wishbone_user_idstringREQUIREDcancel_urlstringdollar_amountnumber> 0expires_ininteger>= 60, <= 900Token TTL in seconds. Max 900 (15 min).
fund_designationstringlock_amountbooleanlock_schoolbooleanreturn_urlstringschool_idstringtheme_overrideobjectResponse
{
"success": true,
"data": {
"embed_token": "wbt_gAAAAABm...",
"embed_url": "https://embed.getwishbone.io/v1/session?token=wbt_gAAAAABm...",
"expires_at": "2026-05-07T14:32:00Z"
},
"meta": { "request_id": "req_01HX..." }
}Cardholder Portal API
Used by the Wishbone cardholder portal. Authenticates with a short-lived bearer token, not your bank API key.
Portal — Auth
Cardholder login, refresh, logout.
Forgot Password
#Authentication
No authenticationRequest
curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/auth/forgot-password" \
-H "Content-Type: application/json" \
-d '{
"email": "jane@acmebank.com"
}'Body
emailstring (email)REQUIREDCardholder Login
#Authentication
No authenticationRequest
curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/auth/login" \
-H "Content-Type: application/json" \
-d '{
"email": "jane@acmebank.com",
"password": "••••••••"
}'Body
emailstring (email)REQUIREDpasswordstringREQUIREDmfa_codestringResponse
{
"success": true,
"data": {
"access_token": "eyJhbGciOiJIUzI1NiIs...",
"refresh_token": "wbr_8f2c1d...",
"token_type": "bearer",
"expires_in": 3600
},
"meta": { "request_id": "req_01HX..." }
}Logout
#Authentication
Authorization: Bearer <access_token>Request
curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/auth/logout" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"refresh_token": "wbr_01HX..."
}'Body
refresh_tokenstringREQUIREDRefresh Token
#Authentication
No authenticationRequest
curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/auth/refresh" \
-H "Content-Type: application/json" \
-d '{
"refresh_token": "wbr_01HX..."
}'Body
refresh_tokenstringREQUIREDPortal — Donations
Cardholder donation history and receipts.
List My Donations
#Authentication
Authorization: Bearer <access_token>Request
curl "https://sandbox.api.getwishbone.io/v1/portal/donations" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"Query parameters
statusstringschool_idstringfromstring (date-time)tostring (date-time)limitinteger>= 1, <= 100cursorstringCreate Donation (Portal-Initiated)
#Authentication
Authorization: Bearer <access_token>Request
curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/donations" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"dollar_amount": 50,
"fund_designation": "annual_fund",
"loyalty_account_id": "b3d1f0c2-8a4e-4f77-9c2f-1e5a7d9b0c34",
"school_id": "sch_tennessee"
}'Body
dollar_amountnumberREQUIRED> 0fund_designationstringREQUIREDloyalty_account_idstring (uuid)REQUIREDschool_idstringREQUIREDcardholder_messagestringmax 500 charsnotify_by_emailbooleanGet Donation Detail
#Authentication
Authorization: Bearer <access_token>Request
curl "https://sandbox.api.getwishbone.io/v1/portal/donations/9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"Path parameters
donation_idstring (uuid)REQUIREDGet Tax Receipt
#Authentication
Authorization: Bearer <access_token>Request
curl "https://sandbox.api.getwishbone.io/v1/portal/donations/9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92/receipt" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"Path parameters
donation_idstring (uuid)REQUIREDResend Tax Receipt
#Authentication
Authorization: Bearer <access_token>Request
curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/donations/9f14c6d2-7b3a-4e51-a0c8-2d6b8e4f1a92/receipt/resend" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'Path parameters
donation_idstring (uuid)REQUIREDPortal — Profile
Profile and loyalty accounts.
Get My Profile
#Authentication
Authorization: Bearer <access_token>Request
curl "https://sandbox.api.getwishbone.io/v1/portal/me" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"Update My Profile
#Authentication
Authorization: Bearer <access_token>Request
curl -X PATCH "https://sandbox.api.getwishbone.io/v1/portal/me" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'Body
display_namestringpasswordanyphonestringpreferred_fundstringpreferred_school_idstringtax_receipt_emailstring (email)Get Linked Loyalty Accounts
#Authentication
Authorization: Bearer <access_token>Request
curl "https://sandbox.api.getwishbone.io/v1/portal/me/loyalty-accounts" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"Portal — Schools
Cardholder-facing school discovery and follows.
Browse Schools (Portal)
#Authentication
Authorization: Bearer <access_token>Request
curl "https://sandbox.api.getwishbone.io/v1/portal/schools" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"Query parameters
searchstringstatestringconferencestringfollowedbooleanlimitinteger>= 1, <= 100cursorstringFollow / Unfollow a School
#Authentication
Authorization: Bearer <access_token>Request
curl -X POST "https://sandbox.api.getwishbone.io/v1/portal/schools/sch_tennessee/follow" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"follow": true
}'Path parameters
school_idstringREQUIREDBody
followbooleanREQUIREDPortal — Preferences
Communication preferences.
Get Communication Preferences
#Authentication
Authorization: Bearer <access_token>Request
curl "https://sandbox.api.getwishbone.io/v1/portal/preferences" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"Update Communication Preferences
#Authentication
Authorization: Bearer <access_token>Request
curl -X PATCH "https://sandbox.api.getwishbone.io/v1/portal/preferences" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'Body
email_campaign_updatesbooleanemail_donation_confirmationbooleanemail_tax_receiptbooleanemail_wishbone_newsletterbooleanmarketing_opt_inbooleanpush_donation_confirmationbooleanpush_school_campaignsbooleansms_campaign_alertsbooleansms_donation_confirmationboolean