Qgiv Account Settings API

Confirmed. Read and update organization and form settings.

OpenAPI Specification

qgiv-account-settings-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Qgiv Account Settings API
  description: The Qgiv API is a token-authenticated, form-scoped service for reading and writing data behind Qgiv (now Bloomerang Fundraising) donation forms, events, and peer-to-peer campaigns. Qgiv was acquired by Bloomerang in January 2024; this legacy API documented at qgiv.com/api remains the programmatic interface for Qgiv accounts. All requests are made with HTTP POST to https://secure.qgiv.com/admin/api, carrying a `token` field bound to one or more forms. Input is accepted as XML or JSON via a `package` field for write operations; output format is selected by the URL file extension (`.xml` or `.json`), independent of the request's input format. There is no bearer/OAuth layer, no documented API versioning scheme, and no documented public webhook subscription endpoint - some endpoints are modeled here directly from the vendor's own documentation examples (marked Confirmed), and request/response bodies for write operations not fully illustrated in the docs are modeled by API Evangelist from the documented example payloads (marked Modeled).
  version: '1.0'
  contact:
    name: Qgiv (Bloomerang Fundraising)
    url: https://www.qgiv.com/api/
  license:
    name: Proprietary
    url: https://www.qgiv.com/terms-of-service
servers:
- url: https://secure.qgiv.com/admin/api
  description: Qgiv production API
security:
- tokenAuth: []
tags:
- name: Account Settings
  description: Confirmed. Read and update organization and form settings.
paths:
  /account/settings:
    get:
      operationId: getAccountSettings
      tags:
      - Account Settings
      summary: Get organization and form settings (Confirmed)
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/TokenOnlyRequest'
      responses:
        '200':
          description: Organization and per-form settings.
          content:
            application/json:
              schema:
                type: object
                properties:
                  settings:
                    $ref: '#/components/schemas/AccountSettings'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: updateAccountSettings
      tags:
      - Account Settings
      summary: Update organization and form settings (Confirmed)
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/PackageRequest'
      responses:
        '200':
          description: The updated settings.
          content:
            application/json:
              schema:
                type: object
                properties:
                  settings:
                    $ref: '#/components/schemas/AccountSettings'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '422':
          $ref: '#/components/responses/ValidationError'
components:
  responses:
    Unauthorized:
      description: Missing or invalid API token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    ValidationError:
      description: The request payload failed validation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  schemas:
    AccountSettings:
      type: object
      properties:
        organization:
          type: object
          properties:
            title:
              type: string
            contactEmail:
              type: string
            contactURL:
              type: string
        forms:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
              activeDonation:
                type: string
              restrictionClass:
                type: string
    PackageRequest:
      type: object
      required:
      - token
      - package
      properties:
        token:
          type: string
          description: API token bound to the form(s) being accessed.
        package:
          type: string
          description: XML- or JSON-formatted input payload for the write operation.
    TokenOnlyRequest:
      type: object
      required:
      - token
      properties:
        token:
          type: string
          description: API token bound to the form(s) being accessed.
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
            message:
              type: string
  securitySchemes:
    tokenAuth:
      type: apiKey
      in: query
      name: token
      description: Documented as a POST body field (`token=<API token>`), not a header or querystring value. Modeled here as an apiKey scheme because OpenAPI 3.0 has no first-class "form field" security type. The token is scoped to one or more specific forms in the Qgiv admin console.