Tithe.ly Accounts API

Authentication and login.

OpenAPI Specification

tithely-accounts-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Tithe.ly Accounts API
  description: 'The Tithe.ly API lets churches and approved partners integrate with the Tithe.ly giving and church-technology platform. Access is gated: it is granted by request to organizations that use (or are moving to) Tithe.ly, and approved requesters receive public and private API keys by email. Two documented generations are modeled here. The V1 payments API handles PCI-safe tokenization (via the hosted Tithely.js library) and charging of tokenized cards and bank accounts. The V2 REST API handles login, organizations, payment categories (giving funds), donation transactions, and templated mail. Endpoint paths and methods are drawn from Tithe.ly''s public documentation; request and response schemas are modeled from the documented behavior because the full field-level schemas are only exposed to approved API-key holders in the private developer docs. Test traffic uses the tithelydev.com hosts; production uses tithe.ly.'
  version: '2.0'
  contact:
    name: Tithe.ly Support
    url: https://docs.tithe.ly/reference/introduction
    email: support@tithe.ly
servers:
- url: https://tithe.ly/api/v2
  description: V2 REST API (live)
- url: https://tithe.ly/api/v1
  description: V1 payments/tokenization API (live)
- url: https://tithelydev.com/api/v1
  description: V1 payments/tokenization API (test/sandbox)
tags:
- name: Accounts
  description: Authentication and login.
paths:
  /login:
    post:
      operationId: login
      tags:
      - Accounts
      summary: Authenticate a user
      description: Authenticates a user and returns the credentials used to form the Authorization header for subsequent V2 requests. This is the only V2 endpoint that does not itself require the Authorization header.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LoginInput'
      responses:
        '200':
          description: Authenticated. Returns API identity and token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LoginResult'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    LoginResult:
      type: object
      description: Modeled. Returns the identity/token used to build the Authorization header.
      properties:
        api_id:
          type: string
        api_token:
          type: string
        user_id:
          type: string
    LoginInput:
      type: object
      required:
      - email
      - password
      properties:
        email:
          type: string
          format: email
        password:
          type: string
          format: password
    Error:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
  responses:
    Unauthorized:
      description: Missing or invalid API credentials.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: 'V2 requests use the header "Authorization: {API_ID}:{API_TOKEN}", where the ID and token come from the public/private API keys issued on access approval (and via the login endpoint). V1 payment calls use the private key issued on approval.'