Skip to content

Integrations — API endpoints

Base domain

  • https://streamercatalyst.com

This Worker has no public hostname of its own. It is reached only through the web Worker at streamercatalyst.com: /m/integrations/* for the dashboard API and the Tiltify sign-in return, and /webhooks/tiltify for Tiltify’s webhook. The paths below are those public paths.

Endpoints

PathMethodAuthDescription
/m/integrations/api/channels/:id/tiltifyGETSession cookieThe Tiltify card’s state: whether an account is connected, and which campaign is linked.
/m/integrations/api/channels/:id/tiltify/connectPOSTSession cookieStart connecting a Tiltify account; returns the Tiltify authorization URL.
/m/integrations/oauth/tiltify/callbackGETOAuth stateTiltify returns here after you authorize. Checked against the state issued at connect, because the session cookie is not sent on a redirect from tiltify.com.
/m/integrations/api/channels/:id/tiltify/campaignsGETSession cookieThe connected Tiltify account’s published campaigns.
/m/integrations/api/channels/:id/tiltify/linkPOST/DELETESession cookieLink a campaign ({ campaign_id }), or unlink it.
/m/integrations/api/channels/:id/tiltify/accountDELETESession cookieUnlink the campaign and forget the Tiltify account.
/webhooks/tiltifyPOSTTiltify HMAC signatureTiltify’s donation webhook, forwarded with the body unread so its signature verifies. Each donation enters the platform as catalyst.charity.donate.

Auth model

  • Session cookie endpoints require an active StreamerCatalyst session (set at login via the platform Worker). A channel-scoped route (/api/channels/:id/…) answers only for the session’s own channel, and a read-only admin masquerade may read but not change anything.
  • OAuth state endpoints are the return leg of a sign-in or account-link redirect. They are accepted only with the state value issued when that flow started.
  • Signature-verified endpoints accept only requests signed by Tiltify; anything unsigned or altered is refused.