Skip to content

Tipping — API endpoints

Base domain

  • https://tips.streamercatalyst.com

The public tip page and its checkout are served on the apex domain, https://streamercatalyst.com/tip/<login>, which the web Worker forwards here. The old tips.streamercatalyst.com/tip/<login> address redirects there.

The StreamerCatalyst dashboard calls the session endpoints same-origin through https://streamercatalyst.com/m/tipping/* (for example /m/tipping/api/channels/:id/config reaches /api/channels/:id/config here). That proxy forwards the session cookie over a Cloudflare service binding and never forwards /internal/*.

Endpoints

PathMethodAuthDescription
/tip/:loginGETPublicThe public tip page, at streamercatalyst.com/tip/<login>.
/tip/checkoutPOSTPublicStarts a Stripe Checkout for a tip from the tip page. Turnstile-verified and rate-limited per IP.
/tip/auth/*GETPublicOptional “tip as your Twitch account” sign-in (start, callback): an identity-only Twitch OAuth with no scopes, bound into a signed token and never a session.
/webhooks/stripePOSTStripe HMAC signatureStripe payment webhook: a tip settles, is refunded, or is disputed.
/webhooks/stripe-connectPOSTStripe HMAC signatureStripe Connect webhook: changes to a streamer’s payout account.
/api/channels/:id/configGET/PUTSession cookieTipping settings, including amount limits and anonymity. Any channel session may read; saving needs the broadcaster or a Lead Mod.
/api/channels/:id/tipsGETSession cookiePaginated tip ledger (?status=&limit=&cursor=). Carries no payer personal data, and anonymous tips carry no name.
/api/channels/:id/tips/summaryGETSession cookieSettled totals for today, 7 days and 30 days, plus the active goal.
/api/channels/:id/tips/heldGETSession cookieTip messages held for approval.
/api/channels/:id/tips/:tipId/approvePOSTSession cookieRelease a held message to alerts and chat (broadcaster or Lead Mod).
/api/channels/:id/tips/:tipId/rejectPOSTSession cookieSuppress a held message; the tip still counts toward totals and the goal (broadcaster or Lead Mod).
/api/channels/:id/tips/manualPOSTSession cookieRecord an off-platform tip by hand (broadcaster or Lead Mod).
/api/channels/:id/goalsGET/POSTSession cookieDonation goals (active, archived, and recent adjustments), or create one. One goal is active per channel.
/api/channels/:id/goals/:goalIdPATCHSession cookieEdit, activate, or deactivate a goal.
/api/channels/:id/goals/:goalId/archivePOSTSession cookieFreeze a goal.
/api/channels/:id/goals/:goalId/adjustmentsPOSTSession cookieCredit an off-platform amount to a goal (a signed delta). A positive one is also announced as a tip unless announce: false.
/api/channels/:id/connect/onboardPOSTSession cookieCreate or resume the Stripe Connect payout account; returns a Stripe onboarding link.
/api/channels/:id/connect/statusGETSession cookiePayout-account status: eligibility, whether charges and payouts are enabled, what Stripe still needs, and recent payouts.
/api/channels/:id/connect/disconnectPOSTSession cookieUnlink the payout account; tips already in flight still settle.
/internal/widget-dataPOSTService binding (internal)Active donation-goal progress for the goal widget (internal).
/internal/tips/*GET/POSTService binding (internal)Disputed-tip queue and refunds for the admin console (internal).

Auth model

  • Session cookie endpoints require an active StreamerCatalyst session (set at login via the platform Worker). A channel-scoped route (/api/channels/:id/…) answers only for the session’s own channel, and a read-only admin masquerade may read but not change anything.
  • Public endpoints require no authentication.
  • Signature-verified endpoints accept only requests signed by Stripe; anything unsigned or altered is refused.
  • Service binding endpoints are for other StreamerCatalyst Workers, called over Cloudflare service bindings with a shared internal token. They are not a public API.