Skip to content

API Reference ​

Onboard.Ninja exposes a public claim API and (on SaaS) a Sanctum-authenticated proxy API.

Claim API (public) ​

Used by the claim page / QR deep link to redeem a code.

POST /api/claim/v1/{campaign}
FieldRequiredDescription
codeyesThe claim code being redeemed.
addressyesRecipient's Cardano (bech32) wallet address.

The endpoint validates the code (existence, remaining uses, per-wallet limit) and the address (bech32 charset and length), then records a claim and queues delivery via the configured backend. It is rate-limited per IP and per campaign (see Configuration).

Typical rejections: unknown/exhausted code, invalid address, nonexistent campaign.

QR codes encode a web+cardano://claim/v1?... URI alongside the campaign claim URL so compatible wallets/handlers can launch the claim flow directly.

Proxy API (SaaS, Sanctum) ​

The proxy API lets a self-hosted instance relay transactions through the hosted backend — set TRANSACTION_BACKEND=proxy and provide a PROXY_API_TOKEN. Create the token on your SaaS Profile → API Tokens page (it's shown once — copy it immediately).

Authenticate with a bearer token:

Authorization: Bearer {id}|{token}

Endpoints (all under /api/v1/proxy, Sanctum-authenticated):

MethodEndpointPurpose
GET/balanceBucket/account balance
POST/paymentSubmit a payment/transaction
GET/status/{id}Transaction status
POST/refundRefund unclaimed funds

Proxy usage counts against your monthly quota (PROXY_MONTHLY_LIMIT, default 1000). Unauthenticated or invalid-token requests return 401.

The proxy API and API tokens are SaaS-only. The self-hosted edition consumes them (as a client) but does not issue them. See Editions.

Released under the Apache License 2.0.