Loyal Aura
Developers

Build on the platform your business runs on.

A REST API, scoped keys and signed webhooks to issue passes, read members and react to events from your own stack — no scraping, no workarounds.

  • REST API
  • Live & test keys
  • Signed webhooks

What you get

A clean API for the same data your team works in.

REST API

Predictable, resource-oriented endpoints to issue and update passes, manage members and read loyalty activity — JSON in, JSON out.

Scoped API keys

Bearer keys with separate live and test environments. Keys are hashed at rest, show only a safe prefix, and can be revoked instantly.

Signed webhooks

Subscribe an endpoint to the events you care about. Each delivery is signed with a shared secret so you can verify it's really us.

Every event, delivered

React to scans, card installs, reward unlocks, tier changes and more — the same triggers that power automations, in your code.

Delivery logs

Every webhook attempt is logged with its response, so debugging a failed delivery is a glance, not a guess.

Built for trust

Key telemetry (last used, IP), optional auto-expiry and soft-delete recovery — security that holds up in production.

From key to integration

01

Create a key

Generate a live or test API key from your developer settings.

02

Call the API

Issue a pass or read a member with a single authenticated request.

03

Subscribe to webhooks

Point an endpoint at the events you want and verify the signature.

04

Ship

Wire the platform into your POS, CRM or product — and go live.

Frequently asked

Which plans include API access?+

The REST API, webhooks and custom integrations are available on the Scale plan. See pricing for details.

How does authentication work?+

Every request uses a bearer API key. Keys come in live and test environments, are hashed at rest, and can be revoked or set to auto-expire at any time.

What can I do with webhooks?+

Subscribe an endpoint to events like scans, card installs, reward unlocks and tier changes. Each delivery is signed so you can verify authenticity, and every attempt is logged.

Is there a sandbox?+

Yes. Use a test-environment key to build and verify your integration without touching live customer data.

Put the platform behind your own product.

Read the API reference, grab a test key, and start building.