Developers
Build on the Stow Cards API
Enroll members, adjust points and redeem rewards from your own systems with a REST API, and hear about new members, points, redemptions, scans and pass updates through signed webhooks. Points and reward changes rebuild the customer’s wallet pass and push it to their phone.
Sign in to the Stow Cards console and open API Keys, under Administration in the sidebar. A key is shown once when you create it, so store it somewhere safe.
Quickstart
Your first call
Send the key in an X-API-Key header. This call adds 25 points to a member. The reply gives the old and new balance and how many of the member’s iPhones accepted the update push.
- REST and JSON over HTTPS, through the same gateway as the console
- Each key is bound to your merchant and carries only the roles you give it
- An Idempotency-Key on points and redemptions, so a retry within 24 hours never applies twice
- Example clients in Node.js, Python, PHP, Ruby and Go, plus a curl script, run the same four calls end to end
# Add points to a member and push the update to their wallet
curl -X PATCH https://api.stow.cards/api/v1/merchants/me/members/MEMBER_UUID/points \
-H "X-API-Key: $STOW_API_KEY" \
-H "Idempotency-Key: 018f3c2e-9d41-7c3a-b5e6-2f8d5b6a7c3d" \
-H "Content-Type: application/json" \
-d '{ "delta": 25, "changeMessage": "Thanks for your purchase!" }'
# 200 OK (abridged)
{
"success": true,
"data": {
"member": { "id": "MEMBER_UUID", "memberCode": "7K2Q9FMRDC" },
"previous": 265,
"current": 290,
"passUpdate": { "apple": { "devicesNotified": 1 } }
}
}
MEMBER_UUID is the id the API returns when you enroll a member or search for their Member ID. It is not the Member ID printed on the pass.
What you can build
The loyalty loop, from your own code
Members
Enroll a customer into a program and their pass is issued for both wallets. Find members by Member ID, name, email or phone number, tag them and read their history.
Member endpointsPoints and rewards
Add or set points, redeem a full card and change a member’s status. Each change rebuilds the pass and pushes it to the phone, with an optional message for the customer.
Points endpointsCSV import
Upload a CSV of up to 5,000 rows into a program. Each row comes back as created, matched to an existing member by email, or failed with the reason.
Import endpointWebhooks
Subscribe an HTTPS endpoint to 12 event types, from new members to scans. Deliveries are signed with HMAC-SHA256, retried on failure, logged and replayable.
Event catalogDocumentation
Where to go next
API reference
Every endpoint with its parameters, schemas and examples, rendered from the OpenAPI spec, starting with a four-call quickstart.
Open the referenceWebhooks guide
The delivery headers, retries and replays, and how to check a signature in Node.js and Python.
Read the guideOpenAPI file
The OpenAPI 3.1 document behind these pages, to load into your own tools.
Get openapi.json