DE/EN/PT

Branding & integrations

API keys

API keys let an external club website communicate securely with Omoplata. Through the Integration API your website can show your live timetable and pull trial sign-ups straight into your club -- with no manual upkeep.

Navigate to Settings > API keys to manage your keys.


How it works

The Integration API is a server-to-server interface: your website's backend calls the API with the API key -- never the visitor's browser directly. That keeps the key secret on the server.

Visitor's browser
      │  (HTML/JS)
      ▼
External club website (SvelteKit / Nuxt / …)
      │  Authorization: Bearer {api_key}
      ▼
Omoplata Integration API  ←→  Club database

Each key belongs to your club only. Typical uses:

OptionDescription
Show your timetabledisplay your club's classes and sessions live on your website.
Trial sign-up formcreate leads in Omoplata from sign-ups submitted on your website.

Creating a key

Create a new API key in settings. You give it a name and tick what it may do. The plaintext key is shown only once -- right after you create it. Copy it immediately and store it securely in your website's server configuration. Only a hash is stored internally; the key itself cannot be retrieved again later.

Keep keys secret

Never expose an API key in the browser or in client-side code. It belongs only in your website's backend. If a key is ever leaked, revoke it and create a new one.


Permissions

A key can only do what you allow when you create it. Without the matching permission the request is rejected -- the tick box is the boundary, not a recommendation.

PermissionWhat the key may do
Read members & contractsRead members and their contracts, including ongoing sync. Covers personal data.
Register new membersCreate a full sign-up from your website as a member in Omoplata.
Read trial availabilityFetch the bookable trial sessions.
Submit trial sign-ups (leads)Create trial sign-ups as leads, plus their follow-ups (confirm the time, invite friends).
Read registration form dataFetch the sign-up form's configuration and contract text.

How much a key needs depends on what your website should do:

What your website should doPermissions needed
Timetable, plans, FAQs, testimonials and the contact formnone -- an active key with no permissions at all is enough. This is the content your club publishes anyway.
Trial sign-up formRead trial availability and Submit trial sign-ups (leads)
Full online sign-up as a memberRead registration form data and Register new members
Sync member data with another systemRead members & contracts

There is no full-access key: every key holds exactly the permissions you gave it. Use Edit to change them later -- the key itself stays the same.

As little as possible

Only grant what the integration genuinely needs. A trial sign-up form has no business reading your member data -- and a leaked key then cannot do more than it should.


Revoking a key

You can revoke a key at any time. Afterwards, all requests using that key are rejected -- create a new key and update your website's configuration.

For a full walkthrough of connecting your website, see Integrate with your website.

Was this page helpful?

Previous
Integrations