GodKog API

REST-endepunkter for bookinger, medlemmer, events, betaling og mer. Alle svar er JSON.

Autentisering

Send API-nøkkelen som Bearer-token i Authorization-headeren:

Authorization: Bearer sk_...

Nøkler er scope-basert: read for GET, write for POST/DELETE. Bruk * for begge.

Base-URL

https://godkog.no

Endepunkter

GET/api/public/v1/bookingsscope: readListe bookinger for din bruker (eller alle med admin-nøkkel).
POST/api/public/v1/bookingsscope: writeOpprett ny booking (hold).
GET/api/public/v1/bookings/{id}scope: readHent én booking.
DELETE/api/public/v1/bookings/{id}scope: writeKanseller en booking.
GET/api/public/v1/membersscope: readListe medlemskap.
GET/api/public/v1/eventsscope: readKommende ritualer/workshops. Query: kind, from, limit.
GET/api/public/v1/events/{id}scope: readEvent-detaljer inkl. ledige plasser.
GET/api/public/v1/communityscope: readCommunity-innlegg (offentlige).
GET/api/public/v1/paymentsscope: readButikk-ordrer.
GET/api/public/v1/inventoryscope: readProdukter i butikk.
POST/api/public/v1/notificationsscope: writeTrigger notification-webhook (ingen push, fanes av dine webhooks).
GET/api/public/v1/analyticsscope: readNøkkeltall (bookinger, omsetning).

Eksempel: liste bookinger

curl https://godkog.no/api/public/v1/bookings \
  -H "Authorization: Bearer sk_..."

Eksempel: opprett booking

curl -X POST https://godkog.no/api/public/v1/bookings \
  -H "Authorization: Bearer sk_..." \
  -H "Content-Type: application/json" \
  -d '{
    "location_id": "uuid",
    "booking_type_id": "uuid",
    "starts_at": "2026-08-01T18:00:00Z",
    "guests": 2
  }'

Webhooks

Konfigurer én eller flere URL-er som mottar hendelser. Hver leveranse signeres med HMAC-SHA256:

POST https://din-server.no/webhook
x-godkog-event: booking.created
x-godkog-signature: <hex sha256 av body med din whsec_...>
content-type: application/json

{"event":"booking.created","data":{...},"at":"..."}

Tilgjengelige hendelser:

  • booking.created
  • booking.cancelled
  • notification.sent

Feilkoder

  • 401 missing_api_key / invalid_api_key — ugyldig eller manglende Bearer.
  • 403 insufficient_scope — nøkkelen mangler nødvendig scope.
  • 400 invalid_input — ugyldig body.
  • 404 not_found — ressursen finnes ikke eller er ikke din.