Skip to content

API overview

The Kudosky Public API lets you pull people, kudos, rewards and anonymous mood data into BI tools, spreadsheets and your own systems, and import a reward catalogue from another system.

https://kmlrvcofvtzdlbomxrbp.supabase.co/functions/v1/external-api

An admin creates keys under Integrations → Public API → Create key:

  1. Name the key after what uses it, for example Power BI dashboard.
  2. Tick only the scopes it needs.
  3. Copy the key. It starts with sk_live_ and is shown once. Store it in a password manager or secrets store.

Revoking a key stops every integration using it immediately.

Send the key in either header:

Authorization: Bearer sk_live_…
X-API-Key: sk_live_…

A request only ever sees the company that owns the key.

Scope Allows
read:members GET /members: names, emails, roles and teams
read:activity GET /activity: kudos with sender, recipient and category
read:rewards GET /rewards: the reward catalogue
read:analytics GET /day-ratings and GET /pulse-responses, without identities
write:rewards POST /rewards: import a catalogue

New keys get read:members and read:activity by default.

Terminal window
curl "https://kmlrvcofvtzdlbomxrbp.supabase.co/functions/v1/external-api/activity?limit=10" \
-H "Authorization: Bearer sk_live_…"

Calling the base URL with no path checks a key: it returns the API version, the key’s scopes and the endpoints.

Parameter Applies to Meaning
limit every list 1–1000, default 100
format every list json (default) or csv
since, until activity, day ratings, pulse ISO 8601 time range
team_id members, day ratings one team
role members one role
category_id, sender_id, receiver_id activity one category or person
include_archived=true rewards include archived rewards

Lists are newest first. There is no paging cursor: narrow the window with since and until to fetch more than 1000 rows.

Status When
400 Invalid body when importing rewards. Nothing is written.
401 Missing, malformed or revoked key.
403 The key lacks the scope for this endpoint.
500 Something failed on our side. Details are logged, not returned.

Errors look like { "error": "…" }. Every endpoint is in the reference.