Resource configuration and account history
Use current-resource configuration for the authenticated integration, the resource list for transaction-linked publications, or grouped reads for memberships, purchases and payment status. Resource and membership terms explain the context. Grouped pages paginate resources; nested records are not paginated.
Member and resource context
Use the supplied API base, resource public key and existing member token. Firebase-enabled members also need their matching ID token. The current-resource operation is authenticated even though its result contains public configuration; it has the session-check exception described locally.
The resource list selects transaction-linked publications. The three grouped summaries instead select active related resources of active partners sharing the selected resource’s partner. Shared context errors apply according to each operation. Examples follow the sample conventions.
Grouped summary selection
Results include active resources of active partners that both have a relationship with this user and share the selected resource’s partner. The outer page/limit paginate those resources; nested records are unpaginated. No requested filter conditions or sort order are applied to the resource selection. Empty results still use items: [{"resources": []}].
This applies to the membership, purchase and transaction summaries, not the transaction-linked resource list. The filter input is parsed and validated but its conditions are not applied; invalid input can therefore still produce an error.
Operations
| Operation | Method / path |
|---|---|
| Get current resource configuration | GET /api/v1/resource |
| List resources used by the user | GET /api/v1/user/resources |
| Read subscriptions grouped by resource | GET /api/v1/user/resources/subscriptions |
| Read purchases grouped by resource | GET /api/v1/user/resources/purchases |
| Read transactions grouped by resource | GET /api/v1/user/resources/transactions |
Get current resource configuration
GET /api/v1/resource
Read public integration configuration for the selected resource. Despite its public-resource name, this operation’s role/context requires an active user; it is not the guest embedded-settings endpoint.
Before you call
Use an existing active member token and resource public key. Despite its short path, this is an authenticated user operation. Payment-system configuration must exist for its selected provider branch. See member and resource context for supplied configuration and shared checks.
Request
GET with no request body or request Content-Type requirement. Response media type is JSON. Requires the user role or inherited permission and active member context. See credential transport.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
resource | header | string | required context | Public resource key; not the secret. |
token | header | string | member context | Existing member-session token. |
firebase-token | header | string | Firebase-enabled member context | Configured Firebase ID token alongside the Wallkit token; see credential transport. |
This action is excluded from ordinary session expiry/revocation checks, but role and user/resource guards still apply. No query fields, filters, sort or pagination are read.
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
public_key | string | Selected resource public key. |
origin | stored string / nullable | Configured resource origin. |
payments_in_live_mode | boolean | Configured live-payment mode, default true when unset. Does not itself make a charge. |
web_app_config | configured object / null | Enabled Firebase account configuration, otherwise null; account-defined keys, not a universal fixed schema. |
default_payment_system | string | Selected default payment-system label. |
stripe_public_key | string / nullable; Stripe branch | Public Stripe key from resource/global configuration. |
app_id, location_id | configured strings; Square branch | Square application and location identifiers; no secret access token in this projection. |
Example: get current resource configuration
The authenticated integration selects Stripe in non-live mode. web_app_config is null because no enabled Firebase configuration is attached. Supply the sample configuration and runtimes. These three requests are equivalent.
cURL
curl "${WALLKIT_API_BASE}/api/v1/resource" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
const url = new URL("/api/v1/resource", process.env.WALLKIT_API_BASE);
const headers = { resource: process.env.RESOURCE_KEY, token: process.env.USER_TOKEN };
const response = await fetch(url, { method: "GET", headers });
const body = await response.json();
console.log(response.status, body);
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/resource")
headers = {"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]}
request = Request(url, headers=headers, method="GET")
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"public_key": "example-resource",
"origin": "https://example.com",
"payments_in_live_mode": false,
"web_app_config": null,
"default_payment_system": "stripe",
"stripe_public_key": "EXAMPLE_STRIPE_PUBLIC_KEY"
}
Alternate result
No enabled Firebase web-app configuration is attached. Do not initialize Firebase from a null object; consult the integration configuration if it is expected.
Response excerpt:
{
"web_app_config": null
}
Recovery
| HTTP status | API code / response | Cause | Next action |
|---|---|---|---|
| 401 | auth_failed | Required identity is missing. | Supply the existing member token and check its selected resource context. |
| 401 | auth_access_fail | Inactive account or locked/suspended resource relationship. | Ask the administrator to check account activation and the resource relationship’s lock/suspension state. |
| 401 / 403 | access | Role does not permit the operation. | Use an identity permitted for this action; ask the administrator to check the assigned role. |
| 404 | resource_not_exists | Required resource is missing or unknown. | Check the resource public key and selected integration context with the administrator. |
See member and resource context for applicable shared checks; follow the local error table above.
Next task
Read embedded settings when configuring the guest-facing integration; use the appropriate credential context for that call.
List resources used by the user
GET /api/v1/user/resources
List resources where this user has at least one transaction. This list spans transaction history across resources. The summary operations below instead require user relationships and a shared partner.
Before you call
Use an existing member token and its normal resource context for session resolution. This list spans transaction-linked resources; the resource header does not restrict it to one resource. See member and resource context for supplied configuration and shared checks.
Request
GET with no request body or request Content-Type requirement. Response media type is JSON. Requires the user role or inherited permission and active member context. See credential transport.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
resource | header | string | supply for integration/session context | Public resource key; not the secret. |
token | header | string | member context | Existing member-session token. |
firebase-token | header | string | Firebase-enabled member context | Configured Firebase ID token alongside the Wallkit token. |
page | query | integer | optional | Use 1 for the first page; pass it explicitly. No explicit omitted-page default in the operation. |
limit | query | integer | optional | Default 10. No universal maximum is specified. |
filter | query | bracket object | optional | Resource model fields, e.g. filter[title]; framework Criteria parsing, not the JSON-string CriteriaFilter recipe. |
No explicit by, order or sort is read. Use the summary calls for nested account records. Resource header remains the session-resolution context; it does not restrict this query to only that resource.
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
items[] | object | Only title, key and host (stored strings/nullable text). Resources with a transaction associated with this user; not every resource membership. |
paginator uses the collection fields. An empty collection is an ordinary result; do not interpret it as an authentication failure.
Example: list resources used by the user
The member has a transaction in Example publication. The response returns its name/key/host, not a membership or payment record. Supply the sample configuration and runtimes. These three requests are equivalent.
cURL
curl "${WALLKIT_API_BASE}/api/v1/user/resources?page=1&limit=10" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
const url = new URL("/api/v1/user/resources", process.env.WALLKIT_API_BASE);
url.searchParams.set("page", "1");
url.searchParams.set("limit", "10");
const headers = { resource: process.env.RESOURCE_KEY, token: process.env.USER_TOKEN };
const response = await fetch(url, { method: "GET", headers });
const body = await response.json();
console.log(response.status, body);
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/user/resources")
url += "?" + urlencode({'page': '1', 'limit': '10'})
headers = {"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]}
request = Request(url, headers=headers, method="GET")
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"items": [
{
"title": "Example publication",
"key": "example-resource",
"host": "https://example.com"
}
]
}
Alternate result
No matching records on this page. Show an empty state; review the member/resource context or filters if unexpected. Do not treat an empty list as permission or as an API error.
Response excerpt:
{
"items": []
}
Recovery
| HTTP status | API code / response | Cause | Next action |
|---|---|---|---|
| 401 | auth_failed | Required identity is missing. | Supply the existing member token and check its selected resource context. |
| 401 | auth_access_fail | Inactive account or locked/suspended resource relationship. | Ask the administrator to check account activation and the resource relationship’s lock/suspension state. |
| 401 / 403 | access | Role does not permit the operation. | Use an identity permitted for this action; ask the administrator to check the assigned role. |
See member and resource context for applicable shared checks; follow the local error table above.
Next task
Read transaction summaries to explain this user’s history inside each selected resource.
Read subscriptions grouped by resource
GET /api/v1/user/resources/subscriptions
Read the user’s plan memberships grouped by related resources of the selected partner. This summarizes existing memberships; it does not purchase or change them.
Before you call
Use an existing member token and selected resource context. Results come from related active resources of active partners sharing that resource’s partner. See member and resource context for supplied configuration and shared checks.
Request
GET with no request body or request Content-Type requirement. Response media type is JSON. Requires the user role or inherited permission and active member context. See credential transport.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
resource | header | string | required context | Public resource key; not the secret. |
token | header | string | member context | Existing member-session token. |
firebase-token | header | string | Firebase-enabled member context | Configured Firebase ID token alongside the Wallkit token. |
page | query | integer | optional | Use 1 for the first page; pass it explicitly. No explicit omitted-page default in the operation. |
limit | query | integer | optional | Default 10. No universal maximum is specified. |
filter | query | object / JSON string | optional | Resource-model filter syntax is parsed/validated, but its conditions are not applied to the resource selection in these summary calls. Do not rely on it to restrict results. |
See grouped summary selection for the resource set, pagination, ignored filters and empty wrapper.
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
items[].resources[] | resource and memberships | Use grouped resource fields and membership summaries. |
paginator uses the collection fields. An empty collection is an ordinary result; do not interpret it as an authentication failure.
Example: read subscriptions grouped by resource
Show this member’s Monthly membership expiration and renewal choice under Example publication. Supply the sample configuration and runtimes. These three requests are equivalent.
cURL
curl "${WALLKIT_API_BASE}/api/v1/user/resources/subscriptions?page=1&limit=10" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
const url = new URL("/api/v1/user/resources/subscriptions", process.env.WALLKIT_API_BASE);
url.searchParams.set("page", "1");
url.searchParams.set("limit", "10");
const headers = { resource: process.env.RESOURCE_KEY, token: process.env.USER_TOKEN };
const response = await fetch(url, { method: "GET", headers });
const body = await response.json();
console.log(response.status, body);
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/user/resources/subscriptions")
url += "?" + urlencode({'page': '1', 'limit': '10'})
headers = {"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]}
request = Request(url, headers=headers, method="GET")
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"items": [
{
"resources": [
{
"id": 1001,
"title": "Example publication",
"key": "example-resource",
"host": "https://example.com",
"plans": [
{
"id": 1001,
"title": "Reader plan",
"slug": "reader",
"description": "Example membership",
"subscription": {
"id": 2001,
"title": "Monthly",
"expiration_date": "2026-12-01 00:00:00",
"autorenew": true
}
}
]
}
]
}
]
}
Alternate result
No resources match the partner/user selection on this page. Keep the wrapper shape; nested records are not separately paginated.
Response excerpt:
{
"items": [
{
"resources": []
}
]
}
Recovery
| HTTP status | API code / response | Cause | Next action |
|---|---|---|---|
| 401 | auth_failed | Required identity is missing. | Supply the existing member token and check its selected resource context. |
| 401 | auth_access_fail | Inactive account or locked/suspended resource relationship. | Ask the administrator to check account activation and the resource relationship’s lock/suspension state. |
| 401 / 403 | access | Role does not permit the operation. | Use an identity permitted for this action; ask the administrator to check the assigned role. |
| 409 | invalid_<field> | Parsed resource filter validation fails; code is built from the failing field (for example invalid_filter_date). | Remove or correct the named filter field. Filter conditions do not restrict these grouped reads; use the documented selection rules. |
See member and resource context for applicable shared checks; follow the local error table above.
Next task
Read the selected resource’s member plans when you need the richer singular membership projection.
Read purchases grouped by resource
GET /api/v1/user/resources/purchases
Read this user’s purchases in each related resource, selecting the resource through the purchase’s transaction. This is a history summary, not a checkout action.
Before you call
Use an existing member token and selected resource context. Results come from related active resources of active partners sharing that resource’s partner. See member and resource context for supplied configuration and shared checks.
Request
GET with no request body or request Content-Type requirement. Response media type is JSON. Requires the user role or inherited permission and active member context. See credential transport.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
resource | header | string | required context | Public resource key; not the secret. |
token | header | string | member context | Existing member-session token. |
firebase-token | header | string | Firebase-enabled member context | Configured Firebase ID token alongside the Wallkit token. |
page | query | integer | optional | Use 1 for the first page; pass it explicitly. No explicit omitted-page default in the operation. |
limit | query | integer | optional | Default 10. No universal maximum is specified. |
filter | query | object / JSON string | optional | Resource-model filter syntax is parsed/validated, but its conditions are not applied to the resource selection in these summary calls. Do not rely on it to restrict results. |
See grouped summary selection for the resource set, pagination, ignored filters and empty wrapper.
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
items[].resources[] | resource and purchases | Use grouped resource fields and purchase and conditional relationships; item and relation have conditional projections. |
paginator uses the collection fields. An empty collection is an ordinary result; do not interpret it as an authentication failure.
Example: read purchases grouped by resource
Show a content purchase for article-1001. Amount is the stored subtotal; its currency unit is not established by this read. Supply the sample configuration and runtimes. These three requests are equivalent.
cURL
curl "${WALLKIT_API_BASE}/api/v1/user/resources/purchases?page=1&limit=10" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
const url = new URL("/api/v1/user/resources/purchases", process.env.WALLKIT_API_BASE);
url.searchParams.set("page", "1");
url.searchParams.set("limit", "10");
const headers = { resource: process.env.RESOURCE_KEY, token: process.env.USER_TOKEN };
const response = await fetch(url, { method: "GET", headers });
const body = await response.json();
console.log(response.status, body);
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/user/resources/purchases")
url += "?" + urlencode({'page': '1', 'limit': '10'})
headers = {"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]}
request = Request(url, headers=headers, method="GET")
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"items": [
{
"resources": [
{
"id": 1001,
"title": "Example publication",
"key": "example-resource",
"host": "https://example.com",
"purchases": [
{
"id": 4001,
"item_type": "content",
"item_key": "article-1001",
"item_id": 1001,
"price": 500,
"discount": 0,
"amount": 500,
"currency": "USD",
"created_at": "2026-09-30 10:00:00"
}
]
}
]
}
]
}
Alternate result
No resources match the partner/user selection on this page. Keep the wrapper shape; nested records are not separately paginated.
Response excerpt:
{
"items": [
{
"resources": []
}
]
}
Recovery
| HTTP status | API code / response | Cause | Next action |
|---|---|---|---|
| 401 | auth_failed | Required identity is missing. | Supply the existing member token and check its selected resource context. |
| 401 | auth_access_fail | Inactive account or locked/suspended resource relationship. | Ask the administrator to check account activation and the resource relationship’s lock/suspension state. |
| 401 / 403 | access | Role does not permit the operation. | Use an identity permitted for this action; ask the administrator to check the assigned role. |
| 409 | invalid_<field> | Parsed resource filter validation fails; code is built from the failing field (for example invalid_filter_date). | Remove or correct the named filter field. Filter conditions do not restrict these grouped reads; use the documented selection rules. |
See member and resource context for applicable shared checks; follow the local error table above.
Next task
Read transaction summaries to distinguish the purchased item from its payment status.
Read transactions grouped by resource
GET /api/v1/user/resources/transactions
Read this user’s transactions for each related resource. This does not create, refund or update a payment.
Before you call
Use an existing member token and selected resource context. Results come from related active resources of active partners sharing that resource’s partner. See member and resource context for supplied configuration and shared checks.
Request
GET with no request body or request Content-Type requirement. Response media type is JSON. Requires the user role or inherited permission and active member context. See credential transport.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
resource | header | string | required context | Public resource key; not the secret. |
token | header | string | member context | Existing member-session token. |
firebase-token | header | string | Firebase-enabled member context | Configured Firebase ID token alongside the Wallkit token. |
page | query | integer | optional | Use 1 for the first page; pass it explicitly. No explicit omitted-page default in the operation. |
limit | query | integer | optional | Default 10. No universal maximum is specified. |
filter | query | object / JSON string | optional | Resource-model filter syntax is parsed/validated, but its conditions are not applied to the resource selection in these summary calls. Do not rely on it to restrict results. |
See grouped summary selection for the resource set, pagination, ignored filters and empty wrapper. Use the transaction definition for supported status meanings; no closed enum is promised.
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
items[].resources[] | resource and transactions | Use grouped resource fields and transaction fields. type means card brand. |
paginator uses the collection fields. An empty collection is an ordinary result; do not interpret it as an authentication failure.
Example: read transactions grouped by resource
Show a succeeded Stripe transaction. succeeded is a source-recognized successful status; the read does not guarantee a complete list of statuses. Supply the sample configuration and runtimes. These three requests are equivalent.
cURL
curl "${WALLKIT_API_BASE}/api/v1/user/resources/transactions?page=1&limit=10" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
const url = new URL("/api/v1/user/resources/transactions", process.env.WALLKIT_API_BASE);
url.searchParams.set("page", "1");
url.searchParams.set("limit", "10");
const headers = { resource: process.env.RESOURCE_KEY, token: process.env.USER_TOKEN };
const response = await fetch(url, { method: "GET", headers });
const body = await response.json();
console.log(response.status, body);
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/user/resources/transactions")
url += "?" + urlencode({'page': '1', 'limit': '10'})
headers = {"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]}
request = Request(url, headers=headers, method="GET")
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"items": [
{
"resources": [
{
"id": 1001,
"title": "Example publication",
"key": "example-resource",
"host": "https://example.com",
"transactions": [
{
"id": 5001,
"date": "2026-09-30 10:00:00",
"amount": 500,
"amount_refunded": 0,
"currency": "USD",
"card": "4242",
"type": "Visa",
"pay_system": "stripe",
"status": "succeeded"
}
]
}
]
}
]
}
Alternate result
No resources match the partner/user selection on this page. Keep the wrapper shape; nested records are not separately paginated.
Response excerpt:
{
"items": [
{
"resources": []
}
]
}
Recovery
| HTTP status | API code / response | Cause | Next action |
|---|---|---|---|
| 401 | auth_failed | Required identity is missing. | Supply the existing member token and check its selected resource context. |
| 401 | auth_access_fail | Inactive account or locked/suspended resource relationship. | Ask the administrator to check account activation and the resource relationship’s lock/suspension state. |
| 401 / 403 | access | Role does not permit the operation. | Use an identity permitted for this action; ask the administrator to check the assigned role. |
| 409 | invalid_<field> | Parsed resource filter validation fails; code is built from the failing field (for example invalid_filter_date). | Remove or correct the named filter field. Filter conditions do not restrict these grouped reads; use the documented selection rules. |
See member and resource context for applicable shared checks; follow the local error table above.
Next task
Read purchase summaries to identify what each history record relates to; these reads do not create or refund payments.