Branding & integrations
API keys
API keys let an external club website communicate securely with Omoplata. Through the Integration API your website can show your live timetable and pull trial sign-ups straight into your club -- with no manual upkeep.
Navigate to Settings > API keys to manage your keys.
How it works
The Integration API is a server-to-server interface: your website's backend calls the API with the API key -- never the visitor's browser directly. That keeps the key secret on the server.
Visitor's browser
│ (HTML/JS)
▼
External club website (SvelteKit / Nuxt / …)
│ Authorization: Bearer {api_key}
▼
Omoplata Integration API ←→ Club database
Each key belongs to your club only. Typical uses:
| Option | Description |
|---|---|
| Show your timetable | display your club's classes and sessions live on your website. |
| Trial sign-up form | create leads in Omoplata from sign-ups submitted on your website. |
Creating a key
Create a new API key in settings. You give it a name and tick what it may do. The plaintext key is shown only once -- right after you create it. Copy it immediately and store it securely in your website's server configuration. Only a hash is stored internally; the key itself cannot be retrieved again later.
Keep keys secret
Never expose an API key in the browser or in client-side code. It belongs only in your website's backend. If a key is ever leaked, revoke it and create a new one.
Permissions
A key can only do what you allow when you create it. Without the matching permission the request is rejected -- the tick box is the boundary, not a recommendation.
| Permission | What the key may do |
|---|---|
| Read members & contracts | Read members and their contracts, including ongoing sync. Covers personal data. |
| Register new members | Create a full sign-up from your website as a member in Omoplata. |
| Read trial availability | Fetch the bookable trial sessions. |
| Submit trial sign-ups (leads) | Create trial sign-ups as leads, plus their follow-ups (confirm the time, invite friends). |
| Read registration form data | Fetch the sign-up form's configuration and contract text. |
How much a key needs depends on what your website should do:
| What your website should do | Permissions needed |
|---|---|
| Timetable, plans, FAQs, testimonials and the contact form | none -- an active key with no permissions at all is enough. This is the content your club publishes anyway. |
| Trial sign-up form | Read trial availability and Submit trial sign-ups (leads) |
| Full online sign-up as a member | Read registration form data and Register new members |
| Sync member data with another system | Read members & contracts |
There is no full-access key: every key holds exactly the permissions you gave it. Use Edit to change them later -- the key itself stays the same.
As little as possible
Only grant what the integration genuinely needs. A trial sign-up form has no business reading your member data -- and a leaked key then cannot do more than it should.
Revoking a key
You can revoke a key at any time. Afterwards, all requests using that key are rejected -- create a new key and update your website's configuration.
For a full walkthrough of connecting your website, see Integrate with your website.