API & webhooks
Plug rewards into your stack.
14 partner API endpoints and 6 signed webhook event types let you enrol, credit, convert, redeem and report from your own systems.
14
Partner API endpoints
6
Webhook event types
3×
Retries on every webhook
4
Nightly timer jobs
Five things your system can do.
Endpoints are grouped by what they do, so integrating feels like your own product.
Enrol
Create members in bulk or one by one from your HR, ERP or loyalty system.
Credit
Credit points or value against an append-only, idempotent ledger.
Convert
Convert points from your own scheme into redeemable value, instantly.
Redeem
Issue vouchers and gift cards; hold, capture or cancel redemptions with stock locking.
Report
Pull redemption, spend and catalogue reports, or export them to CSV.
Webhooks
Six signed event types.
Get notified as rewards are issued, points are credited and vouchers are redeemed, so your system always matches Kaman’s.
HMAC-signed
Every event is signed so you can verify it came from Kaman.
3× retry
Failed deliveries are retried automatically.
Per-key rate limiting
Limits are applied per API key, so one integration can’t starve another.
Brute-force protection
IP-based rate limiting on every redemption call.
1import crypto from "node:crypto";2 3// Verify a Kaman webhook before trusting it.4// See the API reference for the exact header.5export function isFromKaman(6 body: string,7 signature: string,8 secret: string,9) {10 const expected = crypto11 .createHmac("sha256", secret)12 .update(body)13 .digest("hex");14 15 return crypto.timingSafeEqual(16 Buffer.from(expected),17 Buffer.from(signature),18 );19}Sandbox keys from day one.
Branded, revocable API keys and a sandbox are included in every subscription. Build and test your integration before a single real reward is issued.

