membo.app API for integrations and agents
membo.app exposes an API so that a spreadsheet, a website, an automation or an AI assistant can read and act on a club's data. It is the same API the dashboard uses, on a documented subset of routes that stays stable.
Authentication
Create a key in Account › API keys. A key acts on behalf of the admin who created it, limited to the scopes chosen when it was created (view or edit per scope: members, finances, events, communication, access control, page and card). It can never do more than that person. The full key is shown once; only a hash is stored.
Send it as a bearer token:
Authorization: Bearer mk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxStart with GET https://api.membo.app/api/auth/me: the answer carries club_id, which every other route needs.
What a key can and cannot do
- It can read and write within its scopes, exactly like the person in the dashboard: list members, add a member, extend a membership, create an event, record attendance, read payments.
- It cannot manage the account, the team or other keys, and it cannot reach the superadmin. Those routes answer 403.
- A revoked or expired key answers 401. Revoke a key at any time from Account › API keys.
- Every request made with a key is recorded in the club's audit log with the key's prefix.
Limits and conventions
- 300 requests per minute per key. Above that, 429 with a
Retry-Afterheader. - Amounts are in cents (
amount_cents,price_cents). Dates are ISO 8601, UTC. - Errors carry a human-readable
detailin the club's language. - Lists are paginated with
pageandpage_size(up to 1000).
Reference
- Interactive reference: api.membo.app/api/public/docs
- OpenAPI description: api.membo.app/api/public/openapi.json, importable in any client or agent tool.
Main routes
| Need | Route |
|---|---|
| Who am I, which club | GET /api/auth/me |
| Club settings | GET and PUT /api/clubs/{club_id} |
| Key figures | GET /api/clubs/{club_id}/stats |
| Members | GET /api/clubs/{club_id}/members, POST /api/clubs/{club_id}/members/manual, GET …/members/export |
| Member actions | POST /api/clubs/{club_id}/members/{member_id}/actions/extend, mark-paid, suspend, reactivate |
| Tiers | GET and POST /api/clubs/{club_id}/tiers, PUT …/tiers/{tier_id} |
| Promo codes | GET and POST /api/clubs/{club_id}/promo-codes |
| Events | GET and POST /api/clubs/{club_id}/events, GET and PATCH …/events/{event_id}, GET …/registrations, POST …/checkin |
| Access control | GET /api/verify/{serial} (a scanned card), GET /api/clubs/{club_id}/attendance |
Example
List the active members of the club, newest first:
curl -H "Authorization: Bearer mk_live_…" \
"https://api.membo.app/api/clubs/{club_id}/members?status=active&sort=registered&dir=desc&page_size=100"Add a member who paid in cash, with a membership until the end of the year:
curl -X POST -H "Authorization: Bearer mk_live_…" -H "Content-Type: application/json" \
-d '{"first_name":"Marie","last_name":"Dupont","email":"marie@example.org","membership_end":"2026-12-31"}' \
"https://api.membo.app/api/clubs/{club_id}/members/manual"Connect an AI assistant (MCP)
membo.app also speaks the Model Context Protocol (MCP), the standard that Claude, ChatGPT, Cursor and other assistants use to call tools. The same operations as the API are exposed as tools in the vocabulary of the dashboard: whoami, list_members, add_member, extend_membership, mark_member_paid, list_tiers, list_events, create_event, event_registrations, checkin_event, verify_card, club_stats and a few more. A tool never does more than the key allows, and every call is recorded in the audit log.
- Server URL:
https://api.membo.app/mcp(Streamable HTTP) - Authentication: the header
Authorization: Bearer mk_live_…with a key from Account › API keys
Claude Code:
claude mcp add --transport http membo https://api.membo.app/mcp --header "Authorization: Bearer mk_live_…"Cursor, VS Code, Windsurf and most desktop clients (mcp.json):
{ "mcpServers": { "membo": { "url": "https://api.membo.app/mcp", "headers": { "Authorization": "Bearer mk_live_…" } } } }Then ask the assistant: "How many members have not renewed?", "Add Marie Dupont, paid in cash, until the end of the year, and send her card". Clients that only accept OAuth sign-in for remote connectors (ChatGPT connectors today) are not supported yet; OAuth is planned.