Chainvara

← Developers

API reference

Base URL https://www.chainvara.com/api/v1. Authenticate with Authorization: Bearer fos_live_… (or fos_test_… for the sandbox); each endpoint shows the scope its key needs. 65 operations, generated from the OpenAPI file.

Address proofs

get/address-proofstransfers:read

List self-hosted wallet ownership requests

200 List of address proofserror Error object

post/address-proofstransfers:write

Ask the owner of a self-hosted wallet to prove control of it

Body { network, address, label }. Returns the message to sign and the link (url, valid 14 days) to send the owner. EVM (personal_sign or EIP-1271), Solana, Bitcoin, Litecoin and Dogecoin signed messages. Webhook address.ownership_verified.

201 Address proof with urlerror Error object

post/address-proofs/{id}/signaturetransfers:write

Record the owner's signature of an ownership message

Body { signature }. Verified against the address before the proof counts.

Parameters
id *pathstring (uuid)

200 Address prooferror Error object

Addresses

get/addressestransfers:read

List the address book

200 List of trusted addresseserror Error object

post/addressesaddresses:write

Add a trusted destination

Body { network, address, label, note? }. Validated and sanctions-screened; trusted only after the policy's security cooldown. Webhook address.added.

201 Trusted addresserror Error object

post/addresses/{id}/revokeaddresses:write

Revoke a trusted destination

Parameters
id *pathstring (uuid)

200 Revokederror Error object

Audit

get/auditaudit:read

Audit trail (SIEM feed)

The organization's audit events in chain order. Poll with after=<last seq received>. Each event carries seq (gapless per organization), prev_hash and hash = sha256 of the previous hash, the seq and every field.

Parameters
afterqueryintegerReturn events with seq greater than this.
sincequerystring (date-time)
actionquerystringAction name or prefix, e.g. transfer. or api_key.created
limitqueryinteger

200 A list of audit_event objects, has_more and next_after.error Error object

get/audit/verifyaudit:read

Verify the audit hash chain

Recomputes every hash, link and sequence number. Store head.hash outside Chainvara to detect a later rewrite.

200 audit_verification: valid, events, head, problems.error Error object

Deposit addresses

post/deposit-addresseswallets:write

Every deposit address of one of your users

Body { external_user_id, networks?, label? }: one wallet per network, idempotent (calling again returns the same addresses). Deposits arrive as deposit.received webhooks carrying the same external_user_id.

200 deposit_addresses (all existed)201 deposit_addresses (some created)error Error object

Embedded

post/embedded/backupwallets:write

Store or fetch an embedded wallet's encrypted recovery backup

step store { external_user_id, network, backup } or fetch { external_user_id, network }. The backup is encrypted on the device under a 125-bit recovery code Chainvara never sees.

200 OKerror Error object

post/embedded/walletswallets:write

Embedded wallet: joint key generation with the end user's device

Calls relayed by your backend for the device SDK (/sdk/chainvara-embedded.js). Solana (FROST): start (device_round1) then finish (device_round2, public_key). EVM networks (threshold ECDSA): start → commit (device_message, device_commitment) → prove (device_proof) → finish (public_key); each answer carries the next session_id. Bodies up to 2 MB.

Request body (JSON)
step *"start" | "commit" | "prove" | "finish"
external_user_id *string
networkstring
labelstring
device_round1string
session_idstring
device_round2string
device_messagestring
device_commitmentstring
device_proofstring
public_keystring

200 Round answer201 Wallet createderror Error object

post/embedded/signtransfers:write

Embedded wallet: sign an approved transfer with the end user's device

Solana: start (device_commitments) returns the signing package and the transfer to show; the device checks the exact transaction, then finish (device_share) broadcasts. EVM: start (sign_id) returns the unsigned transaction, which the device decodes and hashes itself; sign (device_message1, device_message2); finish (device_message) broadcasts.

Request body (JSON)
step *"start" | "sign" | "finish"
external_user_id *string
transfer_idstring
device_commitmentsstring
sign_idstring
session_idstring
device_sharestring
device_message1string
device_message2string
device_messagestring

200 Submittederror Error object

Events

get/eventsevents:read

List events

Parameters
typequerystring
limitqueryinteger

200 OKerror Error object

Network

get/network/requeststransfers:read

Payment requests sent and received on the Chainvara network

Parameters
directionquery"incoming" | "outgoing"
statusquery"open" | "paying" | "paid" | "declined" | "canceled" | "expired"

200 OKerror Error object

post/network/requeststransfers:write

Request a payment from a connected organization

The payer pays it to your published address on that network, from their console or API, under their own policy and approvals.

Request body (JSON)
to *string
network *string
asset *stringSymbol or asset id
amount *string
reference *string
notestring
ttl_daysinteger

201 Createderror Error object

post/network/requests/{id}/paytransfers:write

Pay an incoming payment request

Parameters
id *pathstring (uuid)
Request body (JSON)
wallet_id *string (uuid)

201 OKerror Error object

post/network/requests/{id}/closetransfers:write

Decline (payer) or cancel (requester) an open request

Parameters
id *pathstring (uuid)

200 OKerror Error object

get/network/obligationstransfers:read

Bilateral obligations with connected organizations

200 OKerror Error object

post/network/obligationstransfers:write

Record an obligation

Counts in the net position only once the counterparty confirms it.

Request body (JSON)
counterparty *string
direction *"they_owe" | "we_owe"
network *string
asset *string
amount *string
reference *string

201 Createderror Error object

post/network/obligations/{id}/{action}transfers:write

Confirm or dispute (counterparty), or cancel (recorder) a pending obligation

Parameters
id *pathstring (uuid)
action *path"confirm" | "dispute" | "cancel"

200 OKerror Error object

get/network/positionstransfers:read

Net position per counterparty and asset

200 OKerror Error object

get/network/settlementstransfers:read

Net settlements

200 OKerror Error object

post/network/settlementstransfers:write

Settle the whole net position with one transfer (net debtor only)

Request body (JSON)
counterparty *string
asset_id *string
wallet_id *string (uuid)

201 Createderror Error object

Networks

get/networks/{id}/feeswallets:read

Network fee estimates

A typical transfer's fee at each fee_level (low, medium, high), in the native coin's smallest unit.

Parameters
id *pathstring

200 network_feeserror Error object

get/networks

Networks and assets for this environment

200 OKerror Error object

Operations

get/operationstransfers:read

List operations

Token, staking and swap operations (plain transfers are under /transfers).

Parameters
limitqueryinteger

200 OKerror Error object

post/operationstransfers:write

Request an operation

Create, mint, burn or profile a token, swap, stake or unstake. Same policy, approvals, co-signer and vault signing as transfers. Token decimals are read from the chain; a swap's guaranteed minimum comes from a fresh quote.

Parameters
Idempotency-KeyheaderstringRetries with the same key return the original response and never repeat the side effect.
Request body (JSON)
wallet_id *string (uuid)
type *"token_create" | "nft_create" | "nft_transfer" | "token_mint" | "token_burn" | "token_metadata" | "token_freeze" | "token_thaw" | "token_lock_supply" | "stake" | "unstake" | "stake_withdraw" | "liquid_stake" | "swap"
freezablebooleantoken_create: the issuer can freeze holders
fixed_supplybooleantoken_create: minting closed after the initial supply
holderstringtoken_freeze, token_thaw: holder address
amountstringInitial supply (token_create), tokens (mint/burn), amount sold (swap), native coin (stake, liquid_stake), items (nft_transfer, default 1)
namestringtoken_create
symbolstringtoken_create: 2–10 capital letters or digits
decimalsintegertoken_create (default 6; Solana 0–9, EVM 0–18)
tokenstringtoken_mint, token_burn, token_metadata: mint or contract address
tostringtoken_mint: recipient (default: the wallet); nft_transfer: recipient
contractstringnft_transfer: ERC-721 or ERC-1155 collection contract
token_idstringnft_transfer: token id (decimal)
sellstringswap: native, a symbol or a token address
buystringswap: native, a symbol or a token address
slippage_bpsintegerswap (default 50 = 0.5%)
validatorstringstake: validator vote account (Solana)
stake_accountstringunstake, stake_withdraw
notestring

200 Idempotent replay201 Createderror Error object

Payees

get/payeestransfers:read

Organizations you can pay by handle

Connected organizations of the payment network and the networks they receive on. Pay one with destination "@handle" on POST /transfers or /payouts.

200 OKerror Error object

Payouts

get/payoutstransfers:read

List payout batches

Recent batches with per-status counts.

Parameters
limitqueryinteger

200 OKerror Error object

post/payoutstransfers:write

Create a payout batch

Up to 500 lines { destination, amount, note? } from one wallet and asset. Every line is validated first; if any is invalid nothing is created and the errors are listed per line. Send an Idempotency-Key so a retry never pays twice.

Parameters
Idempotency-KeyheaderstringRetries with the same key return the original response and never repeat the side effect.
Request body (JSON)
wallet_id *string (uuid)
asset *string
referencestring
items *object[]

201 payout_batcherror Error object

get/payouts/{id}transfers:read

Retrieve a payout batch with every transfer and its status

Parameters
id *pathstring (uuid)

200 payout_batcherror Error object

Policy

get/policytransfers:read

The policy in force

Limits, tiers, address book, Travel Rule, KYT and transaction rules, with the version and the latest versions.

200 policyerror Error object

post/policy/impacttransfers:read

Replay a candidate policy on recent requests

Body { policy } in the shape GET /policy returns. Validated, then replayed on the last 200 requests (24-hour totals and velocity recomputed). Nothing is published.

200 policy_impact: checked, stricter, looser, unchanged, changeserror Error object

Prices

get/prices

Latest USD prices

200 OKerror Error object

Reports

get/reports/ledgertransfers:read

Valued ledger and monthly totals

Parameters
fromquerystring (date)
toquerystring (date)

200 OKerror Error object

get/reports/gainstransfers:read

Realized gains and positions with cost basis

Pooled per asset across the organization's wallets (moves between own wallets excluded). Unknown costs are null, never guessed.

Parameters
fromquerystring (date)
toquerystring (date)
methodquery"fifo" | "average"

200 OKerror Error object

Reserves

post/reserves/snapshotsreserves:write

Create a proof-of-reserves snapshot

Body { customers: [{ user_id, balances: { BTC: "0.25" } }] }. Commits liabilities in a Merkle sum tree (ids hashed) and reads reserves from your wallets.

201 por_snapshoterror Error object

get/reserves/snapshots/{id}/proofreserves:write

A customer's inclusion proof

Parameters
id *pathstring (uuid)
user_id *querystring

200 por_proof: give it to that customer to check on the public pageerror Error object

Screening

get/screeningwallets:read

Sanctions screening of any address (OFAC SDN)

Parameters
network *querystring
address *querystring

200 screening_resulterror Error object

get/screening/inboundtransfers:read

Screening of the senders of your deposits

Every incoming movement's sender is screened (sanctions and your KYT providers). Never credit a flagged deposit before deposit.released.

Parameters
statusquery"clear" | "flagged" | "released" | "reported"
limitqueryinteger

200 OKerror Error object

Security

get/securityevents:read

Security posture of the key's environment

Score 0-100 and every check with its fix, for SIEM and GRC dashboards.

200 security_postureerror Error object

Swap

get/swap/quotetransfers:read

Swap quote

Parameters
wallet_id *querystring
sell *querystring
buy *querystring
amount *querystring
slippage_bpsquerystring

200 OKerror Error object

Tokens

get/tokenswallets:read

Issued tokens

Tokens the organization created, with live supply, market price, market cap and public profile.

200 OKerror Error object

Transfers

get/transferstransfers:read

List transfers

Newest first. When has_more, pass next_cursor as starting_after for the next page (stable while new transfers arrive).

Parameters
statusquerystring
wallet_idquerystring (uuid)
external_idquerystring
tagquerystring
starting_afterquerystring (uuid)
limitqueryinteger

200 OKerror Error object

post/transferstransfers:write

Request a transfer

Evaluated against the environment policy (limits, allow/blocklists, approval tiers). Approved transfers are signed in the vault and broadcast by the worker when execution is enabled.

Parameters
Idempotency-KeyheaderstringRetries with the same key return the original response and never repeat the side effect.
Request body (JSON)
wallet_id *string (uuid)
asset *stringSymbol (USDC, ETH…), asset id, or any token address on Solana (SPL, Token-2022) and EVM networks (ERC-20): symbol and decimals are read from the chain
amount *string
destination *string
notestring
fee_level"low" | "medium" | "high"Network fee priority (EVM, Bitcoin-family, Solana). Default medium.
external_idstringYour own reference, unique per environment; GET /transfers?external_id= finds it.

200 Idempotent replay201 Createderror Error object

post/transfers/previewtransfers:read

Preview a transfer

Same body as POST /transfers. Returns the policy decision, destination status, USD value, network fee and a chain simulation (funds, fees, gas estimate). Nothing is created, signed or sent.

200 transfer_previewerror Error object

post/transfers/{id}/tagstransfers:write

Replace a transfer's accounting tags

Body { tags: ["payroll", "vendor:acme"] }. Tags are never part of what was approved or signed.

Parameters
id *pathstring (uuid)

200 OKerror Error object

get/transfers/{id}

Retrieve a transfer with its timeline

Parameters
id *pathstring (uuid)

200 OKerror Error object

post/transfers/{id}/cancel

Cancel a transfer before submission

Parameters
id *pathstring (uuid)

200 OKerror Error object

post/transfers/{id}/speed-uptransfers:write

Speed up a stuck EVM, Bitcoin or Litecoin transaction

EVM: re-signs the same transaction (same nonce, recipient, amount and data). Bitcoin and Litecoin: replace-by-fee spending the same coins, the higher fee taken from the change. Fees rise by at least 12.5% or to the network price, at most ten times the approved fee. Webhook transfer.sped_up.

Parameters
id *pathstring (uuid)

200 OKerror Error object

post/transfers/{id}/cancel-onchaintransfers:write

Cancel a stuck EVM, Bitcoin or Litecoin transaction on chain

EVM: spends the same nonce on a 0-value transaction to the wallet itself. Bitcoin and Litecoin: spends the same coins back to the wallet. Whichever transaction is included first decides: the transfer ends confirmed, or canceled with nothing sent.

Parameters
id *pathstring (uuid)

200 OKerror Error object

Travel rule

get/travel-rule/messagestransfers:read

Travel Rule messages exchanged with network organizations

Parameters
directionquery"incoming" | "outgoing"

200 OKerror Error object

post/travel-rule/messages/{id}/acknowledgetransfers:write

Acknowledge an incoming Travel Rule message

Parameters
id *pathstring (uuid)

200 OKerror Error object

Vaults

get/vaultswallets:read

List vaults

200 List of vaultserror Error object

post/vaultswallets:write

Create a vault

Body { name, description? }.

201 Vaulterror Error object

post/vaults/{id}/freezewallets:write

Freeze a vault

Body { reason }. Nothing can leave the vault, approved transfers included, until an owner, admin or CFO unfreezes it in the console. Webhook vault.frozen.

Parameters
id *pathstring (uuid)

200 Vaulterror Error object

Wallets

get/walletswallets:read

List wallets

Parameters
purposequery"treasury" | "end_user"
custodyquery"managed" | "watch"
external_user_idquerystring
limitqueryinteger

200 OKerror Error object

post/walletswallets:write

Create a wallet

Generates a new key in the vault (omit `address`), or watches an existing address (pass `address`). With `external_user_id`, creation is idempotent per network: one wallet per end user.

Parameters
Idempotency-KeyheaderstringRetries with the same key return the original response and never repeat the side effect.
Request body (JSON)
network *string
labelstring
external_user_idstring
addressstring
kind"hot" | "warm" | "cold"

200 Existing end-user wallet returned201 Createderror Error object

get/wallets/{id}

Retrieve a wallet

Parameters
id *pathstring (uuid)

200 OKerror Error object

get/wallets/{id}/balances

Wallet balances

Parameters
id *pathstring (uuid)
refreshquerybooleanRead the chain now.

200 OKerror Error object

get/wallets/{id}/transactions

On-chain history

Parameters
id *pathstring (uuid)
limitqueryinteger

200 OKerror Error object

get/wallets/{id}/allowances

Token approvals that can still be used (EVM)

ERC-20 allowances, NFT operators and Permit2 allowances, read live, riskiest first; at_risk = min(allowance, balance).

Parameters
id *pathstring (uuid)

200 allowanceserror Error object

post/wallets/{id}/allowancestransfers:write

Revoke a token approval

Body { kind: erc20 | nft_operator | permit2, token, spender }. Requested as a contract_call operation under the policy and co-signer.

Parameters
id *pathstring (uuid)

201 OKerror Error object

post/wallets/{id}/vaultwallets:write

Move a wallet into a vault

Body { vault_id } (null: out of its vault).

Parameters
id *pathstring (uuid)

200 wallet_vaulterror Error object

post/wallets/{id}/refresh-keyswallets:write

Refresh both key shares of an MPC wallet (same address, old shares void)

Parameters
id *pathstring (uuid)

200 OKerror Error object