Skip to content

Developers

API documentation

Two separate things: the public read API, which anyone may call with no key, and the institutional API, for an organisation that holds a key.

Before you start

The address
This environment's API answers at https://api.vorunex.io. The requests below call it $VORUNEX_API: set that variable to the address.
Versions
Every route begins with /api/v1. A change that would break a client gets a new version beside the old one.
Refusals
A refusal is a problem document (RFC 9457). Read its code, never its words: the words may be improved, and the code does not change.
Paid access
There is no paid plan. No price is set, nothing is billed and nothing is sold.

The public read API

Anyone may read the public record. These routes need no key and no account.

The public registry reads need no key and stay as they are. They are a separate thing from the institutional API.

Each address is limited by how often it may call in a minute, and a refused call says when to try again.

The registry

The listed assets and the public registers. Every list is paged and says when its data was true.

  • GET/api/v1/assets

    The listed assets, with the filters Explore uses and the count behind each filter.

    Show the request
    curl -s "$VORUNEX_API/api/v1/assets" \
      -H "Accept: application/json"
  • GET/api/v1/assets/{ref}

    One asset by its RWA ID or its slug: the record and the passport in force.

    Show the request
    curl -s "$VORUNEX_API/api/v1/assets/$REF" \
      -H "Accept: application/json"

    Set $REF to the value in braces above.

  • GET/api/v1/assets/{ref}/score/history

    An asset's published scores, newest first, each with its model version, its dates and what changed.

    Show the request
    curl -s "$VORUNEX_API/api/v1/assets/$REF/score/history" \
      -H "Accept: application/json"

    Set $REF to the value in braces above.

  • GET/api/v1/passports/{rwaId}

    An asset's passport by its RWA ID. Ask for an earlier version with ?version=, or the one in force on a date with ?asOf=.

    Show the request
    curl -s "$VORUNEX_API/api/v1/passports/$RWA_ID" \
      -H "Accept: application/json"

    Set $RWA_ID to the value in braces above.

  • GET/api/v1/registry/status-changes

    The public register of status changes, each with the record as it was fingerprinted.

    Show the request
    curl -s "$VORUNEX_API/api/v1/registry/status-changes" \
      -H "Accept: application/json"
  • GET/api/v1/registry/material-events

    The public register of material events, for one asset (?asset=) or all, a page at a time.

    Show the request
    curl -s "$VORUNEX_API/api/v1/registry/material-events" \
      -H "Accept: application/json"

Verification

Checks against the published record. An unknown RWA ID or fingerprint is an answer, not an error.

  • GET/api/v1/verify/passport/{rwaId}

    What the record says about a passport, by its RWA ID.

    Show the request
    curl -s "$VORUNEX_API/api/v1/verify/passport/$RWA_ID" \
      -H "Accept: application/json"

    Set $RWA_ID to the value in braces above.

  • GET/api/v1/verify/badge/{rwaId}

    What the record says about a badge, by its RWA ID, and whether the site showing it is registered (?t= carries the badge's token).

    Show the request
    curl -s "$VORUNEX_API/api/v1/verify/badge/$RWA_ID" \
      -H "Accept: application/json"

    Set $RWA_ID to the value in braces above.

  • GET/api/v1/verify/hash/{hash}

    Whether a fingerprint (64 hexadecimal characters) is in the public record, and what it is the fingerprint of.

    Show the request
    curl -s "$VORUNEX_API/api/v1/verify/hash/$HASH" \
      -H "Accept: application/json"

    Set $HASH to the value in braces above.

Watchtower

What monitoring has published, and the rules it runs.

  • GET/api/v1/watchtower/alerts

    Published alerts, newest first, for one asset (?asset=) or the whole public record.

    Show the request
    curl -s "$VORUNEX_API/api/v1/watchtower/alerts" \
      -H "Accept: application/json"
  • GET/api/v1/watchtower/rules

    Every monitoring rule in the rule set in force, and whether it can fire today.

    Show the request
    curl -s "$VORUNEX_API/api/v1/watchtower/rules" \
      -H "Accept: application/json"

Integrity

The sealed days of the audit record, the state of each stored root, and what the integrity claim may say today. The claim itself is said only by the route that reads its evidence.

  • GET/api/v1/audit/period-roots

    The sealed days, newest first, each with its root and the state of its timestamp.

    Show the request
    curl -s "$VORUNEX_API/api/v1/audit/period-roots" \
      -H "Accept: application/json"
  • GET/api/v1/audit/period-roots/{date}/statement

    One day's coverage statement, as plain text, exactly as it was fingerprinted. The day reads YYYY-MM-DD.

    Show the request
    curl -s "$VORUNEX_API/api/v1/audit/period-roots/$DATE/statement" \
      -H "Accept: application/json"

    Set $DATE to the value in braces above.

  • GET/api/v1/audit/period-roots/{date}/proof

    One day's timestamp proof, as a file, once the day's root has been sent to the timestamp calendars.

    Show the request
    curl -s "$VORUNEX_API/api/v1/audit/period-roots/$DATE/proof" \
      -H "Accept: application/json"

    Set $DATE to the value in braces above.

  • GET/api/v1/anchors

    The stored roots, newest first, each with what it covers and the state of its anchor.

    Show the request
    curl -s "$VORUNEX_API/api/v1/anchors" \
      -H "Accept: application/json"
  • GET/api/v1/methodology/integrity

    What the integrity claim may say today, and what it rests on.

    Show the request
    curl -s "$VORUNEX_API/api/v1/methodology/integrity" \
      -H "Accept: application/json"

Method and coverage

How a score and a Risk Class are computed, and what screening covers.

  • GET/api/v1/methodology/score

    The scoring model in force: its categories, weights, tiers and ceilings.

    Show the request
    curl -s "$VORUNEX_API/api/v1/methodology/score" \
      -H "Accept: application/json"
  • GET/api/v1/methodology/risk

    The Risk Class model in force, with its factors and their weights.

    Show the request
    curl -s "$VORUNEX_API/api/v1/methodology/risk" \
      -H "Accept: application/json"
  • GET/api/v1/compliance/screening-coverage

    The screening coverage statement in force.

    Show the request
    curl -s "$VORUNEX_API/api/v1/compliance/screening-coverage" \
      -H "Accept: application/json"

The platform

What is switched on, and the chains the registry reads.

  • GET/api/v1/capabilities

    Every switch and its state: what is live, what is off, and the sentence that says why.

    Show the request
    curl -s "$VORUNEX_API/api/v1/capabilities" \
      -H "Accept: application/json"
  • GET/api/v1/chains

    The chains the registry knows, and the health of the one it reads.

    Show the request
    curl -s "$VORUNEX_API/api/v1/chains" \
      -H "Accept: application/json"
  • GET/api/v1/chains/{id}

    One chain, with what is read from it.

    Show the request
    curl -s "$VORUNEX_API/api/v1/chains/$ID" \
      -H "Accept: application/json"

    Set $ID to the value in braces above.

The institutional API

The same versioned reads again, on their own path, for an organisation that holds an API key, with the organisation's own records beside them.

Switched off

The institutional API is switched off. No key can be created or used. Public registry reads need no key and are not affected.

There is no paid plan. No price is set, nothing is billed and nothing is sold.

Every route a key opens is a read. A key changes nothing.

These limits protect the service. They come from the server's configuration, they are the same for every organisation, and they are not a plan.

While the institutional API is switched off, a keyed route answers with an empty list and a capability block that names the switch and says why. Read that block before the list.

Keys

  • API keys belong to an organisation, never to a personal account. An Owner or an Admin of the organisation creates them in its developer console.
  • Send the key in the Authorization header as a Bearer token. A key in a web address is never accepted.
  • Call it from your own server, never from a web page: a key in a page is a key anyone can read.
  • A key holds scopes, and a scope opens only the routes listed under it. A call outside the key's scopes is refused and recorded.
  • A key reads only its own organisation. Naming another organisation is refused, whatever scopes the key holds.
  • Revoking takes effect at once: the next call with the key is refused.
  • Each call records the key's prefix, the route, the time and the result. No request body, no address asked for and no key is kept.

A member of an organisation opens its developer console from API access in their settings.

The key itself

Any working key may ask what it is.

  • GET/api/v1/institutional/key

    What the key is: its prefix, its organisation, its scopes, its expiry, the limits in force, today's use and the routes it opens. Needs no scope.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/key" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

Registry (registry:read)

Listed assets, their passports and score history, and the public registers of status changes and material events.

  • GET/api/v1/institutional/assetsregistry:read

    The listed assets, with the filters Explore uses and the count behind each filter.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/assets" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"
  • GET/api/v1/institutional/assets/{ref}registry:read

    One asset by its RWA ID or its slug: the record and the passport in force.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/assets/$REF" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $REF to the value in braces above.

  • GET/api/v1/institutional/assets/{ref}/score/historyregistry:read

    An asset's published scores, newest first, each with its model version, its dates and what changed.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/assets/$REF/score/history" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $REF to the value in braces above.

  • GET/api/v1/institutional/passports/{rwaId}registry:read

    An asset's passport by its RWA ID. Ask for an earlier version with ?version=, or the one in force on a date with ?asOf=.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/passports/$RWA_ID" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $RWA_ID to the value in braces above.

  • GET/api/v1/institutional/registry/status-changesregistry:read

    The public register of status changes, each with the record as it was fingerprinted.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/registry/status-changes" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"
  • GET/api/v1/institutional/registry/material-eventsregistry:read

    The public register of material events, for one asset (?asset=) or all, a page at a time.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/registry/material-events" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

Verification (verify:read)

Checks a passport, a badge or a fingerprint against the published record.

  • GET/api/v1/institutional/verify/passport/{rwaId}verify:read

    What the record says about a passport, by its RWA ID.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/verify/passport/$RWA_ID" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $RWA_ID to the value in braces above.

  • GET/api/v1/institutional/verify/badge/{rwaId}verify:read

    What the record says about a badge, by its RWA ID, and whether the site showing it is registered (?t= carries the badge's token).

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/verify/badge/$RWA_ID" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $RWA_ID to the value in braces above.

  • GET/api/v1/institutional/verify/hash/{hash}verify:read

    Whether a fingerprint (64 hexadecimal characters) is in the public record, and what it is the fingerprint of.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/verify/hash/$HASH" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $HASH to the value in braces above.

Watchtower (watchtower:read)

Published alerts and the monitoring rules in force.

  • GET/api/v1/institutional/watchtower/alertswatchtower:read

    Published alerts, newest first, for one asset (?asset=) or the whole public record.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/watchtower/alerts" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"
  • GET/api/v1/institutional/watchtower/ruleswatchtower:read

    Every monitoring rule in the rule set in force, and whether it can fire today.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/watchtower/rules" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

Integrity (integrity:read)

The sealed days of the audit record, each day's statement and proof, and the anchors.

  • GET/api/v1/institutional/audit/period-rootsintegrity:read

    The sealed days, newest first, each with its root and the state of its timestamp.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/audit/period-roots" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"
  • GET/api/v1/institutional/audit/period-roots/{date}/statementintegrity:read

    One day's coverage statement, as plain text, exactly as it was fingerprinted. The day reads YYYY-MM-DD.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/audit/period-roots/$DATE/statement" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $DATE to the value in braces above.

  • GET/api/v1/institutional/audit/period-roots/{date}/proofintegrity:read

    One day's timestamp proof, as a file, once the day's root has been sent to the timestamp calendars.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/audit/period-roots/$DATE/proof" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $DATE to the value in braces above.

  • GET/api/v1/institutional/anchorsintegrity:read

    The stored roots, newest first, each with what it covers and the state of its anchor.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/anchors" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

Your organisation (organisation:read)

Your own organisation's details and, for an issuer, its own assets. Never another organisation's.

  • GET/api/v1/institutional/organisations/{id}organisation:read

    Your own organisation's details and its verification state.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/organisations/$ID" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $ID to the value in braces above.

  • GET/api/v1/institutional/organisations/{id}/assetsorganisation:read

    For an issuer organisation, its own assets, listed or not. Any other organisation reads an empty list.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/organisations/$ID/assets" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $ID to the value in braces above.

Usage (usage:read)

Your own organisation's usage against its limits, and its access log.

  • GET/api/v1/institutional/organisations/{id}/usageusage:read

    Your organisation's calls, day by day and key by key (?days=, at most 31).

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/organisations/$ID/usage" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $ID to the value in braces above.

  • GET/api/v1/institutional/organisations/{id}/callsusage:read

    Your organisation's access log, newest first: the key's prefix, the route, the time and the result.

    Show the request
    curl -s "$VORUNEX_API/api/v1/institutional/organisations/$ID/calls" \
      -H "Authorization: Bearer $VORUNEX_API_KEY" \
      -H "Accept: application/json"

    Set $ID to the value in braces above.

Refusals

A refusal is a problem document (RFC 9457). Read its code, never its words: the words may be improved, and the code does not change.

The refusals a read can answer with
CodeHTTP status
unauthenticated401
forbidden403
not_found404
invalid_query_parameter400
rate_limited429
capability_disabled503
    API documentation, VORUNEX