Explicit inputs. Auditable decisions.
Same-origin JSON endpoints. Account management uses HttpOnly sessions. Evaluation supports scoped agent bearer credentials. Failures return an error without internal stack traces.
/v1/automation
Session-only local automation state, next run, outcome and activity.
/v1/automation
Start or pause automatic monitoring with {enabled:boolean}. Enabling requires an eligible plan.
/v1/automation/run
Run one bounded monitoring sweep; eligible plan required.
/v1/automation/stream
Authenticated read-only server-sent state updates.
/v1/security/events/{id}/approval
Start a durable owner review workflow for a stored request.
/v1/security/events/{id}/approval
Read workflow state and final decision. Pending or processing is never authorization.
/v1/security/events/{id}/reject
Owner-only rejection of a stored review request.
/v1/security/events/{id}/approve
Owner-only approval starts asynchronous processing (HTTP 202). Poll approval status; only a completed result can contain an allow decision. Current policy and native spending limits are rechecked.
/v1/monitors
Owned wallet monitors.
/v1/monitors
Create an entitled test-plan monitor with address and network.
/v1/monitors/{id}/run
Run an owned monitor manually; unavailable providers remain explicit.
/v1/alerts
Owned monitoring change alerts.
/v1/scans
Public wallet assessment. Body: address, network, mode (live or fixture).
/v1/scans
Authenticated private scan history.
/v1/auth/register
Create local account: email and password (12+ characters).
/v1/auth/login
Create an HttpOnly session.
/v1/auth/logout
End the current session.
/v1/session
Current account and development mode.
/v1/agents
Register an agent with name. Account session required.
/v1/policies
Set policy with agentId and policy. Account session required.
/v1/keys
Issue scoped agent key. Shown once.
/v1/keys/{id}/revoke
Revoke an owned key.
/v1/transactions/evaluate
Evaluate agentId, requestId, network, to, valueWei and optional data.
/v1/transactions/simulate
Configured read-only eth_call. Not full asset-change simulation.
/v1/agents/{id}/activity
Tenant-isolated decision history.
/v1/security/events
Authenticated security event history.
/v1/usage
Actual measured usage; unavailable revenue remains unavailable.
/v1/quantum/assess
Classify supported cryptographic names from supplied text.
/v1/billing
Test billing connection status.
/v1/billing/checkout
Test-only checkout; unavailable without configured Stripe integration.
Policy shape
{
"networks": [
"base"
],
"allowlist": [
"0x1111111111111111111111111111111111111111"
],
"denylist": [],
"maxTransactionWei": "1000000000000000",
"maxCumulativeWei": "10000000000000000",
"requireSimulation": true,
"requireHumanApproval": true,
"allowedSelectors": {}
}Amounts are decimal wei strings, never floating-point numbers. Empty selector permissions deny arbitrary calldata. Client-supplied simulation success is not trusted.