qypheraPREVIEWCheck a wallet ↗
API / v1
These developer workflows describe the local application. Account, agent and billing APIs are disabled in this public preview.

Explicit inputs. Auditable decisions.

Same-origin JSON endpoints. Account management uses HttpOnly sessions. Evaluation supports scoped agent bearer credentials. Failures return an error without internal stack traces.

GET

/v1/automation

Session-only local automation state, next run, outcome and activity.

POST

/v1/automation

Start or pause automatic monitoring with {enabled:boolean}. Enabling requires an eligible plan.

POST

/v1/automation/run

Run one bounded monitoring sweep; eligible plan required.

GET

/v1/automation/stream

Authenticated read-only server-sent state updates.

POST

/v1/security/events/{id}/approval

Start a durable owner review workflow for a stored request.

GET

/v1/security/events/{id}/approval

Read workflow state and final decision. Pending or processing is never authorization.

POST

/v1/security/events/{id}/reject

Owner-only rejection of a stored review request.

POST

/v1/security/events/{id}/approve

Owner-only approval starts asynchronous processing (HTTP 202). Poll approval status; only a completed result can contain an allow decision. Current policy and native spending limits are rechecked.

GET

/v1/monitors

Owned wallet monitors.

POST

/v1/monitors

Create an entitled test-plan monitor with address and network.

POST

/v1/monitors/{id}/run

Run an owned monitor manually; unavailable providers remain explicit.

GET

/v1/alerts

Owned monitoring change alerts.

POST

/v1/scans

Public wallet assessment. Body: address, network, mode (live or fixture).

GET

/v1/scans

Authenticated private scan history.

POST

/v1/auth/register

Create local account: email and password (12+ characters).

POST

/v1/auth/login

Create an HttpOnly session.

POST

/v1/auth/logout

End the current session.

GET

/v1/session

Current account and development mode.

POST

/v1/agents

Register an agent with name. Account session required.

POST

/v1/policies

Set policy with agentId and policy. Account session required.

POST

/v1/keys

Issue scoped agent key. Shown once.

POST

/v1/keys/{id}/revoke

Revoke an owned key.

POST

/v1/transactions/evaluate

Evaluate agentId, requestId, network, to, valueWei and optional data.

POST

/v1/transactions/simulate

Configured read-only eth_call. Not full asset-change simulation.

GET

/v1/agents/{id}/activity

Tenant-isolated decision history.

GET

/v1/security/events

Authenticated security event history.

GET

/v1/usage

Actual measured usage; unavailable revenue remains unavailable.

POST

/v1/quantum/assess

Classify supported cryptographic names from supplied text.

GET

/v1/billing

Test billing connection status.

POST

/v1/billing/checkout

Test-only checkout; unavailable without configured Stripe integration.

Policy shape

{
  "networks": [
    "base"
  ],
  "allowlist": [
    "0x1111111111111111111111111111111111111111"
  ],
  "denylist": [],
  "maxTransactionWei": "1000000000000000",
  "maxCumulativeWei": "10000000000000000",
  "requireSimulation": true,
  "requireHumanApproval": true,
  "allowedSelectors": {}
}

Amounts are decimal wei strings, never floating-point numbers. Empty selector permissions deny arbitrary calldata. Client-supplied simulation success is not trusted.