diff --git a/.changesets/20260813-131604-add-updatepaymentmethod-activity.md b/.changesets/20260813-131604-add-updatepaymentmethod-activity.md new file mode 100644 index 0000000..f3843bf --- /dev/null +++ b/.changesets/20260813-131604-add-updatepaymentmethod-activity.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add UpdatePaymentMethod activity" +date: "2026-08-13" +--- + +Introduces a new dashboard only activity for updating payment method invoice email. diff --git a/.changesets/20260824-150000-add-get-active-policies.md b/.changesets/20260824-150000-add-get-active-policies.md new file mode 100644 index 0000000..b13cf69 --- /dev/null +++ b/.changesets/20260824-150000-add-get-active-policies.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add GetActivePolicies" +date: "2026-08-24" +--- + +Add the `GetActivePolicies` query to the Go SDK client, along with the `GetActivePoliciesRequest`, `GetActivePoliciesResponse`, and `ActivePolicyStatus` types. For each policy in an organization, the query reports whether it is currently active based on the enclave's trusted timestamp and the policy's time window; policies without a time field are always active. diff --git a/.changesets/20260825-190000-add-secret-lifecycle-wrappers.md b/.changesets/20260825-190000-add-secret-lifecycle-wrappers.md new file mode 100644 index 0000000..7ec35bd --- /dev/null +++ b/.changesets/20260825-190000-add-secret-lifecycle-wrappers.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add secret lifecycle wrappers" +date: "2026-08-25" +--- + +Adds single-secret lifecycle wrappers `Client.ImportSecret` and `Client.ExportSecret`. diff --git a/.changesets/20260825-190001-add-encrypt-secret-to-bundle.md b/.changesets/20260825-190001-add-encrypt-secret-to-bundle.md new file mode 100644 index 0000000..1bd51da --- /dev/null +++ b/.changesets/20260825-190001-add-encrypt-secret-to-bundle.md @@ -0,0 +1,8 @@ +--- +module: "crypto" +bump: "minor" +title: "Add EncryptSecretToBundle" +date: "2026-08-25" +--- + +Adds `EncryptSecretToBundle`, which verifies and HPKE-encrypts a secret plaintext to an `InitImportSecrets` target bundle. diff --git a/.changesets/20260826-093954-add-cross-protocol-swap-activity-types.md b/.changesets/20260826-093954-add-cross-protocol-swap-activity-types.md new file mode 100644 index 0000000..13e1939 --- /dev/null +++ b/.changesets/20260826-093954-add-cross-protocol-swap-activity-types.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add cross-protocol swap activity types" +date: "2026-08-26" +--- + +Adds Go SDK request types and client methods for CreateSwapQuoteV2 and ExecuteSwapV3. diff --git a/.changesets/20260827-allow-external-swap-destinations.md b/.changesets/20260827-allow-external-swap-destinations.md new file mode 100644 index 0000000..26948ec --- /dev/null +++ b/.changesets/20260827-allow-external-swap-destinations.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Clarify external swap destination addresses" +date: "2026-08-27" +--- + +Document `destination_address` as a raw public address for the output token protocol. diff --git a/.changesets/20260831-102200-rename-destination-wallet-account-to-destination-address.md b/.changesets/20260831-102200-rename-destination-wallet-account-to-destination-address.md new file mode 100644 index 0000000..abb0eb5 --- /dev/null +++ b/.changesets/20260831-102200-rename-destination-wallet-account-to-destination-address.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Rename destination_wallet_account to destination_address" +date: "2026-08-31" +--- + +Rename CreateSwapQuoteV2 and ExecuteSwapV3 `destinationWalletAccount` to `destinationAddress`. The value is still a raw public address for the output token protocol. diff --git a/.changesets/20260831-104940-expose-swap-destination-in-status.md b/.changesets/20260831-104940-expose-swap-destination-in-status.md new file mode 100644 index 0000000..892c428 --- /dev/null +++ b/.changesets/20260831-104940-expose-swap-destination-in-status.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Expose swap destination in status" +date: "2026-08-31" +--- + +Add destinationAddress to GetSwapStatusResponse so clients can identify the receiver for same-chain and cross-chain swaps. diff --git a/.changesets/20260831-120000-earn-force-deallocatable-liquidity.md b/.changesets/20260831-120000-earn-force-deallocatable-liquidity.md new file mode 100644 index 0000000..631c6dc --- /dev/null +++ b/.changesets/20260831-120000-earn-force-deallocatable-liquidity.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Earn: expose forceDeallocatableLiquidity alongside liquidity" +date: "2026-08-31" +--- + +Add `forceDeallocatableLiquidity` and `forceDeallocatableLiquidityDisplay` to EarnVault and EarnEnabledVault: the additional assets withdrawable from a Morpho vault by force-deallocating its non-liquidity adapters at zero penalty, additive to `liquidity`. Empty when the provider does not report it (Aave). diff --git a/.changesets/20260831-155032-remove-unreleased-velocity-control-endpoints.md b/.changesets/20260831-155032-remove-unreleased-velocity-control-endpoints.md new file mode 100644 index 0000000..ca29f4c --- /dev/null +++ b/.changesets/20260831-155032-remove-unreleased-velocity-control-endpoints.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Remove unreleased velocity control endpoints" +date: "2026-08-31" +--- + +Remove the unreleased velocity control client methods and request and response types from the Go SDK. diff --git a/.changesets/20260902-160000-earn-enabled-vault-deploy-status.md b/.changesets/20260902-160000-earn-enabled-vault-deploy-status.md new file mode 100644 index 0000000..1534d0b --- /dev/null +++ b/.changesets/20260902-160000-earn-enabled-vault-deploy-status.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Earn: expose the wrapper deploy status on enabled vaults" +date: "2026-09-02" +--- + +Add `deployStatus`, `deployRequestId` and `deployError` to EarnEnabledVault. A wrapper's entry is written before its deploy transaction lands, so `deployStatus` reports whether that deploy is PENDING, COMPLETED or FAILED; only a COMPLETED wrapper is usable. `deployRequestId` polls `GetEarnDeployStatus` and `deployError` carries the failure detail. All three are empty for wrappers deployed before deploy statuses were recorded. diff --git a/.changesets/20260904-140000-add-request-context-to-export-secrets.md b/.changesets/20260904-140000-add-request-context-to-export-secrets.md new file mode 100644 index 0000000..d5c6dc8 --- /dev/null +++ b/.changesets/20260904-140000-add-request-context-to-export-secrets.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Add request context to export secrets" +date: "2026-09-04" +--- + +Add optional request_context key-value pairs to ExportSecretParams. diff --git a/.changesets/20260905-add-delete-secrets.md b/.changesets/20260905-add-delete-secrets.md new file mode 100644 index 0000000..4e1065f --- /dev/null +++ b/.changesets/20260905-add-delete-secrets.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add DeleteSecrets endpoint" +date: "2026-09-05" +--- + +Add support for deleting stored secrets by ID with DeleteSecrets. diff --git a/.changesets/20260908-163704-add-enclave-resource-size-options.md b/.changesets/20260908-163704-add-enclave-resource-size-options.md new file mode 100644 index 0000000..6a4f879 --- /dev/null +++ b/.changesets/20260908-163704-add-enclave-resource-size-options.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "add enclave resource size options" +date: "2026-09-08" +--- + +Adds enclave resource size options for CPU count and memory in Gi. diff --git a/.changesets/20260910-transaction-history-execution-status.md b/.changesets/20260910-transaction-history-execution-status.md new file mode 100644 index 0000000..9d53c8c --- /dev/null +++ b/.changesets/20260910-transaction-history-execution-status.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Expose transaction history execution status" +date: "2026-09-10" +--- + +Add `executionFailed` to Ethereum and Solana transaction history items so clients can distinguish successful transactions from transactions that failed during on-chain execution. diff --git a/.changesets/20260911-earn-rewards-read.md b/.changesets/20260911-earn-rewards-read.md new file mode 100644 index 0000000..cf7588b --- /dev/null +++ b/.changesets/20260911-earn-rewards-read.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add ListEarnRewards" +date: "2026-09-11" +--- + +Add ListEarnRewards, which returns the Merkl rewards (claimable, claimed, pending per token and chain) attributed to a wallet's Earn positions. diff --git a/.changesets/20260915-earn-claim-rewards.md b/.changesets/20260915-earn-claim-rewards.md new file mode 100644 index 0000000..5f781ec --- /dev/null +++ b/.changesets/20260915-earn-claim-rewards.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add EarnClaimRewards and GetEarnClaimRewardsStatus" +date: "2026-09-15" +--- + +Add the EarnClaimRewards activity, which claims every currently claimable Merkl reward attributed to a wallet on one chain in a single Distributor transaction, and GetEarnClaimRewardsStatus to poll the claim by its claim_request_id. diff --git a/.changesets/20260916-solana-v1-send-transaction-docs.md b/.changesets/20260916-solana-v1-send-transaction-docs.md new file mode 100644 index 0000000..474b9d2 --- /dev/null +++ b/.changesets/20260916-solana-v1-send-transaction-docs.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Document Solana V1 send transaction inputs" +date: "2026-09-16" +--- + +Clarify the hex-encoded transaction input format for SolSendTransaction and SolSendTransactionV2, including V1 trailing signature slots, transaction size limits, and signer limits for sponsored transactions. diff --git a/.changesets/20260917-095707-sync-up-rust-sdk-enclave-size-info.md b/.changesets/20260917-095707-sync-up-rust-sdk-enclave-size-info.md new file mode 100644 index 0000000..b79a277 --- /dev/null +++ b/.changesets/20260917-095707-sync-up-rust-sdk-enclave-size-info.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "sync up rust-sdk enclave size info" +date: "2026-09-17" +--- + +Bug fix for enclave size info used for creating new deployments from existing ones. This change fixes the functionality to not lose the instance size information. diff --git a/.changesets/20260918-161400-add-tokenprogram-to-asset-balance.md b/.changesets/20260918-161400-add-tokenprogram-to-asset-balance.md new file mode 100644 index 0000000..807afe8 --- /dev/null +++ b/.changesets/20260918-161400-add-tokenprogram-to-asset-balance.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add tokenProgram to wallet address balances" +date: "2026-09-18" +--- + +Add an optional `tokenProgram` field on `AssetBalance` returned by `GetWalletAddressBalances`. For Solana token balances it is the SPL Token or Token-2022 program address that owns the mint, so clients can construct transfers without a separate chain lookup. It is omitted for native SOL and non-Solana assets. diff --git a/.changesets/20260918-add-tvc-operator-and-quorum-key-methods.md b/.changesets/20260918-add-tvc-operator-and-quorum-key-methods.md new file mode 100644 index 0000000..1392da1 --- /dev/null +++ b/.changesets/20260918-add-tvc-operator-and-quorum-key-methods.md @@ -0,0 +1,10 @@ +--- +module: "root" +bump: "minor" +title: "Add TVC operator and quorum key methods" +date: "2026-09-18" +--- + +Add `GetTVCOperators` and `GetTVCQuorumKeys` queries and their request and response types. Expose encryption and signing public keys and the optional key source on `TVCOperator`, and add the `TVCQuorumKey` type. + +Add `CreateTVCOperator` and `CreateTVCQuorumKey` methods, their stamping helpers, and their request and response types. diff --git a/.changesets/20260921-095307-adjust-input-types-for-vc-activities.md b/.changesets/20260921-095307-adjust-input-types-for-vc-activities.md new file mode 100644 index 0000000..0457aff --- /dev/null +++ b/.changesets/20260921-095307-adjust-input-types-for-vc-activities.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Adjust input types for velocity controls activities" +date: "2026-09-21" +--- + +Use numeric types for velocity controls activities instead of their string representations diff --git a/.changesets/20260922-134958-add-swap-quote-v3-types.md b/.changesets/20260922-134958-add-swap-quote-v3-types.md new file mode 100644 index 0000000..df807a1 --- /dev/null +++ b/.changesets/20260922-134958-add-swap-quote-v3-types.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add swap quote v3 and sponsorship feature types" +date: "2026-09-22" +--- + +Add generated types for CreateSwapQuoteIntentV3, CreateSwapQuoteResultV2, and the swap fee sponsorship and fixed-rate feature names. CreateSwapQuoteV3 stays disabled, so this does not add a client method. diff --git a/.changesets/20260923-140000-add-kamino-earn-provider.md b/.changesets/20260923-140000-add-kamino-earn-provider.md new file mode 100644 index 0000000..c2a0c59 --- /dev/null +++ b/.changesets/20260923-140000-add-kamino-earn-provider.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Add the Kamino Earn provider" +date: "2026-09-23" +--- + +Add `EARN_PROVIDER_KAMINO` to `EarnProvider` and Solana chain ids to the Earn intent `chainCaip2` enums. diff --git a/.changesets/20260923-add-live-deployment-filter-to-get-tvc-apps.md b/.changesets/20260923-add-live-deployment-filter-to-get-tvc-apps.md new file mode 100644 index 0000000..117d039 --- /dev/null +++ b/.changesets/20260923-add-live-deployment-filter-to-get-tvc-apps.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add live deployment filter to GetTVCApps" +date: "2026-09-23" +--- + +Add an optional `isLive` filter to `GetTVCApps` requests so callers can limit results based on whether an app has a live deployment. diff --git a/.changesets/20260923-make-provisioning-state-required.md b/.changesets/20260923-make-provisioning-state-required.md new file mode 100644 index 0000000..d4ee45a --- /dev/null +++ b/.changesets/20260923-make-provisioning-state-required.md @@ -0,0 +1,10 @@ +--- +module: "root" +bump: "patch" +title: "Make TVC provisioning state required" +date: "2026-09-23" +--- + +Make `ProvisioningState` required on `DeploymentStatus` and `GetTVCDeploymentProvisioningDetailsResponse`. Both fields now use `ProvisioningState` instead of `*ProvisioningState` and are always included when marshaling JSON. + +Callers must replace pointer assignments, dereferences, and nil checks with direct enum values and comparisons. diff --git a/.changesets/20260924-091935-clarify-signrawpayloadresultsignature-descriptions.md b/.changesets/20260924-091935-clarify-signrawpayloadresultsignature-descriptions.md new file mode 100644 index 0000000..4dd5876 --- /dev/null +++ b/.changesets/20260924-091935-clarify-signrawpayloadresultsignature-descriptions.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "clarify SignRawPayloadResult.signature descriptions" +date: "2026-09-24" +--- + +The r/s/v fields of `SignRawPayloadResult` were inaccurately described. They are now more explicit, especially with regards to `v` in EdDSA signatures. diff --git a/.changesets/20260924-120000-rename-earn-chain-caip2-to-caip2.md b/.changesets/20260924-120000-rename-earn-chain-caip2-to-caip2.md new file mode 100644 index 0000000..98ccdd8 --- /dev/null +++ b/.changesets/20260924-120000-rename-earn-chain-caip2-to-caip2.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Rename Earn intent chain_caip2 to caip2" +date: "2026-09-24" +--- + +Renames the `ChainCaip2` field to `Caip2` on the EarnDeployWrapper, EarnDeposit, EarnWithdraw and EarnClaimRewards intent types, matching the chain field name used by the other transaction activities. diff --git a/.changesets/20260924-224500-add-getaccount-linking-info.md b/.changesets/20260924-224500-add-getaccount-linking-info.md new file mode 100644 index 0000000..bd6ccb4 --- /dev/null +++ b/.changesets/20260924-224500-add-getaccount-linking-info.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add linking info to auth proxy GetAccount" +date: "2026-09-24" +--- + +Add `IncludeRequiresSocialLinking` to `AuthProxyGetAccountRequest` and `RequiresSocialLinking` to `AuthProxyGetAccountResponse`. When a request opts in, the response reports whether the organization was matched by a sub-organization's verified email rather than by a registered OIDC identity, so callers can tell an ordinary login apart from one that first requires social linking. diff --git a/.changesets/20260925-152815-fix-openapi-tagsummary-metadata.md b/.changesets/20260925-152815-fix-openapi-tagsummary-metadata.md new file mode 100644 index 0000000..00a3a87 --- /dev/null +++ b/.changesets/20260925-152815-fix-openapi-tagsummary-metadata.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "patch" +title: "Fix OpenAPI tag/summary metadata" +date: "2026-09-25" +--- + +Correct OpenAPI tags, summaries, and descriptions for several public API operations (doc comments only, no behavior change). diff --git a/.changesets/20260928-231739-add-swap-sponsorship-usage-queries.md b/.changesets/20260928-231739-add-swap-sponsorship-usage-queries.md new file mode 100644 index 0000000..ee6860e --- /dev/null +++ b/.changesets/20260928-231739-add-swap-sponsorship-usage-queries.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add swap sponsorship usage query" +date: "2026-09-28" +--- + +Add a swap sponsorship usage query that returns each feature's spending window, settled spending, and remaining capacity. Signed limit-write activities remain internal until the planned SDK launch. diff --git a/.changesets/20261001-120000-add-get-external-signer-tasks.md b/.changesets/20261001-120000-add-get-external-signer-tasks.md new file mode 100644 index 0000000..bfa24aa --- /dev/null +++ b/.changesets/20261001-120000-add-get-external-signer-tasks.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Add GetExternalSignerTasks" +date: "2026-10-01" +--- + +Add the `GetExternalSignerTasks` query to the Go SDK client, along with the `GetExternalSignerTasksRequest`, `GetExternalSignerTasksResponse`, `ExternalSignerTask`, `ExternalCryptoV1Signature`, and `ExternalCryptoV1SignatureScheme` types. The query lets an external signer daemon poll the coordinator for a batch of pending signing tasks keyed by its public key. diff --git a/.changesets/20261001-120000-rename-delete-velocity-controls.md b/.changesets/20261001-120000-rename-delete-velocity-controls.md new file mode 100644 index 0000000..47026c7 --- /dev/null +++ b/.changesets/20261001-120000-rename-delete-velocity-controls.md @@ -0,0 +1,8 @@ +--- +module: "root" +bump: "minor" +title: "Rename DeleteVelocityControl to DeleteVelocityControls" +date: "2026-10-01" +--- + +Renames the `ACTIVITY_TYPE_DELETE_VELOCITY_CONTROL` activity type to `ACTIVITY_TYPE_DELETE_VELOCITY_CONTROLS` (the `ActivityTypeDeleteVelocityControl` constant becomes `ActivityTypeDeleteVelocityControls`), and the `DeleteVelocityControlIntent` and `DeleteVelocityControlResult` types to `DeleteVelocityControlsIntent` and `DeleteVelocityControlsResult`. The intent and result now take a `VelocityControlIds` list instead of a single `VelocityControlID`, matching the other bulk delete activities. diff --git a/client_extensions.go b/client_extensions.go index 123f4e4..e2e5e88 100644 --- a/client_extensions.go +++ b/client_extensions.go @@ -2,8 +2,14 @@ package turnkey import ( "context" + "crypto/ecdsa" "encoding/json" "errors" + "fmt" + "maps" + "slices" + + "github.com/tkhq/go-sdk/crypto" ) // SendSignedRequest sends a POST request with a signed body and decodes the response into T. @@ -75,3 +81,106 @@ func (c *Client) resolveActivityInResponse(ctx context.Context, data map[string] return nil } + +// ImportSecret verifies the enclave signature and org, encrypts one secret, and returns its ID. +// signerKey overrides the production quorum key (non-production only). +func (c *Client) ImportSecret(ctx context.Context, organizationID string, name *string, plaintext []byte, staticProperties map[string]string, signerKey ...*ecdsa.PublicKey) (string, error) { + organizationID, err := c.organizationID(organizationID) + if err != nil { + return "", err + } + + initRes, err := c.InitImportSecrets(ctx, InitImportSecretsRequest{ + OrganizationID: organizationID, + EncryptionSuite: TransportEncryptionSuiteEnclaveEncryptV1, + NumSecrets: 1, + }) + if err != nil { + return "", fmt.Errorf("failed to init import secret: %w", err) + } + + targetBundle, err := exactlyOne(initRes.EnclaveTargetMessages, "enclave target message") + if err != nil { + return "", err + } + + payload, targetPublicKey, err := crypto.EncryptSecretToBundle(plaintext, targetBundle, organizationID, signerKey...) + if err != nil { + return "", fmt.Errorf("failed to encrypt secret to target bundle: %w", err) + } + + importRes, err := c.ImportSecrets(ctx, ImportSecretsRequest{ + OrganizationID: organizationID, + Secrets: []ImportSecretParams{{ + Name: name, + SecretPayload: payload, + TargetPublicKey: targetPublicKey, + EncryptionSuite: TransportEncryptionSuiteEnclaveEncryptV1, + StaticProperties: keyValuesFromMap(staticProperties), + }}, + }) + if err != nil { + return "", fmt.Errorf("failed to import secret: %w", err) + } + + return exactlyOne(importRes.SecretIds, "imported secret id") +} + +// ExportSecret uses a fresh target key, verifies the enclave signature and org, and decrypts one secret. +// signerKey overrides the production quorum key (non-production only). +func (c *Client) ExportSecret(ctx context.Context, organizationID, secretID string, signerKey ...*ecdsa.PublicKey) ([]byte, error) { + organizationID, err := c.organizationID(organizationID) + if err != nil { + return nil, err + } + + targetPublicKey, kemPrivate, err := crypto.GenerateEncryptionKeyPair() + if err != nil { + return nil, fmt.Errorf("failed to generate export target key: %w", err) + } + + exportRes, err := c.ExportSecrets(ctx, ExportSecretsRequest{ + OrganizationID: organizationID, + Secrets: []ExportSecretParams{{ + SecretID: secretID, + TargetPublicKey: targetPublicKey, + EncryptionSuite: TransportEncryptionSuiteEnclaveEncryptV1, + }}, + }) + if err != nil { + return nil, fmt.Errorf("failed to export secret: %w", err) + } + + payload, err := exactlyOne(exportRes.SecretPayloads, "exported secret payload") + if err != nil { + return nil, err + } + + plaintext, err := crypto.DecryptExportBundle([]byte(payload), organizationID, kemPrivate, signerKey...) + if err != nil { + return nil, fmt.Errorf("failed to decrypt secret payload: %w", err) + } + + return plaintext, nil +} + +// exactlyOne returns the sole element of items, with a descriptive error otherwise. +func exactlyOne[T any](items []T, what string) (T, error) { + if len(items) != 1 { + var zero T + return zero, fmt.Errorf("expected exactly one %s, got %d", what, len(items)) + } + + return items[0], nil +} + +// keyValuesFromMap converts a map to KeyValue pairs sorted by key. +func keyValuesFromMap(m map[string]string) []KeyValue { + out := make([]KeyValue, 0, len(m)) + for _, k := range slices.Sorted(maps.Keys(m)) { + key, value := k, m[k] + out = append(out, KeyValue{Key: &key, Value: &value}) + } + + return out +} diff --git a/client_gen.go b/client_gen.go index cf2801d..0775c19 100644 --- a/client_gen.go +++ b/client_gen.go @@ -318,7 +318,7 @@ func (c *Client) StampCreateAuthenticators(ctx context.Context, input CreateAuth return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_authenticators", body, true) } -// Create a fiat on ramp provider credential +// Create a fiat on ramp provider credential. func (c *Client) CreateFiatOnRampCredential(ctx context.Context, input CreateFiatOnRampCredentialRequest) (*CreateFiatOnRampCredentialResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -405,7 +405,7 @@ func (c *Client) StampCreateMfaPolicy(ctx context.Context, input CreateMfaPolicy return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_mfa_policy", body, true) } -// Enable authentication for end users with an OAuth 2.0 provider +// Enable authentication for end users with an OAuth 2.0 provider. func (c *Client) CreateOAuth2Credential(ctx context.Context, input CreateOAuth2CredentialRequest) (*CreateOAuth2CredentialResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -724,7 +724,7 @@ func (c *Client) StampCreateSubOrganization(ctx context.Context, input CreateSub return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_sub_organization", body, true) } -// Get a swap quote. Asset chains are derived from CAIP-19 asset IDs; cross-chain quotes are supported. +// Create a swap quote. Asset chains are derived from CAIP-19 asset IDs; cross-chain quotes are supported. func (c *Client) CreateSwapQuote(ctx context.Context, input CreateSwapQuoteRequest) (*CreateSwapQuoteResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -753,7 +753,7 @@ func (c *Client) StampCreateSwapQuote(ctx context.Context, input CreateSwapQuote return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_swap_quote", body, true) } -// Create a new TVC application +// Create a new TVC application. func (c *Client) CreateTVCApp(ctx context.Context, input CreateTVCAppRequest) (*CreateTVCAppResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -782,7 +782,7 @@ func (c *Client) StampCreateTVCApp(ctx context.Context, input CreateTVCAppReques return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_tvc_app", body, true) } -// Create a new TVC Deployment +// Create a new TVC deployment. func (c *Client) CreateTVCDeployment(ctx context.Context, input CreateTVCDeploymentRequest) (*CreateTVCDeploymentResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -811,7 +811,7 @@ func (c *Client) StampCreateTVCDeployment(ctx context.Context, input CreateTVCDe return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_tvc_deployment", body, true) } -// Post one or more manifest approvals for a TVC Manifest +// Post one or more manifest approvals for a TVC manifest. func (c *Client) CreateTVCManifestApprovals(ctx context.Context, input CreateTVCManifestApprovalsRequest) (*CreateTVCManifestApprovalsResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -840,91 +840,120 @@ func (c *Client) StampCreateTVCManifestApprovals(ctx context.Context, input Crea return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_tvc_manifest_approvals", body, true) } -// Create a user tag and add it to users. -func (c *Client) CreateUserTag(ctx context.Context, input CreateUserTagRequest) (*CreateUserTagResponse, error) { +// Create a TVC operator backed by uncompressed P-256 Turnkey wallet accounts. +func (c *Client) CreateTVCOperator(ctx context.Context, input CreateTVCOperatorRequest) (*CreateTVCOperatorResponse, error) { body, err := c.activityEnvelope(input) if err != nil { return nil, err } var raw map[string]any - if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/create_user_tag", body, &raw, true, nil); err != nil { + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/create_tvc_operator", body, &raw, true, nil); err != nil { return nil, err } - out := new(ActivityResult[CreateUserTagResult]) - if err := decodeActivityResponse(raw, "CreateUserTagResult", out); err != nil { + out := new(ActivityResult[CreateTVCOperatorResult]) + if err := decodeActivityResponse(raw, "CreateTVCOperatorResult", out); err != nil { return nil, err } - result, activity, err := activityAndWait(ctx, c, out, func(r Result) *CreateUserTagResult { return r.CreateUserTagResult }) + result, activity, err := activityAndWait(ctx, c, out, func(r Result) *CreateTVCOperatorResult { return r.CreateTVCOperatorResult }) if err != nil { return nil, err } - return &CreateUserTagResponse{Activity: *activity, CreateUserTagResult: *result}, nil + return &CreateTVCOperatorResponse{Activity: *activity, CreateTVCOperatorResult: *result}, nil } -func (c *Client) StampCreateUserTag(ctx context.Context, input CreateUserTagRequest) (*SignedRequest, error) { +func (c *Client) StampCreateTVCOperator(ctx context.Context, input CreateTVCOperatorRequest) (*SignedRequest, error) { body, err := c.activityEnvelope(input) if err != nil { return nil, err } - return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_user_tag", body, true) + return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_tvc_operator", body, true) } -// Create users in an existing organization. Each user must have at least one valid credential: an API key, an authenticator, an OAuth provider, or an email or phone number with a login method enabled on the organization (email, email OTP, or SMS). -func (c *Client) CreateUsers(ctx context.Context, input CreateUsersRequest) (*CreateUsersResponse, error) { +// Create a hosted TVC Quorum Key and encrypted shares. +func (c *Client) CreateTVCQuorumKey(ctx context.Context, input CreateTVCQuorumKeyRequest) (*CreateTVCQuorumKeyResponse, error) { body, err := c.activityEnvelope(input) if err != nil { return nil, err } var raw map[string]any - if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/create_users", body, &raw, true, nil); err != nil { + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/create_tvc_quorum_key", body, &raw, true, nil); err != nil { return nil, err } - out := new(ActivityResult[CreateUsersResult]) - if err := decodeActivityResponse(raw, "CreateUsersResult", out); err != nil { + out := new(ActivityResult[CreateTVCQuorumKeyResult]) + if err := decodeActivityResponse(raw, "CreateTVCQuorumKeyResult", out); err != nil { return nil, err } - result, activity, err := activityAndWait(ctx, c, out, func(r Result) *CreateUsersResult { return r.CreateUsersResult }) + result, activity, err := activityAndWait(ctx, c, out, func(r Result) *CreateTVCQuorumKeyResult { return r.CreateTVCQuorumKeyResult }) if err != nil { return nil, err } - return &CreateUsersResponse{Activity: *activity, CreateUsersResult: *result}, nil + return &CreateTVCQuorumKeyResponse{Activity: *activity, CreateTVCQuorumKeyResult: *result}, nil } -func (c *Client) StampCreateUsers(ctx context.Context, input CreateUsersRequest) (*SignedRequest, error) { +func (c *Client) StampCreateTVCQuorumKey(ctx context.Context, input CreateTVCQuorumKeyRequest) (*SignedRequest, error) { body, err := c.activityEnvelope(input) if err != nil { return nil, err } - return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_users", body, true) + return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_tvc_quorum_key", body, true) } -// Create a new velocity control. -func (c *Client) CreateVelocityControl(ctx context.Context, input CreateVelocityControlRequest) (*CreateVelocityControlResponse, error) { +// Create a user tag and add it to users. +func (c *Client) CreateUserTag(ctx context.Context, input CreateUserTagRequest) (*CreateUserTagResponse, error) { body, err := c.activityEnvelope(input) if err != nil { return nil, err } var raw map[string]any - if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/create_velocity_control", body, &raw, true, nil); err != nil { + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/create_user_tag", body, &raw, true, nil); err != nil { return nil, err } - out := new(ActivityResult[CreateVelocityControlResult]) - if err := decodeActivityResponse(raw, "CreateVelocityControlResult", out); err != nil { + out := new(ActivityResult[CreateUserTagResult]) + if err := decodeActivityResponse(raw, "CreateUserTagResult", out); err != nil { return nil, err } - result, activity, err := activityAndWait(ctx, c, out, func(r Result) *CreateVelocityControlResult { return r.CreateVelocityControlResult }) + result, activity, err := activityAndWait(ctx, c, out, func(r Result) *CreateUserTagResult { return r.CreateUserTagResult }) if err != nil { return nil, err } - return &CreateVelocityControlResponse{Activity: *activity, CreateVelocityControlResult: *result}, nil + return &CreateUserTagResponse{Activity: *activity, CreateUserTagResult: *result}, nil } -func (c *Client) StampCreateVelocityControl(ctx context.Context, input CreateVelocityControlRequest) (*SignedRequest, error) { +func (c *Client) StampCreateUserTag(ctx context.Context, input CreateUserTagRequest) (*SignedRequest, error) { body, err := c.activityEnvelope(input) if err != nil { return nil, err } - return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_velocity_control", body, true) + return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_user_tag", body, true) +} + +// Create users in an existing organization. Each user must have at least one valid credential: an API key, an authenticator, an OAuth provider, or an email or phone number with a login method enabled on the organization (email, email OTP, or SMS). +func (c *Client) CreateUsers(ctx context.Context, input CreateUsersRequest) (*CreateUsersResponse, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + var raw map[string]any + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/create_users", body, &raw, true, nil); err != nil { + return nil, err + } + out := new(ActivityResult[CreateUsersResult]) + if err := decodeActivityResponse(raw, "CreateUsersResult", out); err != nil { + return nil, err + } + result, activity, err := activityAndWait(ctx, c, out, func(r Result) *CreateUsersResult { return r.CreateUsersResult }) + if err != nil { + return nil, err + } + return &CreateUsersResponse{Activity: *activity, CreateUsersResult: *result}, nil +} + +func (c *Client) StampCreateUsers(ctx context.Context, input CreateUsersRequest) (*SignedRequest, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_users", body, true) } // Create a wallet and derive addresses. @@ -1014,7 +1043,7 @@ func (c *Client) StampCreateWebhookEndpoint(ctx context.Context, input CreateWeb return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/create_webhook_endpoint", body, true) } -// Remove api keys from a user. +// Remove API keys from a user. func (c *Client) DeleteAPIKeys(ctx context.Context, input DeleteAPIKeysRequest) (*DeleteAPIKeysResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -1072,7 +1101,7 @@ func (c *Client) StampDeleteAuthenticators(ctx context.Context, input DeleteAuth return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_authenticators", body, true) } -// Delete a fiat on ramp provider credential +// Delete a fiat on ramp provider credential. func (c *Client) DeleteFiatOnRampCredential(ctx context.Context, input DeleteFiatOnRampCredentialRequest) (*DeleteFiatOnRampCredentialResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -1159,7 +1188,7 @@ func (c *Client) StampDeleteMfaPolicy(ctx context.Context, input DeleteMfaPolicy return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_mfa_policy", body, true) } -// Disable authentication for end users with an OAuth 2.0 provider +// Disable authentication for end users with an OAuth 2.0 provider. func (c *Client) DeleteOAuth2Credential(ctx context.Context, input DeleteOAuth2CredentialRequest) (*DeleteOAuth2CredentialResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -1333,6 +1362,35 @@ func (c *Client) StampDeletePrivateKeys(ctx context.Context, input DeletePrivate return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_private_keys", body, true) } +// Delete secrets by their unique identifiers. All secrets must belong to the organization. +func (c *Client) DeleteSecrets(ctx context.Context, input DeleteSecretsRequest) (*DeleteSecretsResponse, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + var raw map[string]any + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_secrets", body, &raw, true, nil); err != nil { + return nil, err + } + out := new(ActivityResult[DeleteSecretsResult]) + if err := decodeActivityResponse(raw, "DeleteSecretsResult", out); err != nil { + return nil, err + } + result, activity, err := activityAndWait(ctx, c, out, func(r Result) *DeleteSecretsResult { return r.DeleteSecretsResult }) + if err != nil { + return nil, err + } + return &DeleteSecretsResponse{Activity: *activity, DeleteSecretsResult: *result}, nil +} + +func (c *Client) StampDeleteSecrets(ctx context.Context, input DeleteSecretsRequest) (*SignedRequest, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_secrets", body, true) +} + // Delete a smart contract interface. func (c *Client) DeleteSmartContractInterface(ctx context.Context, input DeleteSmartContractInterfaceRequest) (*DeleteSmartContractInterfaceResponse, error) { body, err := c.activityEnvelope(input) @@ -1391,7 +1449,7 @@ func (c *Client) StampDeleteSubOrganization(ctx context.Context, input DeleteSub return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_sub_organization", body, true) } -// Delete a TVC App and all of its deployments +// Delete a TVC app and all of its deployments. func (c *Client) DeleteTVCAppAndDeployments(ctx context.Context, input DeleteTVCAppAndDeploymentsRequest) (*DeleteTVCAppAndDeploymentsResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -1420,7 +1478,7 @@ func (c *Client) StampDeleteTVCAppAndDeployments(ctx context.Context, input Dele return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_tvc_app_and_deployments", body, true) } -// Delete a TVC Deployment +// Delete a TVC deployment. func (c *Client) DeleteTVCDeployment(ctx context.Context, input DeleteTVCDeploymentRequest) (*DeleteTVCDeploymentResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -1507,35 +1565,6 @@ func (c *Client) StampDeleteUsers(ctx context.Context, input DeleteUsersRequest) return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_users", body, true) } -// Delete an existing velocity control. -func (c *Client) DeleteVelocityControl(ctx context.Context, input DeleteVelocityControlRequest) (*DeleteVelocityControlResponse, error) { - body, err := c.activityEnvelope(input) - if err != nil { - return nil, err - } - var raw map[string]any - if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_velocity_control", body, &raw, true, nil); err != nil { - return nil, err - } - out := new(ActivityResult[DeleteVelocityControlResult]) - if err := decodeActivityResponse(raw, "DeleteVelocityControlResult", out); err != nil { - return nil, err - } - result, activity, err := activityAndWait(ctx, c, out, func(r Result) *DeleteVelocityControlResult { return r.DeleteVelocityControlResult }) - if err != nil { - return nil, err - } - return &DeleteVelocityControlResponse{Activity: *activity, DeleteVelocityControlResult: *result}, nil -} - -func (c *Client) StampDeleteVelocityControl(ctx context.Context, input DeleteVelocityControlRequest) (*SignedRequest, error) { - body, err := c.activityEnvelope(input) - if err != nil { - return nil, err - } - return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/delete_velocity_control", body, true) -} - // Delete wallet accounts for an organization. func (c *Client) DeleteWalletAccounts(ctx context.Context, input DeleteWalletAccountsRequest) (*DeleteWalletAccountsResponse, error) { body, err := c.activityEnvelope(input) @@ -1681,6 +1710,35 @@ func (c *Client) StampETHUndelegate7702(ctx context.Context, input ETHUndelegate return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/eth_undelegate_7702", body, true) } +// Claim the Merkl protocol rewards attributed to a wallet's Earn positions. The claim is signed by the wallet itself and every reward token is transferred to it; see ListEarnRewards for what is claimable. +func (c *Client) EarnClaimRewards(ctx context.Context, input EarnClaimRewardsRequest) (*EarnClaimRewardsResponse, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + var raw map[string]any + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/earn_claim_rewards", body, &raw, true, nil); err != nil { + return nil, err + } + out := new(ActivityResult[EarnClaimRewardsResult]) + if err := decodeActivityResponse(raw, "EarnClaimRewardsResult", out); err != nil { + return nil, err + } + result, activity, err := activityAndWait(ctx, c, out, func(r Result) *EarnClaimRewardsResult { return r.EarnClaimRewardsResult }) + if err != nil { + return nil, err + } + return &EarnClaimRewardsResponse{Activity: *activity, EarnClaimRewardsResult: *result}, nil +} + +func (c *Client) StampEarnClaimRewards(ctx context.Context, input EarnClaimRewardsRequest) (*SignedRequest, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/earn_claim_rewards", body, true) +} + // Enable a yield vault for an organization by deploying its fee wrapper. Must be called before any deposits into the vault. func (c *Client) EarnDeployWrapper(ctx context.Context, input EarnDeployWrapperRequest) (*EarnDeployWrapperResponse, error) { body, err := c.activityEnvelope(input) @@ -1999,6 +2057,20 @@ func (c *Client) GetAPIKeys(ctx context.Context, input GetAPIKeysRequest) (*GetA return out, nil } +// For each policy in an organization, report whether it is currently active based on the enclave's trusted timestamp and the policy's time window (if any). Policies without a time field are always active. +func (c *Client) GetActivePolicies(ctx context.Context, input GetActivePoliciesRequest) (*GetActivePoliciesResponse, error) { + organizationID, err := c.organizationID(input.OrganizationID) + if err != nil { + return nil, err + } + input.OrganizationID = organizationID + out := new(GetActivePoliciesResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/get_active_policies", input, out, true, nil); err != nil { + return nil, err + } + return out, nil +} + // List all activities within an organization. func (c *Client) GetActivities(ctx context.Context, input GetActivitiesRequest) (*GetActivitiesResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) @@ -2041,7 +2113,7 @@ func (c *Client) GetAppProofs(ctx context.Context, input GetAppProofsRequest) (* return out, nil } -// Get live runtime status for a TVC App from the cluster. +// Get live runtime status for a TVC app from the cluster. func (c *Client) GetAppStatus(ctx context.Context, input GetAppStatusRequest) (*GetAppStatusResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -2083,7 +2155,7 @@ func (c *Client) GetAuthenticators(ctx context.Context, input GetAuthenticatorsR return out, nil } -// Get the boot proof for a given ephemeral key. +// Get the Boot Proof for a given ephemeral key. func (c *Client) GetBootProof(ctx context.Context, input GetBootProofRequest) (*BootProofResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -2111,6 +2183,20 @@ func (c *Client) GetClaimEarnFeesStatus(ctx context.Context, input GetClaimEarnF return out, nil } +// Poll the status of a rewards claim by its claim_request_id. +func (c *Client) GetEarnClaimRewardsStatus(ctx context.Context, input GetEarnClaimRewardsStatusRequest) (*GetEarnClaimRewardsStatusResponse, error) { + organizationID, err := c.organizationID(input.OrganizationID) + if err != nil { + return nil, err + } + input.OrganizationID = organizationID + out := new(GetEarnClaimRewardsStatusResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/get_earn_claim_rewards_status", input, out, true, nil); err != nil { + return nil, err + } + return out, nil +} + // Poll the status of a wrapper deployment by its deploy_request_id. func (c *Client) GetEarnDeployStatus(ctx context.Context, input GetEarnDeployStatusRequest) (*GetEarnDeployStatusResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) @@ -2153,6 +2239,20 @@ func (c *Client) GetEarnWithdrawStatus(ctx context.Context, input GetEarnWithdra return out, nil } +// Get a batch of external signer tasks. +func (c *Client) GetExternalSignerTasks(ctx context.Context, input GetExternalSignerTasksRequest) (*GetExternalSignerTasksResponse, error) { + organizationID, err := c.organizationID(input.OrganizationID) + if err != nil { + return nil, err + } + input.OrganizationID = organizationID + out := new(GetExternalSignerTasksResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/external_signer/v1/query/get_external_signer_tasks", input, out, true, nil); err != nil { + return nil, err + } + return out, nil +} + // Get gas usage and gas limits for either the parent organization or a sub-organization. func (c *Client) GetGasUsage(ctx context.Context, input GetGasUsageRequest) (*GetGasUsageResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) @@ -2181,7 +2281,7 @@ func (c *Client) GetIPAllowlist(ctx context.Context, input GetIPAllowlistRequest return out, nil } -// Get the latest boot proof for a given enclave app name. +// Get the latest Boot Proof for a given enclave app name. func (c *Client) GetLatestBootProof(ctx context.Context, input GetLatestBootProofRequest) (*BootProofResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -2447,7 +2547,7 @@ func (c *Client) GetSmartContractInterfaces(ctx context.Context, input GetSmartC return out, nil } -// Get all suborg IDs associated given a parent org ID and an optional filter. +// Get all suborg IDs (verified and unverified) associated with a given parent organization ID and an optional filter. func (c *Client) GetSubOrgIds(ctx context.Context, input GetSubOrgIdsRequest) (*GetSubOrgIdsResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -2461,6 +2561,20 @@ func (c *Client) GetSubOrgIds(ctx context.Context, input GetSubOrgIdsRequest) (* return out, nil } +// Read each swap sponsorship feature's spending window and settled spending in the current rolling window. Parents see aggregate spending; children see their own spending. Pending swaps are not reserved. +func (c *Client) GetSwapSponsorshipUsage(ctx context.Context, input GetSwapSponsorshipUsageRequest) (*GetSwapSponsorshipUsageResponse, error) { + organizationID, err := c.organizationID(input.OrganizationID) + if err != nil { + return nil, err + } + input.OrganizationID = organizationID + out := new(GetSwapSponsorshipUsageResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/get_swap_sponsorship_usage", input, out, true, nil); err != nil { + return nil, err + } + return out, nil +} + // Poll the status of a swap by its swap_request_id. Covers same-chain and cross-chain swaps. func (c *Client) GetSwapStatus(ctx context.Context, input GetSwapStatusRequest) (*GetSwapStatusResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) @@ -2475,7 +2589,7 @@ func (c *Client) GetSwapStatus(ctx context.Context, input GetSwapStatusRequest) return out, nil } -// Get details about a single TVC App +// Get details about a single TVC app. func (c *Client) GetTVCApp(ctx context.Context, input GetTVCAppRequest) (*GetTVCAppResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -2489,7 +2603,7 @@ func (c *Client) GetTVCApp(ctx context.Context, input GetTVCAppRequest) (*GetTVC return out, nil } -// List all deployments for a given TVC App +// List all deployments for a given TVC app. func (c *Client) GetTVCAppDeployments(ctx context.Context, input GetTVCAppDeploymentsRequest) (*GetTVCAppDeploymentsResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -2503,7 +2617,7 @@ func (c *Client) GetTVCAppDeployments(ctx context.Context, input GetTVCAppDeploy return out, nil } -// List all TVC Apps within an organization. +// List all TVC apps within an organization. func (c *Client) GetTVCApps(ctx context.Context, input GetTVCAppsRequest) (*GetTVCAppsResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -2517,7 +2631,7 @@ func (c *Client) GetTVCApps(ctx context.Context, input GetTVCAppsRequest) (*GetT return out, nil } -// Get details about a single TVC Deployment +// Get details about a single TVC deployment. func (c *Client) GetTVCDeployment(ctx context.Context, input GetTVCDeploymentRequest) (*GetTVCDeploymentResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -2545,6 +2659,34 @@ func (c *Client) GetTVCDeploymentDebugLogs(ctx context.Context, input GetTVCDepl return out, nil } +// Get the attestation document and manifest envelope of the provisioning enclave for a TVC deployment. +func (c *Client) GetTVCDeploymentProvisioningDetails(ctx context.Context, input GetTVCDeploymentProvisioningDetailsRequest) (*GetTVCDeploymentProvisioningDetailsResponse, error) { + organizationID, err := c.organizationID(input.OrganizationID) + if err != nil { + return nil, err + } + input.OrganizationID = organizationID + out := new(GetTVCDeploymentProvisioningDetailsResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/get_tvc_deployment_provisioning_details", input, out, true, nil); err != nil { + return nil, err + } + return out, nil +} + +// List all TVC operators within an organization, newest first. +func (c *Client) GetTVCOperators(ctx context.Context, input GetTVCOperatorsRequest) (*GetTVCOperatorsResponse, error) { + organizationID, err := c.organizationID(input.OrganizationID) + if err != nil { + return nil, err + } + input.OrganizationID = organizationID + out := new(GetTVCOperatorsResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/list_tvc_operators", input, out, true, nil); err != nil { + return nil, err + } + return out, nil +} + // List QOS versions supported for new TVC deployments and the latest recommended QOS version. func (c *Client) GetTVCQosVersions(ctx context.Context, input GetTVCQosVersionsRequest) (*GetTVCQosVersionsResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) @@ -2559,49 +2701,49 @@ func (c *Client) GetTVCQosVersions(ctx context.Context, input GetTVCQosVersionsR return out, nil } -// Get details about a user. -func (c *Client) GetUser(ctx context.Context, input GetUserRequest) (*GetUserResponse, error) { +// List all hosted TVC Quorum Keys within an organization, newest first. +func (c *Client) GetTVCQuorumKeys(ctx context.Context, input GetTVCQuorumKeysRequest) (*GetTVCQuorumKeysResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { return nil, err } input.OrganizationID = organizationID - out := new(GetUserResponse) - if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/get_user", input, out, true, nil); err != nil { + out := new(GetTVCQuorumKeysResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/list_tvc_quorum_keys", input, out, true, nil); err != nil { return nil, err } return out, nil } -// List all users within an organization. -func (c *Client) GetUsers(ctx context.Context, input GetUsersRequest) (*GetUsersResponse, error) { +// Get details about a user. +func (c *Client) GetUser(ctx context.Context, input GetUserRequest) (*GetUserResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { return nil, err } input.OrganizationID = organizationID - out := new(GetUsersResponse) - if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/list_users", input, out, true, nil); err != nil { + out := new(GetUserResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/get_user", input, out, true, nil); err != nil { return nil, err } return out, nil } -// Get details about a velocity control. -func (c *Client) GetVelocityControl(ctx context.Context, input GetVelocityControlRequest) (*GetVelocityControlResponse, error) { +// List all users within an organization. +func (c *Client) GetUsers(ctx context.Context, input GetUsersRequest) (*GetUsersResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { return nil, err } input.OrganizationID = organizationID - out := new(GetVelocityControlResponse) - if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/get_velocity_control", input, out, true, nil); err != nil { + out := new(GetUsersResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/list_users", input, out, true, nil); err != nil { return nil, err } return out, nil } -// Get all email or phone verified suborg IDs associated given a parent org ID. +// Get all verified suborg IDs associated with a given parent organization ID and an optional filter. func (c *Client) GetVerifiedSubOrgIds(ctx context.Context, input GetVerifiedSubOrgIdsRequest) (*GetVerifiedSubOrgIdsResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -2685,7 +2827,7 @@ func (c *Client) GetWallets(ctx context.Context, input GetWalletsRequest) (*GetW return out, nil } -// Get basic information about your current API or WebAuthN user and their organization. Affords sub-organization look ups via parent organization for WebAuthN or API key users. +// Get basic information about your current API or WebAuthn user and their organization. Affords sub-organization lookups via parent organization for WebAuthn or API key users. func (c *Client) GetWhoami(ctx context.Context, input GetWhoamiRequest) (*GetWhoamiResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { @@ -3031,6 +3173,20 @@ func (c *Client) ListEarnPositions(ctx context.Context, input ListEarnPositionsR return out, nil } +// List the protocol rewards (e.g. MORPHO and third-party campaign tokens, distributed off-chain via Merkl) attributed to a wallet: claimable, lifetime claimed, and pending amounts per reward token. +func (c *Client) ListEarnRewards(ctx context.Context, input ListEarnRewardsRequest) (*ListEarnRewardsResponse, error) { + organizationID, err := c.organizationID(input.OrganizationID) + if err != nil { + return nil, err + } + input.OrganizationID = organizationID + out := new(ListEarnRewardsResponse) + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/list_earn_rewards", input, out, true, nil); err != nil { + return nil, err + } + return out, nil +} + // Get the catalog of all wrappable yield vaults across supported chains, enriched with live TVL and APY. Annotates which vaults the organization has already enabled. func (c *Client) ListEarnVaults(ctx context.Context, input ListEarnVaultsRequest) (*ListEarnVaultsResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) @@ -3157,20 +3313,6 @@ func (c *Client) ListUserTags(ctx context.Context, input ListUserTagsRequest) (* return out, nil } -// List all velocity controls within an organization. -func (c *Client) ListVelocityControls(ctx context.Context, input ListVelocityControlsRequest) (*ListVelocityControlsResponse, error) { - organizationID, err := c.organizationID(input.OrganizationID) - if err != nil { - return nil, err - } - input.OrganizationID = organizationID - out := new(ListVelocityControlsResponse) - if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/query/list_velocity_controls", input, out, true, nil); err != nil { - return nil, err - } - return out, nil -} - // List webhook endpoints within an organization. func (c *Client) ListWebhookEndpoints(ctx context.Context, input ListWebhookEndpointsRequest) (*ListWebhookEndpointsResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) @@ -3214,7 +3356,7 @@ func (c *Client) StampOAuth(ctx context.Context, input OAuthRequest) (*SignedReq return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/oauth", body, true) } -// Authenticate a user with an OAuth 2.0 provider and receive an OIDC token to use with the LoginWithOAuth or CreateSubOrganization activities +// Authenticate a user with an OAuth 2.0 provider and receive an OIDC token to use with the LoginWithOAuth or CreateSubOrganization activities. func (c *Client) OAuth2Authenticate(ctx context.Context, input OAuth2AuthenticateRequest) (*OAuth2AuthenticateResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -3330,6 +3472,64 @@ func (c *Client) StampOTPLogin(ctx context.Context, input OTPLoginRequest) (*Sig return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/otp_login", body, true) } +// Post re-encrypted Quorum Key share for a TVC deployment. +func (c *Client) PostTVCQuorumKeyShare(ctx context.Context, input PostTVCQuorumKeyShareRequest) (*PostTVCQuorumKeyShareResponse, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + var raw map[string]any + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/post_tvc_quorum_key_share", body, &raw, true, nil); err != nil { + return nil, err + } + out := new(ActivityResult[PostTVCQuorumKeyShareResult]) + if err := decodeActivityResponse(raw, "PostTVCQuorumKeyShareResult", out); err != nil { + return nil, err + } + result, activity, err := activityAndWait(ctx, c, out, func(r Result) *PostTVCQuorumKeyShareResult { return r.PostTVCQuorumKeyShareResult }) + if err != nil { + return nil, err + } + return &PostTVCQuorumKeyShareResponse{Activity: *activity, PostTVCQuorumKeyShareResult: *result}, nil +} + +func (c *Client) StampPostTVCQuorumKeyShare(ctx context.Context, input PostTVCQuorumKeyShareRequest) (*SignedRequest, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/post_tvc_quorum_key_share", body, true) +} + +// Re-encrypt a hosted TVC Quorum Key share for a deployment. +func (c *Client) ReEncryptTVCQuorumKeyShare(ctx context.Context, input ReEncryptTVCQuorumKeyShareRequest) (*ReEncryptTVCQuorumKeyShareResponse, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + var raw map[string]any + if err := c.postJSON(ctx, c.config.urls.baseURL, "/public/v1/submit/re_encrypt_tvc_quorum_key_share", body, &raw, true, nil); err != nil { + return nil, err + } + out := new(ActivityResult[ReEncryptTVCQuorumKeyShareResult]) + if err := decodeActivityResponse(raw, "ReEncryptTVCQuorumKeyShareResult", out); err != nil { + return nil, err + } + result, activity, err := activityAndWait(ctx, c, out, func(r Result) *ReEncryptTVCQuorumKeyShareResult { return r.ReEncryptTVCQuorumKeyShareResult }) + if err != nil { + return nil, err + } + return &ReEncryptTVCQuorumKeyShareResponse{Activity: *activity, ReEncryptTVCQuorumKeyShareResult: *result}, nil +} + +func (c *Client) StampReEncryptTVCQuorumKeyShare(ctx context.Context, input ReEncryptTVCQuorumKeyShareRequest) (*SignedRequest, error) { + body, err := c.activityEnvelope(input) + if err != nil { + return nil, err + } + return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/re_encrypt_tvc_quorum_key_share", body, true) +} + // Complete the process of recovering a user by adding an authenticator. func (c *Client) RecoverUser(ctx context.Context, input RecoverUserRequest) (*RecoverUserResponse, error) { body, err := c.activityEnvelope(input) @@ -3446,7 +3646,7 @@ func (c *Client) StampRemoveOrganizationFeature(ctx context.Context, input Remov return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/remove_organization_feature", body, true) } -// Restore a deleted TVC Deployment +// Restore a deleted TVC deployment. func (c *Client) RestoreTVCDeployment(ctx context.Context, input RestoreTVCDeploymentRequest) (*RestoreTVCDeploymentResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -3794,7 +3994,7 @@ func (c *Client) StampStampLogin(ctx context.Context, input StampLoginRequest) ( return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/stamp_login", body, true) } -// Update a fiat on ramp provider credential +// Update a fiat on ramp provider credential. func (c *Client) UpdateFiatOnRampCredential(ctx context.Context, input UpdateFiatOnRampCredentialRequest) (*UpdateFiatOnRampCredentialResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -3852,7 +4052,7 @@ func (c *Client) StampUpdateMfaPolicy(ctx context.Context, input UpdateMfaPolicy return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/update_mfa_policy", body, true) } -// Update an OAuth 2.0 provider credential +// Update an OAuth 2.0 provider credential. func (c *Client) UpdateOAuth2Credential(ctx context.Context, input UpdateOAuth2CredentialRequest) (*UpdateOAuth2CredentialResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -3997,7 +4197,7 @@ func (c *Client) StampUpdateRootQuorum(ctx context.Context, input UpdateRootQuor return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/update_root_quorum", body, true) } -// Set the live deployment for a TVC App +// Set the live deployment for a TVC app. func (c *Client) UpdateTVCAppLiveDeployment(ctx context.Context, input UpdateTVCAppLiveDeploymentRequest) (*UpdateTVCAppLiveDeploymentResponse, error) { body, err := c.activityEnvelope(input) if err != nil { @@ -4258,7 +4458,7 @@ func (c *Client) StampUpsertSwapConfig(ctx context.Context, input UpsertSwapConf return c.signedRequest(ctx, c.config.urls.baseURL, "/public/v1/submit/upsert_swap_config", body, true) } -// Validate a container image URL and pull secret for TVC deployment +// Validate a container image URL and pull secret for TVC deployment. func (c *Client) ValidateTVCImage(ctx context.Context, input ValidateTVCImageRequest) (*ValidateTVCImageResponse, error) { organizationID, err := c.organizationID(input.OrganizationID) if err != nil { diff --git a/codegen/generators/generate.go b/codegen/generators/generate.go index e08a666..3d0e0e1 100644 --- a/codegen/generators/generate.go +++ b/codegen/generators/generate.go @@ -10,16 +10,17 @@ import ( // Options configures SDK code generation. type Options struct { - PublicSwaggerPath string - AuthProxySwaggerPath string - ActivitiesPath string - OutDir string - AllVersions bool + PublicSwaggerPath string + AuthProxySwaggerPath string + ExternalSignerSwaggerPath string + ActivitiesPath string + OutDir string + AllVersions bool } // Generate writes generated SDK client and type files. func Generate(opts Options) ([]string, error) { - specs, err := readSpecs([]string{opts.PublicSwaggerPath, opts.AuthProxySwaggerPath}) + specs, err := readSpecs([]string{opts.PublicSwaggerPath, opts.AuthProxySwaggerPath, opts.ExternalSignerSwaggerPath}) if err != nil { return nil, err } diff --git a/codegen/generators/generator.go b/codegen/generators/generator.go index e84993b..432e2df 100644 --- a/codegen/generators/generator.go +++ b/codegen/generators/generator.go @@ -10,17 +10,22 @@ import ( // in the auth proxy spec). const authProxyOnlyPrefix = "__authProxyOnly__" +// externalSignerOnlyPrefix is the equivalent internal disambiguation prefix for the +// external-signer spec. +const externalSignerOnlyPrefix = "__externalSignerOnly__" + type generator struct { - specs []*swaggerSpec - definitions map[string]*schema - authProxyDefs map[string]bool - authProxyRefRemap map[string]string // original ref name → remapped key (for divergent shared defs) - nameByRef map[string]string - rawByGoName map[string]string // reverse of nameByRef: Go exported name → swagger raw key - usedNames map[string]string - operations []operationInfo - activitiesConfig *activitiesConfig - allVersions bool + specs []*swaggerSpec + definitions map[string]*schema + defNamePrefix map[string]string // raw definition key → Go name prefix ("AuthProxy", "ExternalSigner") + authProxyRefRemap map[string]string // original ref name → remapped key (for divergent shared defs) + externalSignerRefRemap map[string]string + nameByRef map[string]string + rawByGoName map[string]string // reverse of nameByRef: Go exported name → swagger raw key + usedNames map[string]string + operations []operationInfo + activitiesConfig *activitiesConfig + allVersions bool } type operationInfo struct { @@ -49,46 +54,151 @@ const ( func newGenerator(specs []*swaggerSpec, cfg *activitiesConfig, allVersions bool) *generator { g := &generator{ - specs: specs, - definitions: map[string]*schema{}, - authProxyDefs: map[string]bool{}, - authProxyRefRemap: map[string]string{}, - nameByRef: map[string]string{}, - rawByGoName: map[string]string{}, - usedNames: map[string]string{}, - activitiesConfig: cfg, - allVersions: allVersions, + specs: specs, + definitions: map[string]*schema{}, + defNamePrefix: map[string]string{}, + authProxyRefRemap: map[string]string{}, + externalSignerRefRemap: map[string]string{}, + nameByRef: map[string]string{}, + rawByGoName: map[string]string{}, + usedNames: map[string]string{}, + activitiesConfig: cfg, + allVersions: allVersions, } // Load public spec first; it wins for identically-shaped shared definitions. - if len(specs) > 0 { - for name, def := range specs[0].Definitions { + for name, def := range specs[0].Definitions { + g.definitions[name] = def + } + + // auth proxy spec + g.authProxyRefRemap = g.mergeSecondarySpec(specs[1], "AuthProxy", authProxyOnlyPrefix, true) + + // protoc-gen-openapiv2 names a message by its short name when that is unique + // within the generated file set and by its fully-qualified name otherwise, so + // the same proto message can surface under different definition names in + // different specs (e.g. v1PayloadEncoding vs immutablecommonv1PayloadEncoding). + // Canonicalize those aliases onto the public names before merging so shared + // definitions compare equal instead of spawning duplicate types. + // external signer spec + canonicalizeAliasedDefs(specs[2], specs[0]) + g.externalSignerRefRemap = g.mergeSecondarySpec(specs[2], "ExternalSigner", externalSignerOnlyPrefix, false) + + g.buildNameMap() + + return g +} + +// mergeSecondarySpec merges a non-public spec's definitions into the generator. +// Definitions identical to a same-named public one are dropped in favor of the public +// def; divergent same-named ones are stored under internalKeyPrefix and reported in +// the returned ref-remap; spec-only definitions are stored as-is, Go-name-prefixed +// with goNamePrefix only when prefixNewDefs is set. +func (g *generator) mergeSecondarySpec(spec *swaggerSpec, goNamePrefix string, internalKeyPrefix string, prefixNewDefs bool) map[string]string { + refRemap := map[string]string{} + + for name, def := range spec.Definitions { + pubDef, sharedWithPublic := g.specs[0].Definitions[name] + switch { + case !sharedWithPublic: g.definitions[name] = def + if prefixNewDefs { + g.defNamePrefix[name] = goNamePrefix + } + case schemasEqual(pubDef, def): + // Identical shape across specs — public def already stored, no prefix needed. + default: + // Divergent: store this spec's version under a separate internal key. + remapped := internalKeyPrefix + name + g.definitions[remapped] = def + g.defNamePrefix[remapped] = goNamePrefix + refRemap[name] = remapped } } - if len(specs) > 1 { - for name, def := range specs[1].Definitions { - pubDef, sharedWithPublic := specs[0].Definitions[name] - switch { - case !sharedWithPublic: - // Auth-proxy-only: store and prefix with AuthProxy. - g.definitions[name] = def - g.authProxyDefs[name] = true - case schemasEqual(pubDef, def): - // Identical shape across specs — public def already stored, no prefix needed. - default: - // Divergent: store the auth-proxy version under a separate internal key. - remapped := authProxyOnlyPrefix + name - g.definitions[remapped] = def - g.authProxyDefs[remapped] = true - g.authProxyRefRemap[name] = remapped + return refRemap +} + +// canonicalizeAliasedDefs finds definitions in spec that do not exist under the same +// name in the base spec but are byte-identical to exactly one base definition, then +// renames them (dropping the duplicate and rewriting every $ref) onto the base name. +// Runs to a fixpoint so definitions that only differ through such refs collapse too. +func canonicalizeAliasedDefs(spec *swaggerSpec, base *swaggerSpec) { + for { + renames := map[string]string{} + + for _, name := range sortedKeys(spec.Definitions) { + if _, inBase := base.Definitions[name]; inBase { + continue } + + target := "" + for _, baseName := range sortedKeys(base.Definitions) { + if !schemasEqual(spec.Definitions[name], base.Definitions[baseName]) { + continue + } + + if target != "" { + // Ambiguous shape match — leave the definition alone. + target = "" + break + } + + target = baseName + } + + if target != "" { + renames[name] = target + } + } + + if len(renames) == 0 { + return } + + for name := range renames { + delete(spec.Definitions, name) + } + + rewriteSpecRefs(spec, renames) } +} - g.buildNameMap() +func rewriteSpecRefs(spec *swaggerSpec, renames map[string]string) { + for _, def := range spec.Definitions { + rewriteSchemaRefs(def, renames) + } - return g + for _, item := range spec.Paths { + if item.Post == nil { + continue + } + + for _, param := range item.Post.Parameters { + rewriteSchemaRefs(param.Schema, renames) + } + + for _, resp := range item.Post.Responses { + rewriteSchemaRefs(resp.Schema, renames) + } + } +} + +func rewriteSchemaRefs(s *schema, renames map[string]string) { + if s == nil { + return + } + + if s.Ref != "" { + if target, ok := renames[refName(s.Ref)]; ok { + s.Ref = "#/definitions/" + target + } + } + + rewriteSchemaRefs(s.Items, renames) + + for _, prop := range s.Properties { + rewriteSchemaRefs(prop, renames) + } } func schemasEqual(a, b *schema) bool { diff --git a/codegen/generators/naming.go b/codegen/generators/naming.go index 13b94fc..8cb84d0 100644 --- a/codegen/generators/naming.go +++ b/codegen/generators/naming.go @@ -149,6 +149,8 @@ func normalizeProtoPackagePrefixes(raw string) string { "externalDataV1", "external_data_v1_", "externaldatav1", "external_data_v1_", "externalactivityv1", "external_activity_v1_", + "externalCryptoV1", "external_crypto_v1_", + "externalcryptov1", "external_crypto_v1_", "commonV1", "common_v1_", "commonv1", "common_v1_", "dataV1", "data_v1_", diff --git a/codegen/generators/operations.go b/codegen/generators/operations.go index ca06e5c..f5fcc3a 100644 --- a/codegen/generators/operations.go +++ b/codegen/generators/operations.go @@ -7,12 +7,8 @@ import ( "strings" ) -func (g *generator) remapAuthProxyRef(authProxy bool, ref string) string { - if !authProxy || ref == "" { - return ref - } - - if remapped, ok := g.authProxyRefRemap[ref]; ok { +func remapSecondaryRef(remap map[string]string, ref string) string { + if remapped, ok := remap[ref]; ok { return remapped } @@ -23,20 +19,18 @@ var activityWireBodyRE = regexp.MustCompile(`Request(V\d+)?$`) const typeObject = "object" -//nolint:gocyclo // name-deduplication logic requires tracking several concurrent states func (g *generator) buildNameMap() { names := sortedKeys(g.definitions) for _, raw := range names { nameSource := strings.TrimPrefix(raw, authProxyOnlyPrefix) + nameSource = strings.TrimPrefix(nameSource, externalSignerOnlyPrefix) base := exportedName(stripLeadingVersion(normalizeProtoPackagePrefixes(nameSource))) if base == "" { continue } - if g.authProxyDefs[raw] { - base = "AuthProxy" + base - } + base = g.defNamePrefix[raw] + base // Activity wire envelopes (type + timestampMs + organizationId + parameters) // get a Body suffix so they don't collide with the sugared XxxRequest // method-input types emitted by writeActivityInput. @@ -46,10 +40,7 @@ func (g *generator) buildNameMap() { name := base if owner, exists := g.usedNames[name]; exists && owner != raw { - name = exportedName(stripLeadingVersion(nameSource)) - if g.authProxyDefs[raw] { - name = "AuthProxy" + name - } + name = g.defNamePrefix[raw] + exportedName(stripLeadingVersion(nameSource)) for i := 2; ; i++ { if _, taken := g.usedNames[name]; !taken { @@ -98,7 +89,18 @@ func (g *generator) collectOperations() { // Activity types emitted from swagger endpoints (current versions). currentActivityTypes := map[string]bool{} - for _, spec := range g.specs { + for specIndex, spec := range g.specs { + // Operation-level refs from a secondary spec must resolve to that spec's + // internally-remapped keys for definitions that diverge from the public spec. + refRemap := map[string]string{} + + switch specIndex { + case 1: + refRemap = g.authProxyRefRemap + case 2: + refRemap = g.externalSignerRefRemap + } + for _, path := range sortedKeys(spec.Paths) { item := spec.Paths[path] if item.Post == nil { @@ -109,13 +111,14 @@ func (g *generator) collectOperations() { operationName := strings.TrimPrefix(op.OperationID, "PublicApiService_") operationName = strings.TrimPrefix(operationName, "AuthProxyService_") + operationName = strings.TrimPrefix(operationName, "ExternalSignerApiService_") if operationName == "" || strings.Contains(operationName, "NOOP") { continue } authProxy := strings.HasPrefix(op.OperationID, "AuthProxyService_") - requestDef := g.remapAuthProxyRef(authProxy, requestDefinition(op)) - responseDef := g.remapAuthProxyRef(authProxy, responseDefinition(op)) + requestDef := remapSecondaryRef(refRemap, requestDefinition(op)) + responseDef := remapSecondaryRef(refRemap, responseDefinition(op)) methodType := g.methodType(op, path, responseDef) activityType := g.activityType(operationName, requestDef) // activities.json is the authoritative source for intent/result types. diff --git a/codegen/inputs/activities.json b/codegen/inputs/activities.json index 07ac525..07cad50 100644 --- a/codegen/inputs/activities.json +++ b/codegen/inputs/activities.json @@ -208,6 +208,10 @@ "intentType": "InitImportSecretsIntent", "resultType": "InitImportSecretsResult" }, + "ACTIVITY_TYPE_DELETE_SECRETS": { + "intentType": "DeleteSecretsIntent", + "resultType": "DeleteSecretsResult" + }, "ACTIVITY_TYPE_IMPORT_SECRETS": { "intentType": "ImportSecretsIntent", "resultType": "ImportSecretsResult" @@ -340,6 +344,10 @@ "intentType": "ClaimEarnFeesIntent", "resultType": "ClaimEarnFeesResult" }, + "ACTIVITY_TYPE_EARN_CLAIM_REWARDS": { + "intentType": "EarnClaimRewardsIntent", + "resultType": "EarnClaimRewardsResult" + }, "ACTIVITY_TYPE_EARN_DEPLOY_WRAPPER": { "intentType": "EarnDeployWrapperIntent", "resultType": "EarnDeployWrapperResult" @@ -368,6 +376,14 @@ "intentType": "CreateSwapQuoteIntent", "resultType": "CreateSwapQuoteResult" }, + "ACTIVITY_TYPE_CREATE_SWAP_QUOTE_V2": { + "intentType": "CreateSwapQuoteIntentV2", + "resultType": "CreateSwapQuoteResult" + }, + "ACTIVITY_TYPE_EXECUTE_SWAP_V3": { + "intentType": "ExecuteSwapIntentV3", + "resultType": "ExecuteSwapResult" + }, "ACTIVITY_TYPE_UPSERT_SWAP_CONFIG": { "intentType": "UpsertSwapConfigIntent", "resultType": "UpsertSwapConfigResult" @@ -667,14 +683,33 @@ "intentType": "CreateVelocityControlIntent", "resultType": "CreateVelocityControlResult" }, - "ACTIVITY_TYPE_DELETE_VELOCITY_CONTROL": { - "intentType": "DeleteVelocityControlIntent", - "resultType": "DeleteVelocityControlResult" + "ACTIVITY_TYPE_DELETE_VELOCITY_CONTROLS": { + "intentType": "DeleteVelocityControlsIntent", + "resultType": "DeleteVelocityControlsResult" + }, + "ACTIVITY_TYPE_UPDATE_PAYMENT_METHOD": { + "intentType": "UpdatePaymentMethodIntent", + "resultType": "UpdatePaymentMethodResult" }, "ACTIVITY_TYPE_UNSPECIFIED": { "intentType": "*", "resultType": "*", "internal": true + }, + "ACTIVITY_TYPE_CREATE_SWAP_QUOTE_V3": { + "intentType": "CreateSwapQuoteIntentV3", + "resultType": "CreateSwapQuoteResultV2", + "internal": true + }, + "ACTIVITY_TYPE_UPSERT_SWAP_FEE_SPONSORSHIP_LIMIT_CONFIG": { + "intentType": "UpsertSwapFeeSponsorshipLimitConfigIntent", + "resultType": "UpsertSwapFeeSponsorshipLimitConfigResult", + "internal": true + }, + "ACTIVITY_TYPE_UPSERT_SWAP_FIXED_RATE_LIMIT_CONFIG": { + "intentType": "UpsertSwapFixedRateLimitConfigIntent", + "resultType": "UpsertSwapFixedRateLimitConfigResult", + "internal": true } } } diff --git a/codegen/inputs/auth_proxy.swagger.json b/codegen/inputs/auth_proxy.swagger.json index 70e62e3..1c068cc 100644 --- a/codegen/inputs/auth_proxy.swagger.json +++ b/codegen/inputs/auth_proxy.swagger.json @@ -663,6 +663,10 @@ "oidcToken": { "type": "string", "description": "OIDC token to verify access to PII (email/phone number) when filter_type is 'EMAIL' or 'PHONE_NUMBER'. Needed for social linking when verification_token is not available." + }, + "includeRequiresSocialLinking": { + "type": "boolean", + "description": "Whether to include requires_social_linking in the response. Only applies when filter_type is 'OIDC_TOKEN'." } }, "required": ["filterType", "filterValue"] @@ -672,6 +676,10 @@ "properties": { "organizationId": { "type": "string" + }, + "requiresSocialLinking": { + "type": "boolean", + "description": "True when the organization was matched by verified email and the OIDC token is not yet a registered identity on it." } } }, diff --git a/codegen/inputs/external_signer_api.swagger.json b/codegen/inputs/external_signer_api.swagger.json new file mode 100644 index 0000000..fe50999 --- /dev/null +++ b/codegen/inputs/external_signer_api.swagger.json @@ -0,0 +1,10045 @@ +{ + "swagger": "2.0", + "info": { + "title": "services/coordinator/external_signer/v1/external_signer_api.proto", + "version": "version not set" + }, + "tags": [ + { + "name": "ExternalSignerApiService" + } + ], + "consumes": ["application/json"], + "produces": ["application/json"], + "paths": { + "/external_signer/v1/query/get_external_signer_tasks": { + "post": { + "summary": "Get External Signer Tasks", + "description": "Get a batch of external signer tasks.", + "operationId": "ExternalSignerApiService_GetExternalSignerTasks", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1GetExternalSignerTasksResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1GetExternalSignerTasksRequest" + } + } + ], + "tags": ["ExternalSigner"] + } + } + }, + "definitions": { + "apiApiKeyParams": { + "type": "object", + "properties": { + "apiKeyName": { + "type": "string", + "description": "Human-readable name for an API Key." + }, + "publicKey": { + "type": "string", + "description": "The public component of a cryptographic key pair used to sign messages and transactions." + }, + "expirationSeconds": { + "type": "string", + "description": "Optional window (in seconds) indicating how long the API Key should last." + } + }, + "required": ["apiKeyName", "publicKey"] + }, + "billingActivateBillingTierIntent": { + "type": "object", + "properties": { + "productId": { + "type": "string", + "description": "The product that the customer wants to subscribe to." + }, + "orbPlanId": { + "type": "string" + } + }, + "required": ["productId"] + }, + "billingActivateBillingTierResult": { + "type": "object", + "properties": { + "productId": { + "type": "string", + "description": "The id of the product being subscribed to." + } + }, + "required": ["productId"] + }, + "billingDeletePaymentMethodIntent": { + "type": "object", + "properties": { + "paymentMethodId": { + "type": "string", + "description": "The payment method that the customer wants to remove." + } + }, + "required": ["paymentMethodId"] + }, + "billingDeletePaymentMethodResult": { + "type": "object", + "properties": { + "paymentMethodId": { + "type": "string", + "description": "The payment method that was removed." + } + }, + "required": ["paymentMethodId"] + }, + "billingSetPaymentMethodIntent": { + "type": "object", + "properties": { + "number": { + "type": "string", + "description": "The account number of the customer's credit card." + }, + "cvv": { + "type": "string", + "description": "The verification digits of the customer's credit card." + }, + "expiryMonth": { + "type": "string", + "description": "The month that the credit card expires." + }, + "expiryYear": { + "type": "string", + "description": "The year that the credit card expires." + }, + "cardHolderEmail": { + "type": "string", + "description": "The email that will receive invoices for the credit card." + }, + "cardHolderName": { + "type": "string", + "description": "The name associated with the credit card." + } + }, + "required": [ + "number", + "cvv", + "expiryMonth", + "expiryYear", + "cardHolderEmail", + "cardHolderName" + ] + }, + "billingSetPaymentMethodIntentV2": { + "type": "object", + "properties": { + "paymentMethodId": { + "type": "string", + "description": "The id of the payment method that was created clientside." + }, + "cardHolderEmail": { + "type": "string", + "description": "The email that will receive invoices for the credit card." + }, + "cardHolderName": { + "type": "string", + "description": "The name associated with the credit card." + } + }, + "required": ["paymentMethodId", "cardHolderEmail", "cardHolderName"] + }, + "billingSetPaymentMethodResult": { + "type": "object", + "properties": { + "lastFour": { + "type": "string", + "description": "The last four digits of the credit card added." + }, + "cardHolderName": { + "type": "string", + "description": "The name associated with the payment method." + }, + "cardHolderEmail": { + "type": "string", + "description": "The email address associated with the payment method." + } + }, + "required": ["lastFour", "cardHolderName", "cardHolderEmail"] + }, + "billingUpdatePaymentMethodIntent": { + "type": "object", + "properties": { + "paymentEmail": { + "type": "string", + "description": "The email that will receive invoices for the payment method." + } + }, + "required": ["paymentEmail"] + }, + "billingUpdatePaymentMethodResult": { + "type": "object", + "properties": { + "paymentEmail": { + "type": "string", + "description": "The email address associated with the payment method." + } + }, + "required": ["paymentEmail"] + }, + "externalcryptov1Signature": { + "type": "object", + "properties": { + "scheme": { + "$ref": "#/definitions/externalcryptov1SignatureScheme" + }, + "publicKey": { + "type": "string" + }, + "message": { + "type": "string" + }, + "signature": { + "type": "string" + } + } + }, + "externalcryptov1SignatureScheme": { + "type": "string", + "enum": [ + "SIGNATURE_SCHEME_TK_API_P256", + "SIGNATURE_SCHEME_TK_WEBAUTHN", + "SIGNATURE_SCHEME_TK_QUORUM_P256" + ] + }, + "externaldatav1Credential": { + "type": "object", + "properties": { + "publicKey": { + "type": "string", + "description": "The public component of a cryptographic key pair used to sign messages and transactions." + }, + "type": { + "$ref": "#/definitions/v1CredentialType" + }, + "sessionProfileId": { + "type": "string", + "description": "The session profile associated with this credential, if any. This field is only applicable for credentials of type CREDENTIAL_TYPE_LOGIN." + } + }, + "required": ["publicKey", "type"] + }, + "externaldatav1SignatureScheme": { + "type": "string", + "enum": ["SIGNATURE_SCHEME_EPHEMERAL_KEY_P256"] + }, + "externaldatav1Timestamp": { + "type": "object", + "properties": { + "seconds": { + "type": "string" + }, + "nanos": { + "type": "string" + } + }, + "required": ["seconds", "nanos"] + }, + "immutableactivityv1Address": { + "type": "object", + "properties": { + "format": { + "$ref": "#/definitions/v1AddressFormat" + }, + "address": { + "type": "string" + } + } + }, + "immutablecommonv1HashFunction": { + "type": "string", + "enum": [ + "HASH_FUNCTION_NO_OP", + "HASH_FUNCTION_SHA256", + "HASH_FUNCTION_KECCAK256", + "HASH_FUNCTION_NOT_APPLICABLE" + ] + }, + "immutablecommonv1PayloadEncoding": { + "type": "string", + "enum": [ + "PAYLOAD_ENCODING_HEXADECIMAL", + "PAYLOAD_ENCODING_TEXT_UTF8", + "PAYLOAD_ENCODING_EIP712", + "PAYLOAD_ENCODING_EIP7702_AUTHORIZATION" + ] + }, + "protobufAny": { + "type": "object", + "properties": { + "@type": { + "type": "string" + } + }, + "additionalProperties": {} + }, + "rpcStatus": { + "type": "object", + "properties": { + "code": { + "type": "integer", + "format": "int32" + }, + "message": { + "type": "string" + }, + "details": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/protobufAny" + } + } + } + }, + "v1AcceptInvitationIntent": { + "type": "object", + "properties": { + "invitationId": { + "type": "string", + "description": "Unique identifier for a given Invitation object." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "authenticator": { + "$ref": "#/definitions/v1AuthenticatorParams", + "description": "WebAuthN hardware devices that can be used to log in to the Turnkey web app." + } + }, + "required": ["invitationId", "userId", "authenticator"] + }, + "v1AcceptInvitationIntentV2": { + "type": "object", + "properties": { + "invitationId": { + "type": "string", + "description": "Unique identifier for a given Invitation object." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "authenticator": { + "$ref": "#/definitions/v1AuthenticatorParamsV2", + "description": "WebAuthN hardware devices that can be used to log in to the Turnkey web app." + } + }, + "required": ["invitationId", "userId", "authenticator"] + }, + "v1AcceptInvitationResult": { + "type": "object", + "properties": { + "invitationId": { + "type": "string", + "description": "Unique identifier for a given Invitation." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + } + }, + "required": ["invitationId", "userId"] + }, + "v1AccessType": { + "type": "string", + "enum": ["ACCESS_TYPE_WEB", "ACCESS_TYPE_API", "ACCESS_TYPE_ALL"] + }, + "v1Activity": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "Unique identifier for a given Activity object." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "status": { + "$ref": "#/definitions/v1ActivityStatus", + "description": "The current processing status of a specified Activity." + }, + "type": { + "$ref": "#/definitions/v1ActivityType", + "description": "Type of Activity, such as Add User, or Sign Transaction." + }, + "intent": { + "$ref": "#/definitions/v1Intent", + "description": "Intent object crafted by Turnkey based on the user request, used to assess the permissibility of an action." + }, + "result": { + "$ref": "#/definitions/v1Result", + "description": "Result of the intended action." + }, + "votes": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1Vote" + }, + "description": "A list of objects representing a particular User's approval or rejection of a Consensus request, including all relevant metadata." + }, + "appProofs": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AppProof" + }, + "description": "A list of App Proofs generated by enclaves during activity execution, providing verifiable attestations of performed operations." + }, + "fingerprint": { + "type": "string", + "description": "An artifact verifying a User's action." + }, + "canApprove": { + "type": "boolean" + }, + "canReject": { + "type": "boolean" + }, + "createdAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "updatedAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "failure": { + "$ref": "#/definitions/rpcStatus", + "description": "Failure reason of the intended action." + } + }, + "required": [ + "id", + "organizationId", + "status", + "type", + "intent", + "result", + "votes", + "fingerprint", + "canApprove", + "canReject", + "createdAt", + "updatedAt" + ] + }, + "v1ActivityStatus": { + "type": "string", + "enum": [ + "ACTIVITY_STATUS_CREATED", + "ACTIVITY_STATUS_PENDING", + "ACTIVITY_STATUS_COMPLETED", + "ACTIVITY_STATUS_FAILED", + "ACTIVITY_STATUS_CONSENSUS_NEEDED", + "ACTIVITY_STATUS_REJECTED", + "ACTIVITY_STATUS_AUTHENTICATORS_NEEDED" + ] + }, + "v1ActivityType": { + "type": "string", + "enum": [ + "ACTIVITY_TYPE_CREATE_API_KEYS", + "ACTIVITY_TYPE_CREATE_USERS", + "ACTIVITY_TYPE_CREATE_PRIVATE_KEYS", + "ACTIVITY_TYPE_SIGN_RAW_PAYLOAD", + "ACTIVITY_TYPE_CREATE_INVITATIONS", + "ACTIVITY_TYPE_ACCEPT_INVITATION", + "ACTIVITY_TYPE_CREATE_POLICY", + "ACTIVITY_TYPE_DISABLE_PRIVATE_KEY", + "ACTIVITY_TYPE_DELETE_USERS", + "ACTIVITY_TYPE_DELETE_API_KEYS", + "ACTIVITY_TYPE_DELETE_INVITATION", + "ACTIVITY_TYPE_DELETE_ORGANIZATION", + "ACTIVITY_TYPE_DELETE_POLICY", + "ACTIVITY_TYPE_CREATE_USER_TAG", + "ACTIVITY_TYPE_DELETE_USER_TAGS", + "ACTIVITY_TYPE_CREATE_ORGANIZATION", + "ACTIVITY_TYPE_SIGN_TRANSACTION", + "ACTIVITY_TYPE_APPROVE_ACTIVITY", + "ACTIVITY_TYPE_REJECT_ACTIVITY", + "ACTIVITY_TYPE_DELETE_AUTHENTICATORS", + "ACTIVITY_TYPE_CREATE_AUTHENTICATORS", + "ACTIVITY_TYPE_CREATE_PRIVATE_KEY_TAG", + "ACTIVITY_TYPE_DELETE_PRIVATE_KEY_TAGS", + "ACTIVITY_TYPE_SET_PAYMENT_METHOD", + "ACTIVITY_TYPE_ACTIVATE_BILLING_TIER", + "ACTIVITY_TYPE_DELETE_PAYMENT_METHOD", + "ACTIVITY_TYPE_CREATE_POLICY_V2", + "ACTIVITY_TYPE_CREATE_POLICY_V3", + "ACTIVITY_TYPE_CREATE_API_ONLY_USERS", + "ACTIVITY_TYPE_UPDATE_ROOT_QUORUM", + "ACTIVITY_TYPE_UPDATE_USER_TAG", + "ACTIVITY_TYPE_UPDATE_PRIVATE_KEY_TAG", + "ACTIVITY_TYPE_CREATE_AUTHENTICATORS_V2", + "ACTIVITY_TYPE_CREATE_ORGANIZATION_V2", + "ACTIVITY_TYPE_CREATE_USERS_V2", + "ACTIVITY_TYPE_ACCEPT_INVITATION_V2", + "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION", + "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V2", + "ACTIVITY_TYPE_UPDATE_ALLOWED_ORIGINS", + "ACTIVITY_TYPE_CREATE_PRIVATE_KEYS_V2", + "ACTIVITY_TYPE_UPDATE_USER", + "ACTIVITY_TYPE_UPDATE_POLICY", + "ACTIVITY_TYPE_SET_PAYMENT_METHOD_V2", + "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V3", + "ACTIVITY_TYPE_CREATE_WALLET", + "ACTIVITY_TYPE_CREATE_WALLET_ACCOUNTS", + "ACTIVITY_TYPE_INIT_USER_EMAIL_RECOVERY", + "ACTIVITY_TYPE_RECOVER_USER", + "ACTIVITY_TYPE_SET_ORGANIZATION_FEATURE", + "ACTIVITY_TYPE_REMOVE_ORGANIZATION_FEATURE", + "ACTIVITY_TYPE_SIGN_RAW_PAYLOAD_V2", + "ACTIVITY_TYPE_SIGN_TRANSACTION_V2", + "ACTIVITY_TYPE_EXPORT_PRIVATE_KEY", + "ACTIVITY_TYPE_EXPORT_WALLET", + "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V4", + "ACTIVITY_TYPE_EMAIL_AUTH", + "ACTIVITY_TYPE_EXPORT_WALLET_ACCOUNT", + "ACTIVITY_TYPE_INIT_IMPORT_WALLET", + "ACTIVITY_TYPE_IMPORT_WALLET", + "ACTIVITY_TYPE_INIT_IMPORT_PRIVATE_KEY", + "ACTIVITY_TYPE_IMPORT_PRIVATE_KEY", + "ACTIVITY_TYPE_CREATE_POLICIES", + "ACTIVITY_TYPE_SIGN_RAW_PAYLOADS", + "ACTIVITY_TYPE_CREATE_READ_ONLY_SESSION", + "ACTIVITY_TYPE_CREATE_OAUTH_PROVIDERS", + "ACTIVITY_TYPE_DELETE_OAUTH_PROVIDERS", + "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V5", + "ACTIVITY_TYPE_OAUTH", + "ACTIVITY_TYPE_CREATE_API_KEYS_V2", + "ACTIVITY_TYPE_CREATE_READ_WRITE_SESSION", + "ACTIVITY_TYPE_EMAIL_AUTH_V2", + "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V6", + "ACTIVITY_TYPE_DELETE_PRIVATE_KEYS", + "ACTIVITY_TYPE_DELETE_WALLETS", + "ACTIVITY_TYPE_CREATE_READ_WRITE_SESSION_V2", + "ACTIVITY_TYPE_DELETE_SUB_ORGANIZATION", + "ACTIVITY_TYPE_INIT_OTP_AUTH", + "ACTIVITY_TYPE_OTP_AUTH", + "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V7", + "ACTIVITY_TYPE_UPDATE_WALLET", + "ACTIVITY_TYPE_UPDATE_POLICY_V2", + "ACTIVITY_TYPE_CREATE_USERS_V3", + "ACTIVITY_TYPE_INIT_OTP_AUTH_V2", + "ACTIVITY_TYPE_INIT_OTP", + "ACTIVITY_TYPE_VERIFY_OTP", + "ACTIVITY_TYPE_OTP_LOGIN", + "ACTIVITY_TYPE_STAMP_LOGIN", + "ACTIVITY_TYPE_OAUTH_LOGIN", + "ACTIVITY_TYPE_UPDATE_USER_NAME", + "ACTIVITY_TYPE_UPDATE_USER_EMAIL", + "ACTIVITY_TYPE_UPDATE_USER_PHONE_NUMBER", + "ACTIVITY_TYPE_INIT_FIAT_ON_RAMP", + "ACTIVITY_TYPE_CREATE_SMART_CONTRACT_INTERFACE", + "ACTIVITY_TYPE_DELETE_SMART_CONTRACT_INTERFACE", + "ACTIVITY_TYPE_ENABLE_AUTH_PROXY", + "ACTIVITY_TYPE_DISABLE_AUTH_PROXY", + "ACTIVITY_TYPE_UPDATE_AUTH_PROXY_CONFIG", + "ACTIVITY_TYPE_CREATE_OAUTH2_CREDENTIAL", + "ACTIVITY_TYPE_UPDATE_OAUTH2_CREDENTIAL", + "ACTIVITY_TYPE_DELETE_OAUTH2_CREDENTIAL", + "ACTIVITY_TYPE_OAUTH2_AUTHENTICATE", + "ACTIVITY_TYPE_DELETE_WALLET_ACCOUNTS", + "ACTIVITY_TYPE_DELETE_POLICIES", + "ACTIVITY_TYPE_ETH_SEND_RAW_TRANSACTION", + "ACTIVITY_TYPE_ETH_SEND_TRANSACTION", + "ACTIVITY_TYPE_CREATE_FIAT_ON_RAMP_CREDENTIAL", + "ACTIVITY_TYPE_UPDATE_FIAT_ON_RAMP_CREDENTIAL", + "ACTIVITY_TYPE_DELETE_FIAT_ON_RAMP_CREDENTIAL", + "ACTIVITY_TYPE_EMAIL_AUTH_V3", + "ACTIVITY_TYPE_INIT_USER_EMAIL_RECOVERY_V2", + "ACTIVITY_TYPE_INIT_OTP_AUTH_V3", + "ACTIVITY_TYPE_INIT_OTP_V2", + "ACTIVITY_TYPE_UPSERT_GAS_USAGE_CONFIG", + "ACTIVITY_TYPE_CREATE_TVC_APP", + "ACTIVITY_TYPE_CREATE_TVC_DEPLOYMENT", + "ACTIVITY_TYPE_CREATE_TVC_MANIFEST_APPROVALS", + "ACTIVITY_TYPE_SOL_SEND_TRANSACTION", + "ACTIVITY_TYPE_INIT_OTP_V3", + "ACTIVITY_TYPE_VERIFY_OTP_V2", + "ACTIVITY_TYPE_OTP_LOGIN_V2", + "ACTIVITY_TYPE_UPDATE_ORGANIZATION_NAME", + "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V8", + "ACTIVITY_TYPE_CREATE_OAUTH_PROVIDERS_V2", + "ACTIVITY_TYPE_CREATE_USERS_V4", + "ACTIVITY_TYPE_CREATE_WEBHOOK_ENDPOINT", + "ACTIVITY_TYPE_UPDATE_WEBHOOK_ENDPOINT", + "ACTIVITY_TYPE_DELETE_WEBHOOK_ENDPOINT", + "ACTIVITY_TYPE_SET_IP_ALLOWLIST", + "ACTIVITY_TYPE_REMOVE_IP_ALLOWLIST", + "ACTIVITY_TYPE_UPDATE_TVC_APP_LIVE_DEPLOYMENT", + "ACTIVITY_TYPE_DELETE_TVC_DEPLOYMENT", + "ACTIVITY_TYPE_DELETE_TVC_APP_AND_DEPLOYMENTS", + "ACTIVITY_TYPE_RESTORE_TVC_DEPLOYMENT", + "ACTIVITY_TYPE_SPARK_SIGN_FROST", + "ACTIVITY_TYPE_SPARK_PREPARE_TRANSFER", + "ACTIVITY_TYPE_SPARK_CLAIM_TRANSFER", + "ACTIVITY_TYPE_SPARK_PREPARE_LIGHTNING_RECEIVE", + "ACTIVITY_TYPE_POST_TVC_QUORUM_KEY_SHARE", + "ACTIVITY_TYPE_ETH_SEND_TRANSACTION_V2", + "ACTIVITY_TYPE_CREATE_MFA_POLICY", + "ACTIVITY_TYPE_UPDATE_MFA_POLICY", + "ACTIVITY_TYPE_DELETE_MFA_POLICY", + "ACTIVITY_TYPE_CREATE_SESSION_PROFILE", + "ACTIVITY_TYPE_EARN_DEPLOY_WRAPPER", + "ACTIVITY_TYPE_EARN_DEPOSIT", + "ACTIVITY_TYPE_EARN_WITHDRAW", + "ACTIVITY_TYPE_EXECUTE_SWAP", + "ACTIVITY_TYPE_UPSERT_SWAP_CONFIG", + "ACTIVITY_TYPE_CREATE_TVC_OPERATOR", + "ACTIVITY_TYPE_CREATE_TVC_QUORUM_KEY", + "ACTIVITY_TYPE_RE_ENCRYPT_TVC_QUORUM_KEY_SHARE", + "ACTIVITY_TYPE_INIT_IMPORT_SECRETS", + "ACTIVITY_TYPE_SOL_SEND_TRANSACTION_V2", + "ACTIVITY_TYPE_CLAIM_SWAP_FEES", + "ACTIVITY_TYPE_EARN_SET_WRAPPER_STATE", + "ACTIVITY_TYPE_CLAIM_EARN_FEES", + "ACTIVITY_TYPE_UPDATE_WALLET_ACCOUNT_NAME", + "ACTIVITY_TYPE_ETH_UNDELEGATE_7702", + "ACTIVITY_TYPE_EXECUTE_SWAP_V2", + "ACTIVITY_TYPE_CREATE_SWAP_QUOTE", + "ACTIVITY_TYPE_IMPORT_SECRETS", + "ACTIVITY_TYPE_EXPORT_SECRETS", + "ACTIVITY_TYPE_CREATE_VELOCITY_CONTROL", + "ACTIVITY_TYPE_DELETE_VELOCITY_CONTROLS", + "ACTIVITY_TYPE_UPDATE_PAYMENT_METHOD", + "ACTIVITY_TYPE_CREATE_SWAP_QUOTE_V2", + "ACTIVITY_TYPE_EXECUTE_SWAP_V3", + "ACTIVITY_TYPE_DELETE_SECRETS", + "ACTIVITY_TYPE_EARN_CLAIM_REWARDS", + "ACTIVITY_TYPE_CREATE_SWAP_QUOTE_V3", + "ACTIVITY_TYPE_UPSERT_SWAP_FEE_SPONSORSHIP_LIMIT_CONFIG", + "ACTIVITY_TYPE_UPSERT_SWAP_FIXED_RATE_LIMIT_CONFIG" + ] + }, + "v1AddressFormat": { + "type": "string", + "enum": [ + "ADDRESS_FORMAT_UNCOMPRESSED", + "ADDRESS_FORMAT_COMPRESSED", + "ADDRESS_FORMAT_ETHEREUM", + "ADDRESS_FORMAT_SOLANA", + "ADDRESS_FORMAT_COSMOS", + "ADDRESS_FORMAT_TRON", + "ADDRESS_FORMAT_SUI", + "ADDRESS_FORMAT_APTOS", + "ADDRESS_FORMAT_BITCOIN_MAINNET_P2PKH", + "ADDRESS_FORMAT_BITCOIN_MAINNET_P2SH", + "ADDRESS_FORMAT_BITCOIN_MAINNET_P2WPKH", + "ADDRESS_FORMAT_BITCOIN_MAINNET_P2WSH", + "ADDRESS_FORMAT_BITCOIN_MAINNET_P2TR", + "ADDRESS_FORMAT_BITCOIN_TESTNET_P2PKH", + "ADDRESS_FORMAT_BITCOIN_TESTNET_P2SH", + "ADDRESS_FORMAT_BITCOIN_TESTNET_P2WPKH", + "ADDRESS_FORMAT_BITCOIN_TESTNET_P2WSH", + "ADDRESS_FORMAT_BITCOIN_TESTNET_P2TR", + "ADDRESS_FORMAT_BITCOIN_SIGNET_P2PKH", + "ADDRESS_FORMAT_BITCOIN_SIGNET_P2SH", + "ADDRESS_FORMAT_BITCOIN_SIGNET_P2WPKH", + "ADDRESS_FORMAT_BITCOIN_SIGNET_P2WSH", + "ADDRESS_FORMAT_BITCOIN_SIGNET_P2TR", + "ADDRESS_FORMAT_BITCOIN_REGTEST_P2PKH", + "ADDRESS_FORMAT_BITCOIN_REGTEST_P2SH", + "ADDRESS_FORMAT_BITCOIN_REGTEST_P2WPKH", + "ADDRESS_FORMAT_BITCOIN_REGTEST_P2WSH", + "ADDRESS_FORMAT_BITCOIN_REGTEST_P2TR", + "ADDRESS_FORMAT_SEI", + "ADDRESS_FORMAT_XLM", + "ADDRESS_FORMAT_DOGE_MAINNET", + "ADDRESS_FORMAT_DOGE_TESTNET", + "ADDRESS_FORMAT_TON_V3R2", + "ADDRESS_FORMAT_TON_V4R2", + "ADDRESS_FORMAT_TON_V5R1", + "ADDRESS_FORMAT_XRP", + "ADDRESS_FORMAT_SPARK_MAINNET", + "ADDRESS_FORMAT_SPARK_REGTEST" + ] + }, + "v1ApiKey": { + "type": "object", + "properties": { + "credential": { + "$ref": "#/definitions/externaldatav1Credential", + "description": "A User credential that can be used to authenticate to Turnkey." + }, + "apiKeyId": { + "type": "string", + "description": "Unique identifier for a given API Key." + }, + "apiKeyName": { + "type": "string", + "description": "Human-readable name for an API Key." + }, + "createdAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "updatedAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "expirationSeconds": { + "type": "string", + "format": "uint64", + "description": "Optional window (in seconds) indicating how long the API Key should last." + } + }, + "required": [ + "credential", + "apiKeyId", + "apiKeyName", + "createdAt", + "updatedAt" + ] + }, + "v1ApiKeyCurve": { + "type": "string", + "enum": [ + "API_KEY_CURVE_P256", + "API_KEY_CURVE_SECP256K1", + "API_KEY_CURVE_ED25519" + ] + }, + "v1ApiKeyParamsV2": { + "type": "object", + "properties": { + "apiKeyName": { + "type": "string", + "description": "Human-readable name for an API Key." + }, + "publicKey": { + "type": "string", + "description": "The public component of a cryptographic key pair used to sign messages and transactions." + }, + "curveType": { + "$ref": "#/definitions/v1ApiKeyCurve", + "description": "The curve type to be used for processing API key signatures." + }, + "expirationSeconds": { + "type": "string", + "description": "Optional window (in seconds) indicating how long the API Key should last." + } + }, + "required": ["apiKeyName", "publicKey", "curveType"] + }, + "v1ApiOnlyUserParams": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "The name of the new API-only User." + }, + "userEmail": { + "type": "string", + "description": "The email address for this API-only User (optional)." + }, + "userTags": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of tags assigned to the new API-only User. This field, if not needed, should be an empty array in your request body." + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/apiApiKeyParams" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + } + }, + "required": ["userName", "userTags", "apiKeys"] + }, + "v1AppProof": { + "type": "object", + "properties": { + "scheme": { + "$ref": "#/definitions/externaldatav1SignatureScheme", + "description": "Scheme of signing key." + }, + "publicKey": { + "type": "string", + "description": "Ephemeral public key." + }, + "proofPayload": { + "type": "string", + "description": "JSON serialized AppProofPayload." + }, + "signature": { + "type": "string", + "description": "Signature over hashed proof_payload." + } + }, + "required": ["scheme", "publicKey", "proofPayload", "signature"] + }, + "v1ApproveActivityIntent": { + "type": "object", + "properties": { + "fingerprint": { + "type": "string", + "description": "An artifact verifying a User's action." + } + }, + "required": ["fingerprint"] + }, + "v1Attestation": { + "type": "object", + "properties": { + "credentialId": { + "type": "string", + "description": "The cbor encoded then base64 url encoded id of the credential." + }, + "clientDataJson": { + "type": "string", + "description": "A base64 url encoded payload containing metadata about the signing context and the challenge." + }, + "attestationObject": { + "type": "string", + "description": "A base64 url encoded payload containing authenticator data and any attestation the webauthn provider chooses." + }, + "transports": { + "type": "array", + "items": { + "$ref": "#/definitions/v1AuthenticatorTransport" + }, + "description": "The type of authenticator transports." + } + }, + "required": [ + "credentialId", + "clientDataJson", + "attestationObject", + "transports" + ] + }, + "v1AuthenticationMethod": { + "type": "object", + "properties": { + "type": { + "$ref": "#/definitions/v1AuthenticationType", + "description": "The type of authenticator (e.g., AUTHENTICATION_TYPE_EMAIL, AUTHENTICATION_TYPE_SESSION) required for this MFA step." + }, + "id": { + "type": "string", + "description": "Optional specific authenticator ID required (e.g., for requiring a specific session profile id)" + } + }, + "required": ["type"] + }, + "v1AuthenticationMethodParams": { + "type": "object", + "properties": { + "type": { + "$ref": "#/definitions/v1AuthenticationType", + "description": "The type of authenticator (e.g., AUTHENTICATION_TYPE_PASSKEY for passkey authentication)." + }, + "id": { + "type": "string", + "description": "Optional specific authenticator ID required (e.g., UUID of a passkey authenticator). If not provided, any authenticator of the specified type can be used." + } + }, + "required": ["type"] + }, + "v1AuthenticationType": { + "type": "string", + "enum": [ + "AUTHENTICATION_TYPE_EMAIL_OTP", + "AUTHENTICATION_TYPE_SMS_OTP", + "AUTHENTICATION_TYPE_PASSKEY", + "AUTHENTICATION_TYPE_API_KEY", + "AUTHENTICATION_TYPE_OAUTH", + "AUTHENTICATION_TYPE_SESSION" + ] + }, + "v1Authenticator": { + "type": "object", + "properties": { + "transports": { + "type": "array", + "items": { + "$ref": "#/definitions/v1AuthenticatorTransport" + }, + "description": "Types of transports that may be used by an Authenticator (e.g., USB, NFC, BLE)." + }, + "attestationType": { + "type": "string" + }, + "aaguid": { + "type": "string", + "description": "Identifier indicating the type of the Security Key." + }, + "credentialId": { + "type": "string", + "description": "Unique identifier for a WebAuthn credential." + }, + "model": { + "type": "string", + "description": "The type of Authenticator device." + }, + "credential": { + "$ref": "#/definitions/externaldatav1Credential", + "description": "A User credential that can be used to authenticate to Turnkey." + }, + "authenticatorId": { + "type": "string", + "description": "Unique identifier for a given Authenticator." + }, + "authenticatorName": { + "type": "string", + "description": "Human-readable name for an Authenticator." + }, + "createdAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "updatedAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + } + }, + "required": [ + "transports", + "attestationType", + "aaguid", + "credentialId", + "model", + "credential", + "authenticatorId", + "authenticatorName", + "createdAt", + "updatedAt" + ] + }, + "v1AuthenticatorAttestationResponse": { + "type": "object", + "properties": { + "clientDataJson": { + "type": "string" + }, + "attestationObject": { + "type": "string" + }, + "transports": { + "type": "array", + "items": { + "$ref": "#/definitions/v1AuthenticatorTransport" + } + }, + "authenticatorAttachment": { + "type": "string", + "enum": ["cross-platform", "platform"], + "x-nullable": true + } + }, + "required": ["clientDataJson", "attestationObject"] + }, + "v1AuthenticatorParams": { + "type": "object", + "properties": { + "authenticatorName": { + "type": "string", + "description": "Human-readable name for an Authenticator." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "attestation": { + "$ref": "#/definitions/v1PublicKeyCredentialWithAttestation" + }, + "challenge": { + "type": "string", + "description": "Challenge presented for authentication purposes." + } + }, + "required": ["authenticatorName", "userId", "attestation", "challenge"] + }, + "v1AuthenticatorParamsV2": { + "type": "object", + "properties": { + "authenticatorName": { + "type": "string", + "description": "Human-readable name for an Authenticator." + }, + "challenge": { + "type": "string", + "description": "Challenge presented for authentication purposes." + }, + "attestation": { + "$ref": "#/definitions/v1Attestation", + "description": "The attestation that proves custody of the authenticator and provides metadata about it." + } + }, + "required": ["authenticatorName", "challenge", "attestation"] + }, + "v1AuthenticatorTransport": { + "type": "string", + "enum": [ + "AUTHENTICATOR_TRANSPORT_BLE", + "AUTHENTICATOR_TRANSPORT_INTERNAL", + "AUTHENTICATOR_TRANSPORT_NFC", + "AUTHENTICATOR_TRANSPORT_USB", + "AUTHENTICATOR_TRANSPORT_HYBRID" + ] + }, + "v1ClaimEarnFeesIntent": { + "type": "object", + "properties": { + "wrapperAddress": { + "type": "string", + "description": "Address of the deployed Earn wrapper to claim fees for. Must be one of the org's deployed wrappers." + } + }, + "required": ["wrapperAddress"] + }, + "v1ClaimEarnFeesResult": { + "type": "object", + "properties": { + "claimRequestId": { + "type": "string", + "description": "Identifier to poll claim status and tx hash via GetClaimEarnFeesStatus." + } + }, + "required": ["claimRequestId"] + }, + "v1ClaimSwapFeesIntent": { + "type": "object" + }, + "v1ClaimSwapFeesResult": { + "type": "object", + "properties": { + "requestId": { + "type": "string", + "description": "Relay claim request ID submitted through the permit endpoint." + } + }, + "required": ["requestId"] + }, + "v1ClientSignature": { + "type": "object", + "properties": { + "publicKey": { + "type": "string", + "description": "The public component of a cryptographic key pair used to create the signature." + }, + "scheme": { + "$ref": "#/definitions/v1ClientSignatureScheme", + "description": "The signature scheme used to generate the client signature." + }, + "message": { + "type": "string", + "description": "The message that was signed." + }, + "signature": { + "type": "string", + "description": "The cryptographic signature over the message." + } + }, + "required": ["publicKey", "scheme", "message", "signature"] + }, + "v1ClientSignatureScheme": { + "type": "string", + "enum": ["CLIENT_SIGNATURE_SCHEME_API_P256"] + }, + "v1CreateApiKeysIntent": { + "type": "object", + "properties": { + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/apiApiKeyParams" + }, + "description": "A list of API Keys." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + } + }, + "required": ["apiKeys", "userId"] + }, + "v1CreateApiKeysIntentV2": { + "type": "object", + "properties": { + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ApiKeyParamsV2" + }, + "description": "A list of API Keys." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + } + }, + "required": ["apiKeys", "userId"] + }, + "v1CreateApiKeysResult": { + "type": "object", + "properties": { + "apiKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of API Key IDs." + } + }, + "required": ["apiKeyIds"] + }, + "v1CreateApiOnlyUsersIntent": { + "type": "object", + "properties": { + "apiOnlyUsers": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ApiOnlyUserParams" + }, + "description": "A list of API-only Users to create." + } + }, + "required": ["apiOnlyUsers"] + }, + "v1CreateApiOnlyUsersResult": { + "type": "object", + "properties": { + "userIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of API-only User IDs." + } + }, + "required": ["userIds"] + }, + "v1CreateAuthenticatorsIntent": { + "type": "object", + "properties": { + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParams" + }, + "description": "A list of Authenticators." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + } + }, + "required": ["authenticators", "userId"] + }, + "v1CreateAuthenticatorsIntentV2": { + "type": "object", + "properties": { + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParamsV2" + }, + "description": "A list of Authenticators." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + } + }, + "required": ["authenticators", "userId"] + }, + "v1CreateAuthenticatorsResult": { + "type": "object", + "properties": { + "authenticatorIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Authenticator IDs." + } + }, + "required": ["authenticatorIds"] + }, + "v1CreateFiatOnRampCredentialIntent": { + "type": "object", + "properties": { + "onrampProvider": { + "$ref": "#/definitions/v1FiatOnRampProvider", + "description": "The fiat on-ramp provider" + }, + "projectId": { + "type": "string", + "description": "Project ID for the on-ramp provider. Some providers, like Coinbase, require this additional identifier" + }, + "publishableApiKey": { + "type": "string", + "description": "Publishable API key for the on-ramp provider" + }, + "encryptedSecretApiKey": { + "type": "string", + "description": "Secret API key for the on-ramp provider encrypted to our on-ramp encryption public key" + }, + "encryptedPrivateApiKey": { + "type": "string", + "description": "Private API key for the on-ramp provider encrypted to our on-ramp encryption public key. Some providers, like Coinbase, require this additional key." + }, + "sandboxMode": { + "type": "boolean", + "description": "If the on-ramp credential is a sandbox credential" + } + }, + "required": [ + "onrampProvider", + "publishableApiKey", + "encryptedSecretApiKey" + ] + }, + "v1CreateFiatOnRampCredentialResult": { + "type": "object", + "properties": { + "fiatOnRampCredentialId": { + "type": "string", + "description": "Unique identifier of the Fiat On-Ramp credential that was created" + } + }, + "required": ["fiatOnRampCredentialId"] + }, + "v1CreateInvitationsIntent": { + "type": "object", + "properties": { + "invitations": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1InvitationParams" + }, + "description": "A list of Invitations." + } + }, + "required": ["invitations"] + }, + "v1CreateInvitationsResult": { + "type": "object", + "properties": { + "invitationIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Invitation IDs" + } + }, + "required": ["invitationIds"] + }, + "v1CreateMfaPolicyIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User to add the MFA Policy to." + }, + "mfaPolicyName": { + "type": "string", + "description": "Human-readable name for a Policy." + }, + "condition": { + "type": "string", + "description": "A condition expression that evaluates to true or false, determining when this MFA policy applies." + }, + "requiredAuthenticationMethods": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RequiredAuthenticationMethodParams" + }, + "description": "An ordered list of authentication requirements. Each requirement must be satisfied sequentially to complete MFA." + }, + "order": { + "type": "integer", + "format": "int64", + "description": "The order in which this MFA policy is evaluated, starting from 0, relative to other MFA policies. Lower order values are evaluated first." + }, + "notes": { + "type": "string", + "description": "Notes for an MFA Policy." + } + }, + "required": [ + "userId", + "mfaPolicyName", + "condition", + "requiredAuthenticationMethods", + "order" + ] + }, + "v1CreateMfaPolicyResult": { + "type": "object", + "properties": { + "mfaPolicyId": { + "type": "string", + "description": "Unique identifier for a given MFA Policy." + } + }, + "required": ["mfaPolicyId"] + }, + "v1CreateOauth2CredentialIntent": { + "type": "object", + "properties": { + "provider": { + "$ref": "#/definitions/v1Oauth2Provider", + "description": "The OAuth 2.0 provider" + }, + "clientId": { + "type": "string", + "description": "The Client ID issued by the OAuth 2.0 provider" + }, + "encryptedClientSecret": { + "type": "string", + "description": "The client secret issued by the OAuth 2.0 provider encrypted to the TLS Fetcher quorum key" + } + }, + "required": ["provider", "clientId", "encryptedClientSecret"] + }, + "v1CreateOauth2CredentialResult": { + "type": "object", + "properties": { + "oauth2CredentialId": { + "type": "string", + "description": "Unique identifier of the OAuth 2.0 credential that was created" + } + }, + "required": ["oauth2CredentialId"] + }, + "v1CreateOauthProvidersIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User to add an Oauth provider to" + }, + "oauthProviders": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1OauthProviderParams" + }, + "description": "A list of Oauth providers." + } + }, + "required": ["userId", "oauthProviders"] + }, + "v1CreateOauthProvidersIntentV2": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User to add an Oauth provider to" + }, + "oauthProviders": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1OauthProviderParamsV2" + }, + "description": "A list of Oauth providers." + } + }, + "required": ["userId", "oauthProviders"] + }, + "v1CreateOauthProvidersResult": { + "type": "object", + "properties": { + "providerIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of unique identifiers for Oauth Providers" + } + }, + "required": ["providerIds"] + }, + "v1CreateOauthProvidersResultV2": { + "type": "object", + "properties": { + "providerIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of unique identifiers for Oauth Providers" + } + }, + "required": ["providerIds"] + }, + "v1CreateOrganizationIntent": { + "type": "object", + "properties": { + "organizationName": { + "type": "string", + "description": "Human-readable name for an Organization." + }, + "rootEmail": { + "type": "string", + "description": "The root user's email address." + }, + "rootAuthenticator": { + "$ref": "#/definitions/v1AuthenticatorParams", + "description": "The root user's Authenticator." + }, + "rootUserId": { + "type": "string", + "description": "Unique identifier for the root user object." + } + }, + "required": ["organizationName", "rootEmail", "rootAuthenticator"] + }, + "v1CreateOrganizationIntentV2": { + "type": "object", + "properties": { + "organizationName": { + "type": "string", + "description": "Human-readable name for an Organization." + }, + "rootEmail": { + "type": "string", + "description": "The root user's email address." + }, + "rootAuthenticator": { + "$ref": "#/definitions/v1AuthenticatorParamsV2", + "description": "The root user's Authenticator." + }, + "rootUserId": { + "type": "string", + "description": "Unique identifier for the root user object." + } + }, + "required": ["organizationName", "rootEmail", "rootAuthenticator"] + }, + "v1CreateOrganizationResult": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + } + }, + "required": ["organizationId"] + }, + "v1CreatePoliciesIntent": { + "type": "object", + "properties": { + "policies": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1CreatePolicyIntentV3" + }, + "description": "An array of policy intents to be created." + } + }, + "required": ["policies"] + }, + "v1CreatePoliciesResult": { + "type": "object", + "properties": { + "policyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of unique identifiers for the created policies." + } + }, + "required": ["policyIds"] + }, + "v1CreatePolicyIntent": { + "type": "object", + "properties": { + "policyName": { + "type": "string", + "description": "Human-readable name for a Policy." + }, + "selectors": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1Selector" + }, + "description": "A list of simple functions each including a subject, target and boolean. See Policy Engine Language section for additional details." + }, + "effect": { + "$ref": "#/definitions/v1Effect", + "description": "The instruction to DENY or ALLOW a particular activity following policy selector(s)." + }, + "notes": { + "type": "string" + } + }, + "required": ["policyName", "selectors", "effect"] + }, + "v1CreatePolicyIntentV2": { + "type": "object", + "properties": { + "policyName": { + "type": "string", + "description": "Human-readable name for a Policy." + }, + "selectors": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SelectorV2" + }, + "description": "A list of simple functions each including a subject, target and boolean. See Policy Engine Language section for additional details." + }, + "effect": { + "$ref": "#/definitions/v1Effect", + "description": "Whether to ALLOW or DENY requests that match the condition and consensus requirements." + }, + "notes": { + "type": "string" + } + }, + "required": ["policyName", "selectors", "effect"] + }, + "v1CreatePolicyIntentV3": { + "type": "object", + "properties": { + "policyName": { + "type": "string", + "description": "Human-readable name for a Policy." + }, + "effect": { + "$ref": "#/definitions/v1Effect", + "description": "The instruction to DENY or ALLOW an activity." + }, + "condition": { + "type": "string", + "description": "The condition expression that triggers the Effect" + }, + "consensus": { + "type": "string", + "description": "The consensus expression that triggers the Effect" + }, + "notes": { + "type": "string", + "description": "Notes for a Policy." + }, + "time": { + "type": "string", + "description": "The time expression that triggers the Effect" + } + }, + "required": ["policyName", "effect", "notes"] + }, + "v1CreatePolicyResult": { + "type": "object", + "properties": { + "policyId": { + "type": "string", + "description": "Unique identifier for a given Policy." + } + }, + "required": ["policyId"] + }, + "v1CreatePrivateKeyTagIntent": { + "type": "object", + "properties": { + "privateKeyTagName": { + "type": "string", + "description": "Human-readable name for a Private Key Tag." + }, + "privateKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Private Key IDs." + } + }, + "required": ["privateKeyTagName", "privateKeyIds"] + }, + "v1CreatePrivateKeyTagResult": { + "type": "object", + "properties": { + "privateKeyTagId": { + "type": "string", + "description": "Unique identifier for a given Private Key Tag." + }, + "privateKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Private Key IDs." + } + }, + "required": ["privateKeyTagId", "privateKeyIds"] + }, + "v1CreatePrivateKeysIntent": { + "type": "object", + "properties": { + "privateKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1PrivateKeyParams" + }, + "description": "A list of Private Keys." + } + }, + "required": ["privateKeys"] + }, + "v1CreatePrivateKeysIntentV2": { + "type": "object", + "properties": { + "privateKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1PrivateKeyParams" + }, + "description": "A list of Private Keys." + } + }, + "required": ["privateKeys"] + }, + "v1CreatePrivateKeysResult": { + "type": "object", + "properties": { + "privateKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Private Key IDs." + } + }, + "required": ["privateKeyIds"] + }, + "v1CreatePrivateKeysResultV2": { + "type": "object", + "properties": { + "privateKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1PrivateKeyResult" + }, + "description": "A list of Private Key IDs and addresses." + } + }, + "required": ["privateKeys"] + }, + "v1CreateReadOnlySessionIntent": { + "type": "object" + }, + "v1CreateReadOnlySessionResult": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization. If the request is being made by a user and their Sub-Organization ID is unknown, this can be the Parent Organization ID. However, using the Sub-Organization ID is preferred due to performance reasons." + }, + "organizationName": { + "type": "string", + "description": "Human-readable name for an Organization." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "username": { + "type": "string", + "description": "Human-readable name for a User." + }, + "session": { + "type": "string", + "description": "String representing a read only session" + }, + "sessionExpiry": { + "type": "string", + "format": "uint64", + "description": "UTC timestamp in seconds representing the expiry time for the read only session." + } + }, + "required": [ + "organizationId", + "organizationName", + "userId", + "username", + "session", + "sessionExpiry" + ] + }, + "v1CreateReadWriteSessionIntent": { + "type": "object", + "properties": { + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the read write session bundle (credentials) will be encrypted." + }, + "email": { + "type": "string", + "description": "Email of the user to create a read write session for" + }, + "apiKeyName": { + "type": "string", + "description": "Optional human-readable name for an API Key. If none provided, default to Read Write Session - \u003cTimestamp\u003e" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the API key is valid for. If not provided, a default of 15 minutes will be used." + } + }, + "required": ["targetPublicKey", "email"] + }, + "v1CreateReadWriteSessionIntentV2": { + "type": "object", + "properties": { + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the read write session bundle (credentials) will be encrypted." + }, + "userId": { + "type": "string", + "description": "Optional unique identifier for a given User. If none provided, the read write session will be created for the user who is making the request." + }, + "apiKeyName": { + "type": "string", + "description": "Optional human-readable name for an API Key. If none provided, default to Read Write Session - \u003cTimestamp\u003e" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the API key is valid for. If not provided, a default of 15 minutes will be used." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated ReadWriteSession API keys" + } + }, + "required": ["targetPublicKey"] + }, + "v1CreateReadWriteSessionResult": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization. If the request is being made by a user and their Sub-Organization ID is unknown, this can be the Parent Organization ID. However, using the Sub-Organization ID is preferred due to performance reasons." + }, + "organizationName": { + "type": "string", + "description": "Human-readable name for an Organization." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "username": { + "type": "string", + "description": "Human-readable name for a User." + }, + "apiKeyId": { + "type": "string", + "description": "Unique identifier for the created API key." + }, + "credentialBundle": { + "type": "string", + "description": "HPKE encrypted credential bundle" + } + }, + "required": [ + "organizationId", + "organizationName", + "userId", + "username", + "apiKeyId", + "credentialBundle" + ] + }, + "v1CreateReadWriteSessionResultV2": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization. If the request is being made by a user and their Sub-Organization ID is unknown, this can be the Parent Organization ID. However, using the Sub-Organization ID is preferred due to performance reasons." + }, + "organizationName": { + "type": "string", + "description": "Human-readable name for an Organization." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "username": { + "type": "string", + "description": "Human-readable name for a User." + }, + "apiKeyId": { + "type": "string", + "description": "Unique identifier for the created API key." + }, + "credentialBundle": { + "type": "string", + "description": "HPKE encrypted credential bundle" + } + }, + "required": [ + "organizationId", + "organizationName", + "userId", + "username", + "apiKeyId", + "credentialBundle" + ] + }, + "v1CreateSessionProfileIntent": { + "type": "object", + "properties": { + "sessionProfileName": { + "type": "string", + "description": "Human-readable name for a Session Profile." + }, + "scope": { + "type": "string", + "description": "The scope string that defines the permissions for this Session Profile." + }, + "expirationSeconds": { + "type": "string", + "description": "The duration in seconds for which sessions created with this Session Profile are valid. If not set, expiration will be determined by the value passed in to the intent of login activities." + }, + "notes": { + "type": "string", + "description": "Notes for a Session Profile." + } + }, + "required": ["sessionProfileName", "scope"] + }, + "v1CreateSessionProfileResult": { + "type": "object", + "properties": { + "sessionProfileId": { + "type": "string", + "description": "Unique identifier for a given Session Profile." + } + }, + "required": ["sessionProfileId"] + }, + "v1CreateSmartContractInterfaceIntent": { + "type": "object", + "properties": { + "smartContractAddress": { + "type": "string", + "description": "Corresponding contract address or program ID" + }, + "smartContractInterface": { + "type": "string", + "description": "ABI/IDL as a JSON string. Limited to 400kb" + }, + "type": { + "$ref": "#/definitions/v1SmartContractInterfaceType" + }, + "label": { + "type": "string", + "description": "Human-readable name for a Smart Contract Interface." + }, + "notes": { + "type": "string", + "description": "Notes for a Smart Contract Interface." + } + }, + "required": [ + "smartContractAddress", + "smartContractInterface", + "type", + "label" + ] + }, + "v1CreateSmartContractInterfaceResult": { + "type": "object", + "properties": { + "smartContractInterfaceId": { + "type": "string", + "description": "The ID of the created Smart Contract Interface." + } + }, + "required": ["smartContractInterfaceId"] + }, + "v1CreateSubOrganizationIntent": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "Name for this sub-organization" + }, + "rootAuthenticator": { + "$ref": "#/definitions/v1AuthenticatorParamsV2", + "description": "Root User authenticator for this new sub-organization" + } + }, + "required": ["name", "rootAuthenticator"] + }, + "v1CreateSubOrganizationIntentV2": { + "type": "object", + "properties": { + "subOrganizationName": { + "type": "string", + "description": "Name for this sub-organization" + }, + "rootUsers": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RootUserParams" + }, + "description": "Root users to create within this sub-organization" + }, + "rootQuorumThreshold": { + "type": "integer", + "format": "int32", + "description": "The threshold of unique approvals to reach root quorum. This value must be less than or equal to the number of root users" + } + }, + "required": ["subOrganizationName", "rootUsers", "rootQuorumThreshold"] + }, + "v1CreateSubOrganizationIntentV3": { + "type": "object", + "properties": { + "subOrganizationName": { + "type": "string", + "description": "Name for this sub-organization" + }, + "rootUsers": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RootUserParams" + }, + "description": "Root users to create within this sub-organization" + }, + "rootQuorumThreshold": { + "type": "integer", + "format": "int32", + "description": "The threshold of unique approvals to reach root quorum. This value must be less than or equal to the number of root users" + }, + "privateKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1PrivateKeyParams" + }, + "description": "A list of Private Keys." + } + }, + "required": [ + "subOrganizationName", + "rootUsers", + "rootQuorumThreshold", + "privateKeys" + ] + }, + "v1CreateSubOrganizationIntentV4": { + "type": "object", + "properties": { + "subOrganizationName": { + "type": "string", + "description": "Name for this sub-organization" + }, + "rootUsers": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RootUserParams" + }, + "description": "Root users to create within this sub-organization" + }, + "rootQuorumThreshold": { + "type": "integer", + "format": "int32", + "description": "The threshold of unique approvals to reach root quorum. This value must be less than or equal to the number of root users" + }, + "wallet": { + "$ref": "#/definitions/v1WalletParams", + "description": "The wallet to create for the sub-organization" + }, + "disableEmailRecovery": { + "type": "boolean", + "description": "Disable email recovery for the sub-organization" + }, + "disableEmailAuth": { + "type": "boolean", + "description": "Disable email auth for the sub-organization" + } + }, + "required": ["subOrganizationName", "rootUsers", "rootQuorumThreshold"] + }, + "v1CreateSubOrganizationIntentV5": { + "type": "object", + "properties": { + "subOrganizationName": { + "type": "string", + "description": "Name for this sub-organization" + }, + "rootUsers": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RootUserParamsV2" + }, + "description": "Root users to create within this sub-organization" + }, + "rootQuorumThreshold": { + "type": "integer", + "format": "int32", + "description": "The threshold of unique approvals to reach root quorum. This value must be less than or equal to the number of root users" + }, + "wallet": { + "$ref": "#/definitions/v1WalletParams", + "description": "The wallet to create for the sub-organization" + }, + "disableEmailRecovery": { + "type": "boolean", + "description": "Disable email recovery for the sub-organization" + }, + "disableEmailAuth": { + "type": "boolean", + "description": "Disable email auth for the sub-organization" + } + }, + "required": ["subOrganizationName", "rootUsers", "rootQuorumThreshold"] + }, + "v1CreateSubOrganizationIntentV6": { + "type": "object", + "properties": { + "subOrganizationName": { + "type": "string", + "description": "Name for this sub-organization" + }, + "rootUsers": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RootUserParamsV3" + }, + "description": "Root users to create within this sub-organization" + }, + "rootQuorumThreshold": { + "type": "integer", + "format": "int32", + "description": "The threshold of unique approvals to reach root quorum. This value must be less than or equal to the number of root users" + }, + "wallet": { + "$ref": "#/definitions/v1WalletParams", + "description": "The wallet to create for the sub-organization" + }, + "disableEmailRecovery": { + "type": "boolean", + "description": "Disable email recovery for the sub-organization" + }, + "disableEmailAuth": { + "type": "boolean", + "description": "Disable email auth for the sub-organization" + } + }, + "required": ["subOrganizationName", "rootUsers", "rootQuorumThreshold"] + }, + "v1CreateSubOrganizationIntentV7": { + "type": "object", + "properties": { + "subOrganizationName": { + "type": "string", + "description": "Name for this sub-organization" + }, + "rootUsers": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RootUserParamsV4" + }, + "description": "Root users to create within this sub-organization" + }, + "rootQuorumThreshold": { + "type": "integer", + "format": "int32", + "description": "The threshold of unique approvals to reach root quorum. This value must be less than or equal to the number of root users" + }, + "wallet": { + "$ref": "#/definitions/v1WalletParams", + "description": "The wallet to create for the sub-organization" + }, + "disableEmailRecovery": { + "type": "boolean", + "description": "Disable email recovery for the sub-organization" + }, + "disableEmailAuth": { + "type": "boolean", + "description": "Disable email auth for the sub-organization" + }, + "disableSmsAuth": { + "type": "boolean", + "description": "Disable OTP SMS auth for the sub-organization" + }, + "disableOtpEmailAuth": { + "type": "boolean", + "description": "Disable OTP email auth for the sub-organization" + }, + "verificationToken": { + "type": "string", + "description": "Signed JWT containing a unique id, expiry, verification type, contact" + }, + "clientSignature": { + "$ref": "#/definitions/v1ClientSignature", + "description": "Optional signature proving authorization for this sub-organization creation. The signature is over the verification token ID and the root user parameters for the root user associated with the verification token. Only required if a public key was provided during the verification step." + } + }, + "required": ["subOrganizationName", "rootUsers", "rootQuorumThreshold"] + }, + "v1CreateSubOrganizationIntentV8": { + "type": "object", + "properties": { + "subOrganizationName": { + "type": "string", + "description": "Name for this sub-organization" + }, + "rootUsers": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RootUserParamsV5" + }, + "description": "Root users to create within this sub-organization" + }, + "rootQuorumThreshold": { + "type": "integer", + "format": "int32", + "description": "The threshold of unique approvals to reach root quorum. This value must be less than or equal to the number of root users" + }, + "wallet": { + "$ref": "#/definitions/v1WalletParams", + "description": "The wallet to create for the sub-organization" + }, + "disableEmailRecovery": { + "type": "boolean", + "description": "Disable email recovery for the sub-organization" + }, + "disableEmailAuth": { + "type": "boolean", + "description": "Disable email auth for the sub-organization" + }, + "disableSmsAuth": { + "type": "boolean", + "description": "Disable OTP SMS auth for the sub-organization" + }, + "disableOtpEmailAuth": { + "type": "boolean", + "description": "Disable OTP email auth for the sub-organization" + }, + "verificationToken": { + "type": "string", + "description": "Signed JWT containing a unique id, expiry, verification type, contact" + }, + "clientSignature": { + "$ref": "#/definitions/v1ClientSignature", + "description": "Optional signature proving authorization for this sub-organization creation. The signature is over the verification token ID and the root user parameters for the root user associated with the verification token. Only required if a public key was provided during the verification step." + } + }, + "required": ["subOrganizationName", "rootUsers", "rootQuorumThreshold"] + }, + "v1CreateSubOrganizationResult": { + "type": "object", + "properties": { + "subOrganizationId": { + "type": "string" + }, + "rootUserIds": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": ["subOrganizationId"] + }, + "v1CreateSubOrganizationResultV3": { + "type": "object", + "properties": { + "subOrganizationId": { + "type": "string" + }, + "privateKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1PrivateKeyResult" + }, + "description": "A list of Private Key IDs and addresses." + }, + "rootUserIds": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": ["subOrganizationId", "privateKeys"] + }, + "v1CreateSubOrganizationResultV4": { + "type": "object", + "properties": { + "subOrganizationId": { + "type": "string" + }, + "wallet": { + "$ref": "#/definitions/v1WalletResult" + }, + "rootUserIds": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": ["subOrganizationId"] + }, + "v1CreateSubOrganizationResultV5": { + "type": "object", + "properties": { + "subOrganizationId": { + "type": "string" + }, + "wallet": { + "$ref": "#/definitions/v1WalletResult" + }, + "rootUserIds": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": ["subOrganizationId"] + }, + "v1CreateSubOrganizationResultV6": { + "type": "object", + "properties": { + "subOrganizationId": { + "type": "string" + }, + "wallet": { + "$ref": "#/definitions/v1WalletResult" + }, + "rootUserIds": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": ["subOrganizationId"] + }, + "v1CreateSubOrganizationResultV7": { + "type": "object", + "properties": { + "subOrganizationId": { + "type": "string" + }, + "wallet": { + "$ref": "#/definitions/v1WalletResult" + }, + "rootUserIds": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": ["subOrganizationId"] + }, + "v1CreateSubOrganizationResultV8": { + "type": "object", + "properties": { + "subOrganizationId": { + "type": "string" + }, + "wallet": { + "$ref": "#/definitions/v1WalletResult" + }, + "rootUserIds": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": ["subOrganizationId"] + }, + "v1CreateSwapQuoteIntent": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "Wallet account or Private Key address used to price the executable provider quote. Private Key identifiers are not supported." + }, + "inputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the input asset. The chain is derived from this value." + }, + "outputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the output asset." + }, + "inputAmount": { + "type": "string", + "description": "Base-unit amount of the input asset." + }, + "slippageBps": { + "type": "string", + "description": "Provider-neutral maximum allowed slippage in basis points. Turnkey converts this value to each provider's request format. When omitted, each provider applies its default slippage behavior." + } + }, + "required": ["signWith", "inputToken", "outputToken", "inputAmount"] + }, + "v1CreateSwapQuoteIntentV2": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "Wallet account address used to price the executable provider quote. Private Key identifiers are not supported." + }, + "inputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the input asset. The chain is derived from this value." + }, + "outputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the output asset." + }, + "inputAmount": { + "type": "string", + "description": "Base-unit amount of the input asset." + }, + "slippageBps": { + "type": "string", + "description": "Provider-neutral maximum allowed slippage in basis points. Turnkey converts this value to each provider's request format. When omitted, each provider applies its default slippage behavior." + }, + "destinationAddress": { + "type": "string", + "description": "Raw public address that receives the output asset. Required for cross-protocol swaps. The address must match the output token protocol. Wallet account IDs, private key IDs, and CAIP account or asset identifiers are not supported." + } + }, + "required": ["signWith", "inputToken", "outputToken", "inputAmount"] + }, + "v1CreateSwapQuoteIntentV3": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "Wallet account address used to price the executable provider quote. Private Key identifiers are not supported." + }, + "inputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the input asset. The chain is derived from this value." + }, + "outputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the output asset." + }, + "inputAmount": { + "type": "string", + "description": "Base-unit amount of the input asset." + }, + "slippageBps": { + "type": "string", + "description": "Provider-neutral maximum allowed slippage in basis points. Turnkey converts this value to each provider's request format. When omitted, each provider applies its default slippage behavior." + }, + "destinationAddress": { + "type": "string", + "description": "Raw public address that receives the output asset. Required for cross-protocol swaps. The address must match the output token protocol. Wallet account IDs, private key IDs, and CAIP account or asset identifiers are not supported." + }, + "feeSponsorship": { + "type": "boolean" + }, + "fixedRate": { + "type": "boolean" + } + }, + "required": ["signWith", "inputToken", "outputToken", "inputAmount"] + }, + "v1CreateSwapQuoteResult": { + "type": "object", + "properties": { + "quotes": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SwapQuote" + }, + "description": "One or more provider quotes for this request. Today this contains a single Relay quote; pass quotes[i].quoteId to execute_swap_v2 to bind execution." + } + }, + "required": ["quotes"] + }, + "v1CreateSwapQuoteResultV2": { + "type": "object", + "properties": { + "quotes": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SwapQuoteV2" + } + } + } + }, + "v1CreateTvcAppIntent": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "The name of the new TVC application" + }, + "quorumPublicKey": { + "type": "string", + "description": "Quorum public key to use for this application" + }, + "manifestSetId": { + "type": "string", + "description": "Unique identifier for an existing TVC operator set to use as the Manifest Set for this TVC application. If left empty, a new Manifest Set configuration is required" + }, + "manifestSetParams": { + "$ref": "#/definitions/v1TvcOperatorSetParams", + "description": "Configuration to create a new TVC operator set, used as the Manifest Set for this TVC application. If left empty, a Manifest Set ID is required" + }, + "shareSetId": { + "type": "string", + "description": "Unique identifier for an existing TVC operator set to use as the Share Set for this TVC application. If left empty, a new Share Set configuration is required" + }, + "shareSetParams": { + "$ref": "#/definitions/v1TvcOperatorSetParams", + "description": "Configuration to create a new TVC operator set, used as the Share Set for this TVC application. If left empty, a Share Set ID is required" + }, + "enableEgress": { + "type": "boolean", + "description": "Enables network egress for this TVC app. Default if not provided: false." + }, + "enableDebugModeDeployments": { + "type": "boolean", + "description": "When true, this app may create deployments in debug-mode. Debug-mode deployments expose logs and emit zero'd attestation PCRs, so remote attestation cannot succeed. Cannot be changed after app creation. Setting this true means the app's quorum key is considered permanently insecure, and a new app with a fresh quorum key must be created. Default if not provided: false." + } + }, + "required": ["name", "quorumPublicKey"] + }, + "v1CreateTvcAppResult": { + "type": "object", + "properties": { + "appId": { + "type": "string", + "description": "The unique identifier for the TVC application" + }, + "manifestSetId": { + "type": "string", + "description": "The unique identifier for the TVC manifest set" + }, + "manifestSetOperatorIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The unique identifier(s) of the manifest set operators" + }, + "manifestSetThreshold": { + "type": "integer", + "format": "int64", + "description": "The required number of approvals for the manifest set" + }, + "shareSetId": { + "type": "string", + "description": "The unique identifier for the TVC share set" + }, + "shareSetOperatorIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The unique identifiers of the share set operators" + }, + "shareSetThreshold": { + "type": "integer", + "format": "int64", + "description": "The required number of approvals for the share set" + } + }, + "required": [ + "appId", + "manifestSetId", + "manifestSetOperatorIds", + "manifestSetThreshold", + "shareSetId", + "shareSetOperatorIds", + "shareSetThreshold" + ] + }, + "v1CreateTvcDeploymentIntent": { + "type": "object", + "properties": { + "appId": { + "type": "string", + "description": "The unique identifier of the to-be-deployed TVC application" + }, + "qosVersion": { + "type": "string", + "description": "The QuorumOS version to use to deploy this application" + }, + "pivotContainerImageUrl": { + "type": "string", + "description": "URL of the container containing the pivot binary" + }, + "pivotPath": { + "type": "string", + "description": "Location of the binary in the pivot container" + }, + "pivotArgs": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Arguments to pass to the pivot binary at startup. Encoded as a list of strings, for example [\"--foo\", \"bar\"]" + }, + "expectedPivotDigest": { + "type": "string", + "description": "Digest of the pivot binary in the pivot container. This value will be inserted in the QOS manifest to ensure application integrity." + }, + "nonce": { + "type": "integer", + "format": "int64", + "description": "Optional nonce to ensure uniqueness of the deployment manifest. If not provided, it defaults to the current Unix timestamp in seconds." + }, + "pivotContainerEncryptedPullSecret": { + "type": "string", + "description": "Optional encrypted pull secret to authorize Turnkey to pull the pivot container image. If your image is public, leave this empty." + }, + "debugMode": { + "type": "boolean", + "description": "Optional flag to indicate whether to deploy the TVC app in debug mode, which includes additional logging and debugging tools. Default is false." + }, + "healthCheckType": { + "$ref": "#/definitions/v1TvcHealthCheckType", + "description": "Health check type (TVC_HEALTH_CHECK_TYPE_HTTP or TVC_HEALTH_CHECK_TYPE_GRPC). HTTP health checks are made with a GET request on /health, and gRPC health checks follow the standard gRPC health checking protocol." + }, + "healthCheckPort": { + "type": "integer", + "format": "int64", + "description": "Port to use for health checks." + }, + "publicIngressPort": { + "type": "integer", + "format": "int64", + "description": "Port to use for public ingress." + }, + "replicas": { + "type": "integer", + "format": "int64", + "description": "Optional desired replica count for this deployment." + }, + "instanceSizeCpus": { + "type": "integer", + "format": "int64", + "description": "Optional desired instance cpu count." + }, + "instanceSizeRam": { + "type": "integer", + "format": "int64", + "description": "Optional desired instance memory size in GiB." + } + }, + "required": [ + "appId", + "qosVersion", + "pivotContainerImageUrl", + "pivotPath", + "pivotArgs", + "expectedPivotDigest", + "healthCheckType", + "healthCheckPort", + "publicIngressPort" + ] + }, + "v1CreateTvcDeploymentResult": { + "type": "object", + "properties": { + "deploymentId": { + "type": "string", + "description": "The unique identifier for the TVC deployment" + }, + "manifestId": { + "type": "string", + "description": "The unique identifier for the TVC manifest" + } + }, + "required": ["deploymentId", "manifestId"] + }, + "v1CreateTvcManifestApprovalsIntent": { + "type": "object", + "properties": { + "manifestId": { + "type": "string", + "description": "Unique identifier of the TVC deployment to approve" + }, + "approvals": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1TvcManifestApproval" + }, + "description": "List of manifest approvals" + } + }, + "required": ["manifestId", "approvals"] + }, + "v1CreateTvcManifestApprovalsResult": { + "type": "object", + "properties": { + "approvalIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The unique identifier(s) for the manifest approvals" + } + }, + "required": ["approvalIds"] + }, + "v1CreateTvcOperatorIntent": { + "type": "object", + "properties": { + "walletName": { + "type": "string", + "description": "Human-readable name for a new wallet created for this TVC operator" + }, + "walletId": { + "type": "string", + "description": "Unique identifier for an existing wallet to reuse for this TVC operator" + }, + "path": { + "type": "string", + "description": "Base derivation path for creating TVC operator wallet accounts" + }, + "operatorName": { + "type": "string", + "description": "Human-readable name for this new TVC operator" + } + }, + "required": ["path", "operatorName"] + }, + "v1CreateTvcOperatorResult": { + "type": "object", + "properties": { + "walletId": { + "type": "string", + "description": "The unique identifier for the wallet containing TVC operator accounts" + }, + "operatorId": { + "type": "string", + "description": "The unique identifier for the TVC operator" + }, + "encryptPublicKey": { + "type": "string", + "description": "Public encryption key for this TVC operator" + }, + "signPublicKey": { + "type": "string", + "description": "Public signing key for this TVC operator" + } + }, + "required": [ + "walletId", + "operatorId", + "encryptPublicKey", + "signPublicKey" + ] + }, + "v1CreateTvcQuorumKeyIntent": { + "type": "object", + "properties": { + "threshold": { + "type": "integer", + "format": "int64", + "description": "The threshold of operators needed to reassemble this TVC quorum key" + }, + "operatorEncryptKeys": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Operator public keys used to encrypt and later approve the generated TVC quorum key shares" + } + }, + "required": ["threshold", "operatorEncryptKeys"] + }, + "v1CreateTvcQuorumKeyResult": { + "type": "object", + "properties": { + "quorumKeyId": { + "type": "string", + "description": "The unique identifier for the TVC quorum key" + }, + "quorumPublicKey": { + "type": "string", + "description": "Public key for the generated TVC quorum key" + }, + "shareIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The unique identifier(s) for the generated TVC quorum key shares" + } + }, + "required": ["quorumKeyId", "quorumPublicKey", "shareIds"] + }, + "v1CreateUserTagIntent": { + "type": "object", + "properties": { + "userTagName": { + "type": "string", + "description": "Human-readable name for a User Tag." + }, + "userIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User IDs." + } + }, + "required": ["userTagName", "userIds"] + }, + "v1CreateUserTagResult": { + "type": "object", + "properties": { + "userTagId": { + "type": "string", + "description": "Unique identifier for a given User Tag." + }, + "userIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User IDs." + } + }, + "required": ["userTagId", "userIds"] + }, + "v1CreateUsersIntent": { + "type": "object", + "properties": { + "users": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1UserParams" + }, + "description": "A list of Users." + } + }, + "required": ["users"] + }, + "v1CreateUsersIntentV2": { + "type": "object", + "properties": { + "users": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1UserParamsV2" + }, + "description": "A list of Users." + } + }, + "required": ["users"] + }, + "v1CreateUsersIntentV3": { + "type": "object", + "properties": { + "users": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1UserParamsV3" + }, + "description": "A list of Users." + } + }, + "required": ["users"] + }, + "v1CreateUsersIntentV4": { + "type": "object", + "properties": { + "users": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1UserParamsV4" + }, + "description": "A list of Users." + } + }, + "required": ["users"] + }, + "v1CreateUsersResult": { + "type": "object", + "properties": { + "userIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User IDs." + } + }, + "required": ["userIds"] + }, + "v1CreateVelocityControlIntent": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "Human-readable name for the Velocity Control." + }, + "dataSource": { + "$ref": "#/definitions/v1VelocityControlDataSource", + "description": "Data source for the Velocity Control." + }, + "aggregation": { + "$ref": "#/definitions/v1VelocityControlAggregation", + "description": "Aggregation expression that the Velocity Control evaluates." + }, + "identifier": { + "type": "string", + "description": "Identifier for the Velocity Control. Policies reference it as `controls.\u003cidentifier\u003e`. It must be unique within the Organization." + } + }, + "required": ["name", "dataSource", "aggregation", "identifier"] + }, + "v1CreateVelocityControlResult": { + "type": "object", + "properties": { + "velocityControlId": { + "type": "string" + } + }, + "required": ["velocityControlId"] + }, + "v1CreateWalletAccountsIntent": { + "type": "object", + "properties": { + "walletId": { + "type": "string", + "description": "Unique identifier for a given Wallet." + }, + "accounts": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1WalletAccountParams" + }, + "description": "A list of wallet Accounts." + }, + "persist": { + "type": "boolean", + "description": "Indicates if the wallet accounts should be persisted. This is helpful if you'd like to see the addresses of different derivation paths without actually creating the accounts. Defaults to true." + } + }, + "required": ["walletId", "accounts"] + }, + "v1CreateWalletAccountsResult": { + "type": "object", + "properties": { + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of derived addresses." + } + }, + "required": ["addresses"] + }, + "v1CreateWalletIntent": { + "type": "object", + "properties": { + "walletName": { + "type": "string", + "description": "Human-readable name for a Wallet." + }, + "accounts": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1WalletAccountParams" + }, + "description": "A list of wallet Accounts. This field, if not needed, should be an empty array in your request body." + }, + "mnemonicLength": { + "type": "integer", + "format": "int32", + "description": "Length of mnemonic to generate the Wallet seed. Defaults to 12. Accepted values: 12, 15, 18, 21, 24." + } + }, + "required": ["walletName", "accounts"] + }, + "v1CreateWalletResult": { + "type": "object", + "properties": { + "walletId": { + "type": "string", + "description": "Unique identifier for a Wallet." + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of account addresses." + } + }, + "required": ["walletId", "addresses"] + }, + "v1CreateWebhookEndpointIntent": { + "type": "object", + "properties": { + "url": { + "type": "string", + "description": "The destination URL for webhook delivery." + }, + "name": { + "type": "string", + "description": "Human-readable name for this webhook endpoint." + }, + "subscriptions": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1WebhookSubscriptionParams" + }, + "description": "Event subscriptions to create for this endpoint." + } + }, + "required": ["url", "name"] + }, + "v1CreateWebhookEndpointResult": { + "type": "object", + "properties": { + "endpointId": { + "type": "string", + "description": "Unique identifier of the created webhook endpoint." + }, + "webhookEndpoint": { + "$ref": "#/definitions/v1WebhookEndpointData", + "description": "The created webhook endpoint data." + } + }, + "required": ["endpointId", "webhookEndpoint"] + }, + "v1CredPropsAuthenticationExtensionsClientOutputs": { + "type": "object", + "properties": { + "rk": { + "type": "boolean" + } + }, + "required": ["rk"] + }, + "v1CredentialType": { + "type": "string", + "enum": [ + "CREDENTIAL_TYPE_WEBAUTHN_AUTHENTICATOR", + "CREDENTIAL_TYPE_API_KEY_P256", + "CREDENTIAL_TYPE_RECOVER_USER_KEY_P256", + "CREDENTIAL_TYPE_API_KEY_SECP256K1", + "CREDENTIAL_TYPE_EMAIL_AUTH_KEY_P256", + "CREDENTIAL_TYPE_API_KEY_ED25519", + "CREDENTIAL_TYPE_OTP_AUTH_KEY_P256", + "CREDENTIAL_TYPE_READ_WRITE_SESSION_KEY_P256", + "CREDENTIAL_TYPE_OAUTH_KEY_P256", + "CREDENTIAL_TYPE_LOGIN" + ] + }, + "v1Curve": { + "type": "string", + "enum": ["CURVE_SECP256K1", "CURVE_ED25519", "CURVE_P256"] + }, + "v1DeleteApiKeysIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "apiKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of API Key IDs." + } + }, + "required": ["userId", "apiKeyIds"] + }, + "v1DeleteApiKeysResult": { + "type": "object", + "properties": { + "apiKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of API Key IDs." + } + }, + "required": ["apiKeyIds"] + }, + "v1DeleteAuthenticatorsIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "authenticatorIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Authenticator IDs." + } + }, + "required": ["userId", "authenticatorIds"] + }, + "v1DeleteAuthenticatorsResult": { + "type": "object", + "properties": { + "authenticatorIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Unique identifier for a given Authenticator." + } + }, + "required": ["authenticatorIds"] + }, + "v1DeleteFiatOnRampCredentialIntent": { + "type": "object", + "properties": { + "fiatOnrampCredentialId": { + "type": "string", + "description": "The ID of the fiat on-ramp credential to delete" + } + }, + "required": ["fiatOnrampCredentialId"] + }, + "v1DeleteFiatOnRampCredentialResult": { + "type": "object", + "properties": { + "fiatOnRampCredentialId": { + "type": "string", + "description": "Unique identifier of the Fiat On-Ramp credential that was deleted" + } + }, + "required": ["fiatOnRampCredentialId"] + }, + "v1DeleteInvitationIntent": { + "type": "object", + "properties": { + "invitationId": { + "type": "string", + "description": "Unique identifier for a given Invitation object." + } + }, + "required": ["invitationId"] + }, + "v1DeleteInvitationResult": { + "type": "object", + "properties": { + "invitationId": { + "type": "string", + "description": "Unique identifier for a given Invitation." + } + }, + "required": ["invitationId"] + }, + "v1DeleteMfaPolicyIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User to delete the MFA Policy from." + }, + "mfaPolicyId": { + "type": "string", + "description": "Unique identifier for a given MFA Policy." + } + }, + "required": ["userId", "mfaPolicyId"] + }, + "v1DeleteMfaPolicyResult": { + "type": "object", + "properties": { + "mfaPolicyId": { + "type": "string", + "description": "Unique identifier for a given MFA Policy." + } + }, + "required": ["mfaPolicyId"] + }, + "v1DeleteOauth2CredentialIntent": { + "type": "object", + "properties": { + "oauth2CredentialId": { + "type": "string", + "description": "The ID of the OAuth 2.0 credential to delete" + } + }, + "required": ["oauth2CredentialId"] + }, + "v1DeleteOauth2CredentialResult": { + "type": "object", + "properties": { + "oauth2CredentialId": { + "type": "string", + "description": "Unique identifier of the OAuth 2.0 credential that was deleted" + } + }, + "required": ["oauth2CredentialId"] + }, + "v1DeleteOauthProvidersIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User to remove an Oauth provider from" + }, + "providerIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Unique identifier for a given Provider." + } + }, + "required": ["userId", "providerIds"] + }, + "v1DeleteOauthProvidersResult": { + "type": "object", + "properties": { + "providerIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of unique identifiers for Oauth Providers" + } + }, + "required": ["providerIds"] + }, + "v1DeleteOrganizationIntent": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + } + }, + "required": ["organizationId"] + }, + "v1DeleteOrganizationResult": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + } + }, + "required": ["organizationId"] + }, + "v1DeletePoliciesIntent": { + "type": "object", + "properties": { + "policyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of unique identifiers for policies within an organization" + } + }, + "required": ["policyIds"] + }, + "v1DeletePoliciesResult": { + "type": "object", + "properties": { + "policyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of unique identifiers for the deleted policies." + } + }, + "required": ["policyIds"] + }, + "v1DeletePolicyIntent": { + "type": "object", + "properties": { + "policyId": { + "type": "string", + "description": "Unique identifier for a given Policy." + } + }, + "required": ["policyId"] + }, + "v1DeletePolicyResult": { + "type": "object", + "properties": { + "policyId": { + "type": "string", + "description": "Unique identifier for a given Policy." + } + }, + "required": ["policyId"] + }, + "v1DeletePrivateKeyTagsIntent": { + "type": "object", + "properties": { + "privateKeyTagIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Private Key Tag IDs." + } + }, + "required": ["privateKeyTagIds"] + }, + "v1DeletePrivateKeyTagsResult": { + "type": "object", + "properties": { + "privateKeyTagIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Private Key Tag IDs." + }, + "privateKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Private Key IDs." + } + }, + "required": ["privateKeyTagIds", "privateKeyIds"] + }, + "v1DeletePrivateKeysIntent": { + "type": "object", + "properties": { + "privateKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of unique identifiers for private keys within an organization" + }, + "deleteWithoutExport": { + "type": "boolean", + "description": "Optional parameter for deleting the private keys, even if any have not been previously exported. If they have been exported, this field is ignored." + } + }, + "required": ["privateKeyIds"] + }, + "v1DeletePrivateKeysResult": { + "type": "object", + "properties": { + "privateKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of private key unique identifiers that were removed" + } + }, + "required": ["privateKeyIds"] + }, + "v1DeleteSecretsIntent": { + "type": "object", + "properties": { + "secretIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Unique identifiers of the secrets to delete. Must contain between 1 and 32 distinct UUIDs. All secrets must belong to the organization." + } + }, + "required": ["secretIds"] + }, + "v1DeleteSecretsResult": { + "type": "object", + "properties": { + "secretIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Unique identifiers of the deleted secrets, in the order requested." + } + }, + "required": ["secretIds"] + }, + "v1DeleteSmartContractInterfaceIntent": { + "type": "object", + "properties": { + "smartContractInterfaceId": { + "type": "string", + "description": "The ID of a Smart Contract Interface intended for deletion." + } + }, + "required": ["smartContractInterfaceId"] + }, + "v1DeleteSmartContractInterfaceResult": { + "type": "object", + "properties": { + "smartContractInterfaceId": { + "type": "string", + "description": "The ID of the deleted Smart Contract Interface." + } + }, + "required": ["smartContractInterfaceId"] + }, + "v1DeleteSubOrganizationIntent": { + "type": "object", + "properties": { + "deleteWithoutExport": { + "type": "boolean", + "description": "Sub-organization deletion, by default, requires associated wallets and private keys to be exported for security reasons. Set this boolean to true to force sub-organization deletion even if some wallets or private keys within it have not been exported yet. Default: false." + } + } + }, + "v1DeleteSubOrganizationResult": { + "type": "object", + "properties": { + "subOrganizationUuid": { + "type": "string", + "description": "Unique identifier of the sub organization that was removed" + } + }, + "required": ["subOrganizationUuid"] + }, + "v1DeleteTvcAppAndDeploymentsIntent": { + "type": "object", + "properties": { + "appId": { + "type": "string", + "description": "The unique identifier of the TVC app to delete. The app and all associated deployments will be removed." + } + }, + "required": ["appId"] + }, + "v1DeleteTvcAppAndDeploymentsResult": { + "type": "object", + "properties": { + "appId": { + "type": "string", + "description": "The unique identifier of the deleted TVC app." + } + }, + "required": ["appId"] + }, + "v1DeleteTvcDeploymentIntent": { + "type": "object", + "properties": { + "deploymentId": { + "type": "string", + "description": "The unique identifier of the TVC deployment to delete." + } + }, + "required": ["deploymentId"] + }, + "v1DeleteTvcDeploymentResult": { + "type": "object", + "properties": { + "deploymentId": { + "type": "string", + "description": "The unique identifier of the deleted TVC deployment." + } + }, + "required": ["deploymentId"] + }, + "v1DeleteUserTagsIntent": { + "type": "object", + "properties": { + "userTagIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User Tag IDs." + } + }, + "required": ["userTagIds"] + }, + "v1DeleteUserTagsResult": { + "type": "object", + "properties": { + "userTagIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User Tag IDs." + }, + "userIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User IDs." + } + }, + "required": ["userTagIds", "userIds"] + }, + "v1DeleteUsersIntent": { + "type": "object", + "properties": { + "userIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User IDs." + } + }, + "required": ["userIds"] + }, + "v1DeleteUsersResult": { + "type": "object", + "properties": { + "userIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User IDs." + } + }, + "required": ["userIds"] + }, + "v1DeleteVelocityControlsIntent": { + "type": "object", + "properties": { + "velocityControlIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of unique identifiers for Velocity Controls within an Organization." + } + }, + "required": ["velocityControlIds"] + }, + "v1DeleteVelocityControlsResult": { + "type": "object", + "properties": { + "velocityControlIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of unique identifiers for the deleted Velocity Controls." + } + }, + "required": ["velocityControlIds"] + }, + "v1DeleteWalletAccountsIntent": { + "type": "object", + "properties": { + "walletAccountIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of unique identifiers for wallet accounts within an organization" + }, + "deleteWithoutExport": { + "type": "boolean", + "description": "Optional parameter for deleting the wallet accounts, even if any have not been previously exported. If they have been exported, this field is ignored." + } + }, + "required": ["walletAccountIds"] + }, + "v1DeleteWalletAccountsResult": { + "type": "object", + "properties": { + "walletAccountIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of wallet account unique identifiers that were removed" + } + }, + "required": ["walletAccountIds"] + }, + "v1DeleteWalletsIntent": { + "type": "object", + "properties": { + "walletIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of unique identifiers for wallets within an organization" + }, + "deleteWithoutExport": { + "type": "boolean", + "description": "Optional parameter for deleting the wallets, even if any have not been previously exported. If they have been exported, this field is ignored." + } + }, + "required": ["walletIds"] + }, + "v1DeleteWalletsResult": { + "type": "object", + "properties": { + "walletIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of wallet unique identifiers that were removed" + } + }, + "required": ["walletIds"] + }, + "v1DeleteWebhookEndpointIntent": { + "type": "object", + "properties": { + "endpointId": { + "type": "string", + "description": "Unique identifier of the webhook endpoint to delete." + } + }, + "required": ["endpointId"] + }, + "v1DeleteWebhookEndpointResult": { + "type": "object", + "properties": { + "endpointId": { + "type": "string", + "description": "Unique identifier of the deleted webhook endpoint." + } + }, + "required": ["endpointId"] + }, + "v1DisableAuthProxyIntent": { + "type": "object" + }, + "v1DisableAuthProxyResult": { + "type": "object" + }, + "v1DisablePrivateKeyIntent": { + "type": "object", + "properties": { + "privateKeyId": { + "type": "string", + "description": "Unique identifier for a given Private Key." + } + }, + "required": ["privateKeyId"] + }, + "v1DisablePrivateKeyResult": { + "type": "object", + "properties": { + "privateKeyId": { + "type": "string", + "description": "Unique identifier for a given Private Key." + } + }, + "required": ["privateKeyId"] + }, + "v1EarnClaimRewardsIntent": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "A Turnkey-managed wallet address the rewards are attributed to. The claim transaction is signed by this wallet and the Merkl Distributor transfers every reward token to it." + }, + "caip2": { + "type": "string", + "description": "CAIP-2 chain to claim rewards on (e.g. 'eip155:8453'). Rewards accrue per chain; see ListEarnRewards." + }, + "sponsor": { + "type": "boolean", + "description": "Whether to sponsor this transaction via Gas Station." + } + }, + "required": ["signWith", "caip2"] + }, + "v1EarnClaimRewardsResult": { + "type": "object", + "properties": { + "claimRequestId": { + "type": "string", + "description": "Identifier to poll claim status and tx hash via GetEarnClaimRewardsStatus." + } + }, + "required": ["claimRequestId"] + }, + "v1EarnDeployWrapperIntent": { + "type": "object", + "properties": { + "vaultAddress": { + "type": "string", + "description": "Address of the underlying yield vault to wrap (from the ListEarnVaults catalog)." + }, + "caip2": { + "type": "string", + "enum": [ + "eip155:1", + "eip155:8453", + "eip155:42161", + "eip155:137", + "eip155:56", + "eip155:4217", + "solana:mainnet", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", + "solana:devnet", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1" + ], + "description": "CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base)." + }, + "clientFeeBps": { + "type": "string", + "description": "Your fee on gross yield, in basis points (e.g., '2000' for 20%). Maximum is 4000 (40%)." + }, + "clientFeeWallet": { + "type": "string", + "description": "The wallet address that receives the client's fee payouts on-chain. Must be a Turnkey-managed wallet address." + } + }, + "required": ["vaultAddress", "caip2", "clientFeeBps", "clientFeeWallet"] + }, + "v1EarnDeployWrapperResult": { + "type": "object", + "properties": { + "wrapperAddress": { + "type": "string", + "description": "Address of the deployed fee wrapper (the deposit target)." + }, + "splitterAddress": { + "type": "string", + "description": "Address of the deployed fee splitter (PaymentSplitter for Morpho, RevenueSplitterOwner for Aave)." + }, + "deployRequestId": { + "type": "string", + "description": "Identifier to poll deploy status." + } + }, + "required": ["wrapperAddress", "splitterAddress", "deployRequestId"] + }, + "v1EarnDepositIntent": { + "type": "object", + "properties": { + "wrapperAddress": { + "type": "string", + "description": "Address of the deployed Earn wrapper to deposit into, from ListEarnVaults/ListEarnPositions. Must be one of the org's deployed wrappers." + }, + "signWith": { + "type": "string", + "description": "A Wallet account address or Private Key address to deposit from and sign with. Must be an on-chain address; Private Key identifiers are not supported." + }, + "assets": { + "type": "string", + "description": "Amount of the underlying asset to deposit, in raw on-chain units (e.g., '1000000' for 1 USDC at 6 decimals)." + }, + "caip2": { + "type": "string", + "enum": [ + "eip155:1", + "eip155:8453", + "eip155:42161", + "eip155:137", + "eip155:56", + "eip155:4217", + "solana:mainnet", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", + "solana:devnet", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1" + ], + "description": "CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base)." + }, + "sponsor": { + "type": "boolean", + "description": "Whether to sponsor this transaction via Gas Station." + } + }, + "required": ["wrapperAddress", "signWith", "assets", "caip2"] + }, + "v1EarnDepositResult": { + "type": "object", + "properties": { + "depositRequestId": { + "type": "string", + "description": "Identifier to poll deposit status and tx hash via GetEarnDepositStatus." + } + }, + "required": ["depositRequestId"] + }, + "v1EarnSetWrapperStateIntent": { + "type": "object", + "properties": { + "wrapperAddress": { + "type": "string", + "description": "Address of the deployed Earn wrapper to update, from ListEarnVaults/ListEarnPositions. Must be one of the org's deployed wrappers." + }, + "depositsDisabled": { + "type": "boolean", + "description": "When true, deposits to this wrapper are rejected; withdrawals are unaffected. Set to false to re-enable deposits." + } + }, + "required": ["wrapperAddress", "depositsDisabled"] + }, + "v1EarnSetWrapperStateResult": { + "type": "object", + "properties": { + "wrapperAddress": { + "type": "string", + "description": "Address of the updated Earn wrapper." + }, + "depositsDisabled": { + "type": "boolean", + "description": "The wrapper's deposit state after this activity." + } + }, + "required": ["wrapperAddress", "depositsDisabled"] + }, + "v1EarnWithdrawIntent": { + "type": "object", + "properties": { + "wrapperAddress": { + "type": "string", + "description": "Address of the deployed Earn wrapper holding the position to withdraw from, from ListEarnPositions. Must be one of the org's deployed wrappers." + }, + "signWith": { + "type": "string", + "description": "A Wallet account address or Private Key address to withdraw to and sign with. Must be an on-chain address; Private Key identifiers are not supported." + }, + "caip2": { + "type": "string", + "enum": [ + "eip155:1", + "eip155:8453", + "eip155:42161", + "eip155:137", + "eip155:56", + "eip155:4217", + "solana:mainnet", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", + "solana:devnet", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1" + ], + "description": "CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base)." + }, + "sponsor": { + "type": "boolean", + "description": "Whether to sponsor this transaction via Gas Station." + }, + "amountValue": { + "type": "string", + "description": "The amount of the underlying asset to withdraw, in raw on-chain units. Pass 'MAX' to withdraw the entire position." + } + }, + "required": ["wrapperAddress", "signWith", "caip2", "amountValue"] + }, + "v1EarnWithdrawResult": { + "type": "object", + "properties": { + "withdrawRequestId": { + "type": "string", + "description": "Identifier to poll withdrawal status and tx hash via GetEarnWithdrawStatus." + } + }, + "required": ["withdrawRequestId"] + }, + "v1Effect": { + "type": "string", + "enum": ["EFFECT_ALLOW", "EFFECT_DENY"] + }, + "v1EmailAuthCustomizationParams": { + "type": "object", + "properties": { + "appName": { + "type": "string", + "description": "The name of the application. This field is required and will be used in email notifications if an email template is not provided." + }, + "logoUrl": { + "type": "string", + "description": "A URL pointing to a logo in PNG format. Note this logo will be resized to fit into 340px x 124px." + }, + "magicLinkTemplate": { + "type": "string", + "description": "A template for the URL to be used in a magic link button, e.g. `https://dapp.xyz/%s`. The auth bundle will be interpolated into the `%s`." + }, + "templateVariables": { + "type": "string", + "description": "JSON object containing key/value pairs to be used with custom templates." + }, + "templateId": { + "type": "string", + "description": "Unique identifier for a given Email Template. If not specified, the default is the most recent Email Template." + } + }, + "required": ["appName"] + }, + "v1EmailAuthIntent": { + "type": "object", + "properties": { + "email": { + "type": "string", + "description": "Email of the authenticating user." + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the email auth bundle (credentials) will be encrypted." + }, + "apiKeyName": { + "type": "string", + "description": "Optional human-readable name for an API Key. If none provided, default to Email Auth - \u003cTimestamp\u003e" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the API key is valid for. If not provided, a default of 15 minutes will be used." + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailCustomizationParams", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated Email Auth API keys" + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the email" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["email", "targetPublicKey"] + }, + "v1EmailAuthIntentV2": { + "type": "object", + "properties": { + "email": { + "type": "string", + "description": "Email of the authenticating user." + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the email auth bundle (credentials) will be encrypted." + }, + "apiKeyName": { + "type": "string", + "description": "Optional human-readable name for an API Key. If none provided, default to Email Auth - \u003cTimestamp\u003e" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the API key is valid for. If not provided, a default of 15 minutes will be used." + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailCustomizationParams", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated Email Auth API keys" + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the email" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["email", "targetPublicKey"] + }, + "v1EmailAuthIntentV3": { + "type": "object", + "properties": { + "email": { + "type": "string", + "description": "Email of the authenticating user." + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the email auth bundle (credentials) will be encrypted." + }, + "apiKeyName": { + "type": "string", + "description": "Optional human-readable name for an API Key. If none provided, default to Email Auth - \u003cTimestamp\u003e" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the API key is valid for. If not provided, a default of 15 minutes will be used." + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailAuthCustomizationParams", + "description": "Parameters for customizing emails. If not provided, the default email will be used. Note that app_name is required." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated Email Auth API keys" + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the email" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["email", "targetPublicKey", "emailCustomization"] + }, + "v1EmailAuthResult": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for the authenticating User." + }, + "apiKeyId": { + "type": "string", + "description": "Unique identifier for the created API key." + } + }, + "required": ["userId", "apiKeyId"] + }, + "v1EmailCustomizationParams": { + "type": "object", + "properties": { + "appName": { + "type": "string", + "description": "The name of the application." + }, + "logoUrl": { + "type": "string", + "description": "A URL pointing to a logo in PNG format. Note this logo will be resized to fit into 340px x 124px." + }, + "magicLinkTemplate": { + "type": "string", + "description": "A template for the URL to be used in a magic link button, e.g. `https://dapp.xyz/%s`. The auth bundle will be interpolated into the `%s`." + }, + "templateVariables": { + "type": "string", + "description": "JSON object containing key/value pairs to be used with custom templates." + }, + "templateId": { + "type": "string", + "description": "Unique identifier for a given Email Template. If not specified, the default is the most recent Email Template." + } + } + }, + "v1EmailCustomizationParamsV2": { + "type": "object", + "properties": { + "logoUrl": { + "type": "string", + "description": "A URL pointing to a logo in PNG format. Note this logo will be resized to fit into 340px x 124px." + }, + "magicLinkTemplate": { + "type": "string", + "description": "A template for the URL to be used in a magic link button, e.g. `https://dapp.xyz/%s`. The auth bundle will be interpolated into the `%s`." + }, + "templateVariables": { + "type": "string", + "description": "JSON object containing key/value pairs to be used with custom templates." + }, + "templateId": { + "type": "string", + "description": "Unique identifier for a given Email Template. If not specified, the default is the most recent Email Template." + } + } + }, + "v1EnableAuthProxyIntent": { + "type": "object" + }, + "v1EnableAuthProxyResult": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "A User ID with permission to initiate authentication." + } + }, + "required": ["userId"] + }, + "v1EthCallParams": { + "type": "object", + "properties": { + "to": { + "type": "string", + "description": "Recipient address as a hex string with 0x prefix." + }, + "value": { + "type": "string", + "description": "Amount of native asset to send in wei." + }, + "data": { + "type": "string", + "description": "Hex-encoded call data for contract interactions." + } + }, + "required": ["to"] + }, + "v1EthSendRawTransactionIntent": { + "type": "object", + "properties": { + "signedTransaction": { + "type": "string", + "description": "The raw, signed transaction to be sent." + }, + "caip2": { + "type": "string", + "enum": [ + "eip155:1", + "eip155:11155111", + "eip155:8453", + "eip155:84532", + "eip155:137", + "eip155:80002", + "eip155:56", + "eip155:97", + "eip155:10", + "eip155:11155420", + "eip155:143", + "eip155:10143", + "eip155:42161", + "eip155:4217", + "eip155:42431", + "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" + ], + "description": "CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." + } + }, + "required": ["signedTransaction", "caip2"] + }, + "v1EthSendRawTransactionResult": { + "type": "object", + "properties": { + "transactionHash": { + "type": "string", + "description": "The transaction hash of the sent transaction" + } + }, + "required": ["transactionHash"] + }, + "v1EthSendTransactionIntent": { + "type": "object", + "properties": { + "from": { + "type": "string", + "description": "A wallet or private key address to sign with. This does not support private key IDs." + }, + "sponsor": { + "type": "boolean", + "description": "Whether to sponsor this transaction via Gas Station." + }, + "caip2": { + "type": "string", + "enum": [ + "eip155:1", + "eip155:11155111", + "eip155:8453", + "eip155:84532", + "eip155:137", + "eip155:80002", + "eip155:56", + "eip155:97", + "eip155:10", + "eip155:11155420", + "eip155:143", + "eip155:10143", + "eip155:42161", + "eip155:4217", + "eip155:42431", + "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" + ], + "description": "CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." + }, + "to": { + "type": "string", + "description": "Recipient address as a hex string with 0x prefix." + }, + "value": { + "type": "string", + "description": "Amount of native asset to send in wei." + }, + "data": { + "type": "string", + "description": "Hex-encoded call data for contract interactions." + }, + "nonce": { + "type": "string", + "description": "Transaction nonce, for EIP-1559 and Turnkey Gas Station authorizations." + }, + "gasLimit": { + "type": "string", + "description": "Maximum amount of gas to use for this transaction, for EIP-1559 transactions." + }, + "maxFeePerGas": { + "type": "string", + "description": "Maximum total fee per gas unit (base fee + priority fee) in wei. Required for non-sponsored (EIP-1559) transactions. Not used for sponsored transactions." + }, + "maxPriorityFeePerGas": { + "type": "string", + "description": "Maximum priority fee (tip) per gas unit in wei. Required for non-sponsored (EIP-1559) transactions. Not used for sponsored transactions." + }, + "deadline": { + "type": "string", + "description": "Unix timestamp in seconds for EIP-712 execution deadline. Only used when sponsor=true." + }, + "gasStationNonce": { + "type": "string", + "description": "The gas station delegate contract nonce. Only used when sponsor=true. Include this if you want maximal security posture." + } + }, + "required": ["from", "caip2", "to"] + }, + "v1EthSendTransactionIntentV2": { + "type": "object", + "properties": { + "from": { + "type": "string", + "description": "A wallet or private key address to sign with. This does not support private key IDs." + }, + "caip2": { + "type": "string", + "enum": [ + "eip155:1", + "eip155:11155111", + "eip155:8453", + "eip155:84532", + "eip155:137", + "eip155:80002", + "eip155:56", + "eip155:97", + "eip155:10", + "eip155:11155420", + "eip155:143", + "eip155:10143", + "eip155:42161", + "eip155:4217", + "eip155:42431", + "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" + ], + "description": "CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." + }, + "sponsor": { + "type": "boolean", + "description": "Whether to sponsor this transaction via Gas Station. If false or unset, the EOA pays gas. A single call uses EIP-1559; multiple calls use EIP-7702 batch execution via Gas Station." + }, + "nonce": { + "type": "string", + "description": "Outer transaction nonce. Omit to auto-fetch." + }, + "gasLimit": { + "type": "string", + "description": "Maximum amount of gas for the outer transaction. Omit to auto-estimate." + }, + "maxFeePerGas": { + "type": "string", + "description": "Maximum total fee per gas unit (base fee + priority fee) in wei. Omit to auto-estimate." + }, + "maxPriorityFeePerGas": { + "type": "string", + "description": "Maximum priority fee (tip) per gas unit in wei. Omit to auto-estimate." + }, + "deadline": { + "type": "string", + "description": "Unix timestamp in seconds for EIP-712 execution deadline. Only used when sponsor=true." + }, + "gasStationNonce": { + "type": "string", + "description": "The gas station delegate contract nonce used in the BatchExecution EIP-712 message. Valid for sponsored transactions and non-sponsored multi-call batches. Omit to auto-fetch. Use the nonces endpoint for replay protection." + }, + "calls": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1EthCallParams" + }, + "description": "Ordered list of calls to execute. Must contain between 1 and 50 entries. A single entry with sponsor=false uses EIP-1559; multiple entries use EIP-7702 batch execution via Gas Station." + } + }, + "required": ["from", "caip2", "calls"] + }, + "v1EthSendTransactionResult": { + "type": "object", + "properties": { + "sendTransactionStatusId": { + "type": "string", + "description": "The send_transaction_status ID associated with the transaction submission" + } + }, + "required": ["sendTransactionStatusId"] + }, + "v1EthSendTransactionResultV2": { + "type": "object", + "properties": { + "sendTransactionStatusId": { + "type": "string", + "description": "The send_transaction_status ID associated with the transaction submission" + } + }, + "required": ["sendTransactionStatusId"] + }, + "v1EthUndelegate7702Intent": { + "type": "object", + "properties": { + "from": { + "type": "string", + "description": "A wallet or private key address to undelegate. This does not support private key IDs." + }, + "caip2": { + "type": "string", + "enum": [ + "eip155:1", + "eip155:11155111", + "eip155:8453", + "eip155:84532", + "eip155:137", + "eip155:80002", + "eip155:56", + "eip155:97", + "eip155:10", + "eip155:11155420", + "eip155:143", + "eip155:10143", + "eip155:42161", + "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" + ], + "description": "CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." + }, + "nonce": { + "type": "string", + "description": "Outer transaction nonce. Omit to auto-fetch." + }, + "gasLimit": { + "type": "string", + "description": "Maximum amount of gas for the undelegation transaction. Omit to use the fixed undelegation gas limit." + }, + "maxFeePerGas": { + "type": "string", + "description": "Maximum total fee per gas unit (base fee + priority fee) in wei. Omit to auto-estimate." + }, + "maxPriorityFeePerGas": { + "type": "string", + "description": "Maximum priority fee (tip) per gas unit in wei. Omit to auto-estimate." + } + }, + "required": ["from", "caip2"] + }, + "v1EthUndelegate7702Result": { + "type": "object", + "properties": { + "sendTransactionStatusId": { + "type": "string", + "description": "The send_transaction_status ID associated with the undelegation transaction submission" + } + }, + "required": ["sendTransactionStatusId"] + }, + "v1ExecuteSwapIntent": { + "type": "object", + "properties": { + "inputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the input asset. The chain is derived from this value." + }, + "outputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the output asset. May be on a different chain than `input_token` for cross-chain swaps." + }, + "inputAmount": { + "type": "string", + "description": "Base-unit amount of the input asset." + }, + "walletAccount": { + "type": "string", + "description": "Wallet account address to sign and submit the swap transaction from. Cross-wallet swaps are not supported." + }, + "sponsor": { + "type": "boolean", + "description": "Whether to sponsor the resulting swap transaction via Gas Station when supported by the chain." + }, + "slippage": { + "type": "string", + "description": "Maximum allowed slippage in basis points." + }, + "provider": { + "type": "string", + "description": "Swap provider to execute with, as returned by create_swap_quote. When omitted, execution uses the default provider." + }, + "minOutputAmount": { + "type": "string", + "description": "Minimum acceptable base-unit amount of the output asset. Execution fails if the swap provider's quoted minimum output falls below this floor at execution time." + } + }, + "required": [ + "inputToken", + "outputToken", + "inputAmount", + "walletAccount", + "minOutputAmount" + ] + }, + "v1ExecuteSwapIntentV2": { + "type": "object", + "properties": { + "quoteId": { + "type": "string", + "description": "Quote identifier returned by create_swap_quote. Execution is bound to this quote; the signer is derived from the quote and must not be resupplied." + }, + "inputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the input asset." + }, + "inputAmount": { + "type": "string", + "description": "Exact base-unit amount of the input asset committed by the quote." + }, + "outputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the output asset." + }, + "quotedOutputAmount": { + "type": "string", + "description": "Exact quoted base-unit output amount committed by the quote." + }, + "minOutputAmount": { + "type": "string", + "description": "Exact minimum base-unit output committed by the quote." + }, + "sponsor": { + "type": "boolean", + "description": "Whether the quoted transaction is sponsored." + }, + "evmNonce": { + "type": "string", + "description": "Exact EVM sender (EOA account) nonce. Valid only for a non-sponsored EVM swap. Honored for already-delegated (Type-2) batch swaps and single-call swaps; ignored for not-yet-delegated EIP-7702 (Type-4) batches where the outer nonce is derived from the authorization. Prefer gas_station_nonce for batch replay protection and use the nonces endpoint to fetch it. Omit to auto-fetch." + }, + "recentBlockhash": { + "type": "string", + "description": "Exact Solana recent blockhash. Valid only for a Solana swap, including sponsored swaps. Omit to auto-fetch." + }, + "gasStationNonce": { + "type": "string", + "description": "Exact gas station delegate contract nonce used in the BatchExecution EIP-712 message. Valid for sponsored EVM swaps and non-sponsored EVM swaps that execute as a multi-call batch (for example ERC-20 approve + swap). This is the replay-protection nonce for gas-station batches; use the nonces endpoint to fetch it. Omit to auto-fetch." + } + }, + "required": [ + "quoteId", + "inputToken", + "inputAmount", + "outputToken", + "quotedOutputAmount", + "minOutputAmount", + "sponsor" + ] + }, + "v1ExecuteSwapIntentV3": { + "type": "object", + "properties": { + "quoteId": { + "type": "string", + "description": "Quote identifier returned by create_swap_quote. Execution is bound to this quote; the signer is derived from the quote and must not be resupplied." + }, + "inputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the input asset." + }, + "inputAmount": { + "type": "string", + "description": "Exact base-unit amount of the input asset committed by the quote." + }, + "outputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the output asset." + }, + "quotedOutputAmount": { + "type": "string", + "description": "Exact quoted base-unit output amount committed by the quote." + }, + "minOutputAmount": { + "type": "string", + "description": "Exact minimum base-unit output committed by the quote." + }, + "sponsor": { + "type": "boolean", + "description": "Whether the quoted transaction is sponsored." + }, + "evmNonce": { + "type": "string", + "description": "Exact EVM sender (EOA account) nonce. Valid only for a non-sponsored EVM swap. Honored for already-delegated (Type-2) batch swaps and single-call swaps; ignored for not-yet-delegated EIP-7702 (Type-4) batches where the outer nonce is derived from the authorization. Prefer gas_station_nonce for batch replay protection and use the nonces endpoint to fetch it. Omit to auto-fetch." + }, + "recentBlockhash": { + "type": "string", + "description": "Exact Solana recent blockhash. Valid only for a Solana swap, including sponsored swaps. Omit to auto-fetch." + }, + "gasStationNonce": { + "type": "string", + "description": "Exact gas station delegate contract nonce used in the BatchExecution EIP-712 message. Valid for sponsored EVM swaps and non-sponsored EVM swaps that execute as a multi-call batch (for example ERC-20 approve + swap). This is the replay-protection nonce for gas-station batches; use the nonces endpoint to fetch it. Omit to auto-fetch." + }, + "destinationAddress": { + "type": "string", + "description": "Raw public address that receives the output asset. Required for cross-protocol swaps. The address must match the output token protocol. Wallet account IDs, private key IDs, and CAIP account or asset identifiers are not supported." + } + }, + "required": [ + "quoteId", + "inputToken", + "inputAmount", + "outputToken", + "quotedOutputAmount", + "minOutputAmount", + "sponsor" + ] + }, + "v1ExecuteSwapResult": { + "type": "object", + "properties": { + "swapRequestId": { + "type": "string", + "description": "Identifier to poll swap status via GetSwapStatus." + }, + "provider": { + "type": "string", + "description": "Swap provider used to build the transaction." + }, + "quoteId": { + "type": "string", + "description": "Quote identifier used for execution, if any." + } + }, + "required": ["swapRequestId"] + }, + "v1ExportPrivateKeyIntent": { + "type": "object", + "properties": { + "privateKeyId": { + "type": "string", + "description": "Unique identifier for a given Private Key." + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the export bundle will be encrypted." + } + }, + "required": ["privateKeyId", "targetPublicKey"] + }, + "v1ExportPrivateKeyResult": { + "type": "object", + "properties": { + "privateKeyId": { + "type": "string", + "description": "Unique identifier for a given Private Key." + }, + "exportBundle": { + "type": "string", + "description": "Export bundle containing a private key encrypted to the client's target public key." + } + }, + "required": ["privateKeyId", "exportBundle"] + }, + "v1ExportSecretParams": { + "type": "object", + "properties": { + "secretId": { + "type": "string", + "description": "Unique identifier for the secret to export." + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the exported secret will be encrypted." + }, + "encryptionSuite": { + "$ref": "#/definitions/v1TransportEncryptionSuite", + "description": "Transport encryption suite used for the exported secret." + }, + "requestContext": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1KeyValue" + }, + "description": "Bind metadata to the request." + } + }, + "required": ["secretId", "targetPublicKey", "encryptionSuite"] + }, + "v1ExportSecretsIntent": { + "type": "object", + "properties": { + "secrets": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ExportSecretParams" + }, + "description": "A list of secrets to export." + } + }, + "required": ["secrets"] + }, + "v1ExportSecretsResult": { + "type": "object", + "properties": { + "secretPayloads": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Encryption suite specific payload containing each secret ciphertext, in the order the params were specified. For enclave encrypt v1 each entry is a JSON-encoded ServerSendMsg." + } + }, + "required": ["secretPayloads"] + }, + "v1ExportWalletAccountIntent": { + "type": "object", + "properties": { + "address": { + "type": "string", + "description": "Address to identify Wallet Account." + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the export bundle will be encrypted." + } + }, + "required": ["address", "targetPublicKey"] + }, + "v1ExportWalletAccountResult": { + "type": "object", + "properties": { + "address": { + "type": "string", + "description": "Address to identify Wallet Account." + }, + "exportBundle": { + "type": "string", + "description": "Export bundle containing a private key encrypted by the client's target public key." + } + }, + "required": ["address", "exportBundle"] + }, + "v1ExportWalletIntent": { + "type": "object", + "properties": { + "walletId": { + "type": "string", + "description": "Unique identifier for a given Wallet." + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the export bundle will be encrypted." + }, + "language": { + "$ref": "#/definitions/v1MnemonicLanguage", + "description": "The language of the mnemonic to export. Defaults to English." + } + }, + "required": ["walletId", "targetPublicKey"] + }, + "v1ExportWalletResult": { + "type": "object", + "properties": { + "walletId": { + "type": "string", + "description": "Unique identifier for a given Wallet." + }, + "exportBundle": { + "type": "string", + "description": "Export bundle containing a wallet mnemonic + optional newline passphrase encrypted by the client's target public key." + } + }, + "required": ["walletId", "exportBundle"] + }, + "v1ExternalSignerTask": { + "type": "object", + "properties": { + "taskId": { + "type": "string", + "description": "Unique identifier for a given external signer task." + }, + "userId": { + "type": "string", + "description": "Unique identifier for the user associated with the external signer task." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for the organization associated with the external signer task." + }, + "activity": { + "$ref": "#/definitions/v1Activity", + "description": "The activity associated with the external signer task." + }, + "signature": { + "$ref": "#/definitions/externalcryptov1Signature", + "description": "Ump signature associated with the external signer task." + } + }, + "required": [ + "taskId", + "userId", + "organizationId", + "activity", + "signature" + ] + }, + "v1Feature": { + "type": "object", + "properties": { + "name": { + "$ref": "#/definitions/v1FeatureName" + }, + "value": { + "type": "string" + } + } + }, + "v1FeatureName": { + "type": "string", + "enum": [ + "FEATURE_NAME_ROOT_USER_EMAIL_RECOVERY", + "FEATURE_NAME_WEBAUTHN_ORIGINS", + "FEATURE_NAME_EMAIL_AUTH", + "FEATURE_NAME_EMAIL_RECOVERY", + "FEATURE_NAME_WEBHOOK", + "FEATURE_NAME_SMS_AUTH", + "FEATURE_NAME_OTP_EMAIL_AUTH", + "FEATURE_NAME_AUTH_PROXY", + "FEATURE_NAME_SOLANA_RENT_PREFUND_ENABLED", + "FEATURE_NAME_SWAP_CONFIG", + "FEATURE_NAME_EARN_CONFIG", + "FEATURE_NAME_SWAP_FEE_SPONSORSHIP", + "FEATURE_NAME_SWAP_FIXED_RATE" + ] + }, + "v1FiatOnRampBlockchainNetwork": { + "type": "string", + "enum": [ + "FIAT_ON_RAMP_BLOCKCHAIN_NETWORK_BITCOIN", + "FIAT_ON_RAMP_BLOCKCHAIN_NETWORK_ETHEREUM", + "FIAT_ON_RAMP_BLOCKCHAIN_NETWORK_SOLANA", + "FIAT_ON_RAMP_BLOCKCHAIN_NETWORK_BASE" + ] + }, + "v1FiatOnRampCryptoCurrency": { + "type": "string", + "enum": [ + "FIAT_ON_RAMP_CRYPTO_CURRENCY_BTC", + "FIAT_ON_RAMP_CRYPTO_CURRENCY_ETH", + "FIAT_ON_RAMP_CRYPTO_CURRENCY_SOL", + "FIAT_ON_RAMP_CRYPTO_CURRENCY_USDC" + ] + }, + "v1FiatOnRampCurrency": { + "type": "string", + "enum": [ + "FIAT_ON_RAMP_CURRENCY_AUD", + "FIAT_ON_RAMP_CURRENCY_BGN", + "FIAT_ON_RAMP_CURRENCY_BRL", + "FIAT_ON_RAMP_CURRENCY_CAD", + "FIAT_ON_RAMP_CURRENCY_CHF", + "FIAT_ON_RAMP_CURRENCY_COP", + "FIAT_ON_RAMP_CURRENCY_CZK", + "FIAT_ON_RAMP_CURRENCY_DKK", + "FIAT_ON_RAMP_CURRENCY_DOP", + "FIAT_ON_RAMP_CURRENCY_EGP", + "FIAT_ON_RAMP_CURRENCY_EUR", + "FIAT_ON_RAMP_CURRENCY_GBP", + "FIAT_ON_RAMP_CURRENCY_HKD", + "FIAT_ON_RAMP_CURRENCY_IDR", + "FIAT_ON_RAMP_CURRENCY_ILS", + "FIAT_ON_RAMP_CURRENCY_JOD", + "FIAT_ON_RAMP_CURRENCY_KES", + "FIAT_ON_RAMP_CURRENCY_KWD", + "FIAT_ON_RAMP_CURRENCY_LKR", + "FIAT_ON_RAMP_CURRENCY_MXN", + "FIAT_ON_RAMP_CURRENCY_NGN", + "FIAT_ON_RAMP_CURRENCY_NOK", + "FIAT_ON_RAMP_CURRENCY_NZD", + "FIAT_ON_RAMP_CURRENCY_OMR", + "FIAT_ON_RAMP_CURRENCY_PEN", + "FIAT_ON_RAMP_CURRENCY_PLN", + "FIAT_ON_RAMP_CURRENCY_RON", + "FIAT_ON_RAMP_CURRENCY_SEK", + "FIAT_ON_RAMP_CURRENCY_THB", + "FIAT_ON_RAMP_CURRENCY_TRY", + "FIAT_ON_RAMP_CURRENCY_TWD", + "FIAT_ON_RAMP_CURRENCY_USD", + "FIAT_ON_RAMP_CURRENCY_VND", + "FIAT_ON_RAMP_CURRENCY_ZAR" + ] + }, + "v1FiatOnRampPaymentMethod": { + "type": "string", + "enum": [ + "FIAT_ON_RAMP_PAYMENT_METHOD_CREDIT_DEBIT_CARD", + "FIAT_ON_RAMP_PAYMENT_METHOD_APPLE_PAY", + "FIAT_ON_RAMP_PAYMENT_METHOD_GBP_BANK_TRANSFER", + "FIAT_ON_RAMP_PAYMENT_METHOD_GBP_OPEN_BANKING_PAYMENT", + "FIAT_ON_RAMP_PAYMENT_METHOD_GOOGLE_PAY", + "FIAT_ON_RAMP_PAYMENT_METHOD_SEPA_BANK_TRANSFER", + "FIAT_ON_RAMP_PAYMENT_METHOD_PIX_INSTANT_PAYMENT", + "FIAT_ON_RAMP_PAYMENT_METHOD_PAYPAL", + "FIAT_ON_RAMP_PAYMENT_METHOD_VENMO", + "FIAT_ON_RAMP_PAYMENT_METHOD_MOONPAY_BALANCE", + "FIAT_ON_RAMP_PAYMENT_METHOD_CRYPTO_ACCOUNT", + "FIAT_ON_RAMP_PAYMENT_METHOD_FIAT_WALLET", + "FIAT_ON_RAMP_PAYMENT_METHOD_ACH_BANK_ACCOUNT" + ] + }, + "v1FiatOnRampProvider": { + "type": "string", + "enum": [ + "FIAT_ON_RAMP_PROVIDER_COINBASE", + "FIAT_ON_RAMP_PROVIDER_MOONPAY" + ] + }, + "v1GetExternalSignerTasksRequest": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given organization." + }, + "externalSignerPublicKey": { + "type": "string", + "description": "Public key of the external signer." + }, + "maxTasks": { + "type": "integer", + "format": "int64", + "description": "Maximum number of tasks to retrieve." + } + }, + "required": ["organizationId", "externalSignerPublicKey", "maxTasks"] + }, + "v1GetExternalSignerTasksResponse": { + "type": "object", + "properties": { + "tasks": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ExternalSignerTask" + }, + "description": "List of external signer tasks." + } + }, + "required": ["tasks"] + }, + "v1ImportPrivateKeyIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User importing a Private Key." + }, + "privateKeyName": { + "type": "string", + "description": "Human-readable name for a Private Key." + }, + "encryptedBundle": { + "type": "string", + "description": "Bundle containing a raw private key encrypted to the enclave's target public key." + }, + "curve": { + "$ref": "#/definitions/v1Curve", + "description": "Cryptographic Curve used to generate a given Private Key." + }, + "addressFormats": { + "type": "array", + "items": { + "$ref": "#/definitions/v1AddressFormat" + }, + "description": "Cryptocurrency-specific formats for a derived address (e.g., Ethereum)." + } + }, + "required": [ + "userId", + "privateKeyName", + "encryptedBundle", + "curve", + "addressFormats" + ] + }, + "v1ImportPrivateKeyResult": { + "type": "object", + "properties": { + "privateKeyId": { + "type": "string", + "description": "Unique identifier for a Private Key." + }, + "addresses": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/immutableactivityv1Address" + }, + "description": "A list of addresses." + } + }, + "required": ["privateKeyId", "addresses"] + }, + "v1ImportSecretParams": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "Optional human-readable name for the secret. Names must be unique within an organization when provided." + }, + "secretPayload": { + "type": "string", + "description": "Encryption suite specific payload containing the secret ciphertext. For enclave encrypt v1 this is a JSON-encoded ClientSendMsg." + }, + "targetPublicKey": { + "type": "string", + "description": "Targeted transport encryption public key, as returned by InitImportSecrets." + }, + "encryptionSuite": { + "$ref": "#/definitions/v1TransportEncryptionSuite", + "description": "Transport encryption suite used for the ingress secret." + }, + "staticProperties": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1KeyValue" + }, + "description": "Policy-visible, static properties to permanently bind to the secret." + } + }, + "required": ["secretPayload", "targetPublicKey", "encryptionSuite"] + }, + "v1ImportSecretsIntent": { + "type": "object", + "properties": { + "secrets": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ImportSecretParams" + }, + "description": "A list of secrets to import." + } + }, + "required": ["secrets"] + }, + "v1ImportSecretsResult": { + "type": "object", + "properties": { + "secretIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Unique identifier for each imported secret, in the order the params were specified." + } + }, + "required": ["secretIds"] + }, + "v1ImportWalletIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User importing a Wallet." + }, + "walletName": { + "type": "string", + "description": "Human-readable name for a Wallet." + }, + "encryptedBundle": { + "type": "string", + "description": "Bundle containing a wallet mnemonic encrypted to the enclave's target public key." + }, + "accounts": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1WalletAccountParams" + }, + "description": "A list of wallet Accounts." + } + }, + "required": ["userId", "walletName", "encryptedBundle", "accounts"] + }, + "v1ImportWalletResult": { + "type": "object", + "properties": { + "walletId": { + "type": "string", + "description": "Unique identifier for a Wallet." + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of account addresses." + } + }, + "required": ["walletId", "addresses"] + }, + "v1InitFiatOnRampIntent": { + "type": "object", + "properties": { + "onrampProvider": { + "$ref": "#/definitions/v1FiatOnRampProvider", + "description": "Enum to specify which on-ramp provider to use" + }, + "walletAddress": { + "type": "string", + "description": "Destination wallet address for the buy transaction." + }, + "network": { + "$ref": "#/definitions/v1FiatOnRampBlockchainNetwork", + "description": "Blockchain network to be used for the transaction, e.g., bitcoin, ethereum. Maps to MoonPay's network or Coinbase's defaultNetwork." + }, + "cryptoCurrencyCode": { + "$ref": "#/definitions/v1FiatOnRampCryptoCurrency", + "description": "Code for the cryptocurrency to be purchased, e.g., btc, eth. Maps to MoonPay's currencyCode or Coinbase's defaultAsset." + }, + "fiatCurrencyCode": { + "$ref": "#/definitions/v1FiatOnRampCurrency", + "description": "Code for the fiat currency to be used in the transaction, e.g., USD, EUR." + }, + "fiatCurrencyAmount": { + "type": "string", + "description": "Specifies a preset fiat amount for the transaction, e.g., '100'. Must be greater than '20'. If not provided, the user will be prompted to enter an amount." + }, + "paymentMethod": { + "$ref": "#/definitions/v1FiatOnRampPaymentMethod", + "description": "Pre-selected payment method, e.g., CREDIT_DEBIT_CARD, APPLE_PAY. Validated against the chosen provider." + }, + "countryCode": { + "type": "string", + "description": "ISO 3166-1 two-digit country code for Coinbase representing the purchasing user’s country of residence, e.g., US, GB." + }, + "countrySubdivisionCode": { + "type": "string", + "description": "ISO 3166-2 two-digit country subdivision code for Coinbase representing the purchasing user’s subdivision of residence within their country, e.g. NY. Required if country_code=US." + }, + "sandboxMode": { + "type": "boolean", + "description": "Optional flag to indicate whether to use the sandbox mode to simulate transactions for the on-ramp provider. Default is false." + }, + "urlForSignature": { + "type": "string", + "description": "Optional MoonPay Widget URL to sign when using MoonPay client SDKs with URL Signing enabled." + } + }, + "required": [ + "onrampProvider", + "walletAddress", + "network", + "cryptoCurrencyCode" + ] + }, + "v1InitFiatOnRampResult": { + "type": "object", + "properties": { + "onRampUrl": { + "type": "string", + "description": "Unique URL for a given fiat on-ramp flow." + }, + "onRampTransactionId": { + "type": "string", + "description": "Unique identifier used to retrieve transaction statuses for a given fiat on-ramp flow." + }, + "onRampUrlSignature": { + "type": "string", + "description": "Optional signature of the MoonPay Widget URL. The signature is generated if the Init Fiat On Ramp intent includes the urlForSignature field. The signature can be used to initialize the MoonPay SDKs when URL signing is enabled for your project." + } + }, + "required": ["onRampUrl", "onRampTransactionId"] + }, + "v1InitImportPrivateKeyIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User importing a Private Key." + } + }, + "required": ["userId"] + }, + "v1InitImportPrivateKeyResult": { + "type": "object", + "properties": { + "importBundle": { + "type": "string", + "description": "Import bundle containing a public key and signature to use for importing client data." + } + }, + "required": ["importBundle"] + }, + "v1InitImportSecretsIntent": { + "type": "object", + "properties": { + "encryptionSuite": { + "$ref": "#/definitions/v1TransportEncryptionSuite", + "description": "Transport encryption suite used for ingress secrets." + }, + "numSecrets": { + "type": "integer", + "format": "int32", + "description": "The number of secrets the user intends to import." + } + }, + "required": ["encryptionSuite", "numSecrets"] + }, + "v1InitImportSecretsResult": { + "type": "object", + "properties": { + "enclaveTargetMessages": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Enclave ingress target keys along with metadata specific to the encryption suite. For enclave encrypt v1 this will be ServerTargetMsgV1." + } + }, + "required": ["enclaveTargetMessages"] + }, + "v1InitImportWalletIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User importing a Wallet." + } + }, + "required": ["userId"] + }, + "v1InitImportWalletResult": { + "type": "object", + "properties": { + "importBundle": { + "type": "string", + "description": "Import bundle containing a public key and signature to use for importing client data." + } + }, + "required": ["importBundle"] + }, + "v1InitOtpAuthIntent": { + "type": "object", + "properties": { + "otpType": { + "type": "string", + "description": "Enum to specify whether to send OTP via SMS, email, or WhatsApp" + }, + "contact": { + "type": "string", + "description": "Email or phone number to send the OTP code to" + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailCustomizationParams", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "smsCustomization": { + "$ref": "#/definitions/v1SmsCustomizationParams", + "description": "Optional parameters for customizing SMS message. If not provided, the default sms message will be used." + }, + "userIdentifier": { + "type": "string", + "description": "Optional client-generated user identifier to enable per-user rate limiting for SMS auth. We recommend using a hash of the client-side IP address." + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the OTP email" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["otpType", "contact"] + }, + "v1InitOtpAuthIntentV2": { + "type": "object", + "properties": { + "otpType": { + "type": "string", + "description": "Enum to specify whether to send OTP via SMS, email, or WhatsApp" + }, + "contact": { + "type": "string", + "description": "Email or phone number to send the OTP code to" + }, + "otpLength": { + "type": "integer", + "format": "int32", + "description": "Optional length of the OTP code. Default = 9" + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailCustomizationParams", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "smsCustomization": { + "$ref": "#/definitions/v1SmsCustomizationParams", + "description": "Optional parameters for customizing SMS message. If not provided, the default SMS message will be used." + }, + "userIdentifier": { + "type": "string", + "description": "Optional client-generated user identifier to enable per-user rate limiting for SMS auth. We recommend using a hash of the client-side IP address." + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the OTP email" + }, + "alphanumeric": { + "type": "boolean", + "description": "Optional flag to specify if the OTP code should be alphanumeric (Crockford’s Base32). Default = true" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["otpType", "contact"] + }, + "v1InitOtpAuthIntentV3": { + "type": "object", + "properties": { + "otpType": { + "type": "string", + "description": "Whether to send OTP via SMS, email, or WhatsApp. Possible values: OTP_TYPE_SMS, OTP_TYPE_EMAIL, OTP_TYPE_WHATSAPP" + }, + "contact": { + "type": "string", + "description": "Email or phone number to send the OTP code to" + }, + "otpLength": { + "type": "integer", + "format": "int32", + "description": "Optional length of the OTP code. Default = 9" + }, + "appName": { + "type": "string", + "description": "The name of the application. This field is required and will be used in email notifications if an email template is not provided." + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailCustomizationParamsV2", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "smsCustomization": { + "$ref": "#/definitions/v1SmsCustomizationParams", + "description": "Optional parameters for customizing SMS message. If not provided, the default SMS message will be used." + }, + "userIdentifier": { + "type": "string", + "description": "Optional client-generated user identifier to enable per-user rate limiting for SMS auth. We recommend using a hash of the client-side IP address." + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the OTP email" + }, + "alphanumeric": { + "type": "boolean", + "description": "Optional flag to specify if the OTP code should be alphanumeric (Crockford’s Base32). Default = true" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the OTP is valid for. If not provided, a default of 5 minutes will be used. Maximum value is 600 seconds (10 minutes)" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["otpType", "contact", "appName"] + }, + "v1InitOtpAuthResult": { + "type": "object", + "properties": { + "otpId": { + "type": "string", + "description": "Unique identifier for an OTP authentication" + } + }, + "required": ["otpId"] + }, + "v1InitOtpAuthResultV2": { + "type": "object", + "properties": { + "otpId": { + "type": "string", + "description": "Unique identifier for an OTP authentication" + } + }, + "required": ["otpId"] + }, + "v1InitOtpIntent": { + "type": "object", + "properties": { + "otpType": { + "type": "string", + "description": "Whether to send OTP via SMS, email, or WhatsApp. Possible values: OTP_TYPE_SMS, OTP_TYPE_EMAIL, OTP_TYPE_WHATSAPP" + }, + "contact": { + "type": "string", + "description": "Email or phone number to send the OTP code to" + }, + "otpLength": { + "type": "integer", + "format": "int32", + "description": "Optional length of the OTP code. Default = 9" + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailCustomizationParams", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "smsCustomization": { + "$ref": "#/definitions/v1SmsCustomizationParams", + "description": "Optional parameters for customizing SMS message. If not provided, the default sms message will be used." + }, + "userIdentifier": { + "type": "string", + "description": "Optional client-generated user identifier to enable per-user rate limiting for SMS auth. We recommend using a hash of the client-side IP address." + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the OTP email" + }, + "alphanumeric": { + "type": "boolean", + "description": "Optional flag to specify if the OTP code should be alphanumeric (Crockford’s Base32). Default = true" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the OTP is valid for. If not provided, a default of 5 minutes will be used. Maximum value is 600 seconds (10 minutes)" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["otpType", "contact"] + }, + "v1InitOtpIntentV2": { + "type": "object", + "properties": { + "otpType": { + "type": "string", + "description": "Whether to send OTP via SMS, email, or WhatsApp. Possible values: OTP_TYPE_SMS, OTP_TYPE_EMAIL, OTP_TYPE_WHATSAPP" + }, + "contact": { + "type": "string", + "description": "Email or phone number to send the OTP code to" + }, + "otpLength": { + "type": "integer", + "format": "int32", + "description": "Optional length of the OTP code. Default = 9" + }, + "appName": { + "type": "string", + "description": "The name of the application. This field is required and will be used in email notifications if an email template is not provided." + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailCustomizationParamsV2", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "smsCustomization": { + "$ref": "#/definitions/v1SmsCustomizationParams", + "description": "Optional parameters for customizing SMS message. If not provided, the default SMS message will be used." + }, + "userIdentifier": { + "type": "string", + "description": "Optional client-generated user identifier to enable per-user rate limiting for SMS auth. We recommend using a hash of the client-side IP address." + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the OTP email" + }, + "alphanumeric": { + "type": "boolean", + "description": "Optional flag to specify if the OTP code should be alphanumeric (Crockford’s Base32). Default = true" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the OTP is valid for. If not provided, a default of 5 minutes will be used. Maximum value is 600 seconds (10 minutes)" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["otpType", "contact", "appName"] + }, + "v1InitOtpIntentV3": { + "type": "object", + "properties": { + "otpType": { + "type": "string", + "description": "Whether to send OTP via SMS, email, or WhatsApp. Possible values: OTP_TYPE_SMS, OTP_TYPE_EMAIL, OTP_TYPE_WHATSAPP" + }, + "contact": { + "type": "string", + "description": "Email or phone number to send the OTP code to" + }, + "appName": { + "type": "string", + "description": "The name of the application." + }, + "otpLength": { + "type": "integer", + "format": "int32", + "description": "Optional length of the OTP code. Default = 9" + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailCustomizationParamsV2", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "smsCustomization": { + "$ref": "#/definitions/v1SmsCustomizationParams", + "description": "Optional parameters for customizing SMS message. If not provided, the default sms message will be used." + }, + "userIdentifier": { + "type": "string", + "description": "Optional client-generated user identifier to enable per-user rate limiting for SMS auth. We recommend using a hash of the client-side IP address." + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the OTP email" + }, + "alphanumeric": { + "type": "boolean", + "description": "Optional flag to specify if the OTP code should be alphanumeric (Crockford’s Base32). If set to false, OTP code will only be numeric. Default = true" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the OTP is valid for. If not provided, a default of 5 minutes will be used. Maximum value is 600 seconds (10 minutes)" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["otpType", "contact", "appName"] + }, + "v1InitOtpResult": { + "type": "object", + "properties": { + "otpId": { + "type": "string", + "description": "Unique identifier for an OTP authentication" + } + }, + "required": ["otpId"] + }, + "v1InitOtpResultV2": { + "type": "object", + "properties": { + "otpId": { + "type": "string", + "description": "Unique identifier for an OTP flow" + }, + "otpEncryptionTargetBundle": { + "type": "string", + "description": "Signed bundle containing a target encryption key to use when submitting OTP codes." + } + }, + "required": ["otpId", "otpEncryptionTargetBundle"] + }, + "v1InitUserEmailRecoveryIntent": { + "type": "object", + "properties": { + "email": { + "type": "string", + "description": "Email of the user starting recovery" + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the recovery bundle will be encrypted." + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the recovery credential is valid for. If not provided, a default of 15 minutes will be used." + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailCustomizationParams", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the OTP email" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["email", "targetPublicKey"] + }, + "v1InitUserEmailRecoveryIntentV2": { + "type": "object", + "properties": { + "email": { + "type": "string", + "description": "Email of the user starting recovery" + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the recovery bundle will be encrypted." + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the recovery credential is valid for. If not provided, a default of 15 minutes will be used." + }, + "emailCustomization": { + "$ref": "#/definitions/v1EmailAuthCustomizationParams", + "description": "Parameters for customizing emails. If not provided, the default email will be used. Note that `app_name` is required." + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Optional custom email address from which to send the OTP email" + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Optional custom sender name for use with sendFromEmailAddress; if left empty, will default to 'Notifications'" + }, + "replyToEmailAddress": { + "type": "string", + "description": "Optional custom email address to use as reply-to" + } + }, + "required": ["email", "targetPublicKey", "emailCustomization"] + }, + "v1InitUserEmailRecoveryResult": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for the user being recovered." + } + }, + "required": ["userId"] + }, + "v1Intent": { + "type": "object", + "properties": { + "createOrganizationIntent": { + "$ref": "#/definitions/v1CreateOrganizationIntent" + }, + "createAuthenticatorsIntent": { + "$ref": "#/definitions/v1CreateAuthenticatorsIntent" + }, + "createUsersIntent": { + "$ref": "#/definitions/v1CreateUsersIntent" + }, + "createPrivateKeysIntent": { + "$ref": "#/definitions/v1CreatePrivateKeysIntent" + }, + "signRawPayloadIntent": { + "$ref": "#/definitions/v1SignRawPayloadIntent" + }, + "createInvitationsIntent": { + "$ref": "#/definitions/v1CreateInvitationsIntent" + }, + "acceptInvitationIntent": { + "$ref": "#/definitions/v1AcceptInvitationIntent" + }, + "createPolicyIntent": { + "$ref": "#/definitions/v1CreatePolicyIntent" + }, + "disablePrivateKeyIntent": { + "$ref": "#/definitions/v1DisablePrivateKeyIntent" + }, + "deleteUsersIntent": { + "$ref": "#/definitions/v1DeleteUsersIntent" + }, + "deleteAuthenticatorsIntent": { + "$ref": "#/definitions/v1DeleteAuthenticatorsIntent" + }, + "deleteInvitationIntent": { + "$ref": "#/definitions/v1DeleteInvitationIntent" + }, + "deleteOrganizationIntent": { + "$ref": "#/definitions/v1DeleteOrganizationIntent" + }, + "deletePolicyIntent": { + "$ref": "#/definitions/v1DeletePolicyIntent" + }, + "createUserTagIntent": { + "$ref": "#/definitions/v1CreateUserTagIntent" + }, + "deleteUserTagsIntent": { + "$ref": "#/definitions/v1DeleteUserTagsIntent" + }, + "signTransactionIntent": { + "$ref": "#/definitions/v1SignTransactionIntent" + }, + "createApiKeysIntent": { + "$ref": "#/definitions/v1CreateApiKeysIntent" + }, + "deleteApiKeysIntent": { + "$ref": "#/definitions/v1DeleteApiKeysIntent" + }, + "approveActivityIntent": { + "$ref": "#/definitions/v1ApproveActivityIntent" + }, + "rejectActivityIntent": { + "$ref": "#/definitions/v1RejectActivityIntent" + }, + "createPrivateKeyTagIntent": { + "$ref": "#/definitions/v1CreatePrivateKeyTagIntent" + }, + "deletePrivateKeyTagsIntent": { + "$ref": "#/definitions/v1DeletePrivateKeyTagsIntent" + }, + "createPolicyIntentV2": { + "$ref": "#/definitions/v1CreatePolicyIntentV2" + }, + "setPaymentMethodIntent": { + "$ref": "#/definitions/billingSetPaymentMethodIntent" + }, + "activateBillingTierIntent": { + "$ref": "#/definitions/billingActivateBillingTierIntent" + }, + "deletePaymentMethodIntent": { + "$ref": "#/definitions/billingDeletePaymentMethodIntent" + }, + "createPolicyIntentV3": { + "$ref": "#/definitions/v1CreatePolicyIntentV3" + }, + "createApiOnlyUsersIntent": { + "$ref": "#/definitions/v1CreateApiOnlyUsersIntent" + }, + "updateRootQuorumIntent": { + "$ref": "#/definitions/v1UpdateRootQuorumIntent" + }, + "updateUserTagIntent": { + "$ref": "#/definitions/v1UpdateUserTagIntent" + }, + "updatePrivateKeyTagIntent": { + "$ref": "#/definitions/v1UpdatePrivateKeyTagIntent" + }, + "createAuthenticatorsIntentV2": { + "$ref": "#/definitions/v1CreateAuthenticatorsIntentV2" + }, + "acceptInvitationIntentV2": { + "$ref": "#/definitions/v1AcceptInvitationIntentV2" + }, + "createOrganizationIntentV2": { + "$ref": "#/definitions/v1CreateOrganizationIntentV2" + }, + "createUsersIntentV2": { + "$ref": "#/definitions/v1CreateUsersIntentV2" + }, + "createSubOrganizationIntent": { + "$ref": "#/definitions/v1CreateSubOrganizationIntent" + }, + "createSubOrganizationIntentV2": { + "$ref": "#/definitions/v1CreateSubOrganizationIntentV2" + }, + "updateAllowedOriginsIntent": { + "$ref": "#/definitions/v1UpdateAllowedOriginsIntent" + }, + "createPrivateKeysIntentV2": { + "$ref": "#/definitions/v1CreatePrivateKeysIntentV2" + }, + "updateUserIntent": { + "$ref": "#/definitions/v1UpdateUserIntent" + }, + "updatePolicyIntent": { + "$ref": "#/definitions/v1UpdatePolicyIntent" + }, + "setPaymentMethodIntentV2": { + "$ref": "#/definitions/billingSetPaymentMethodIntentV2" + }, + "createSubOrganizationIntentV3": { + "$ref": "#/definitions/v1CreateSubOrganizationIntentV3" + }, + "createWalletIntent": { + "$ref": "#/definitions/v1CreateWalletIntent" + }, + "createWalletAccountsIntent": { + "$ref": "#/definitions/v1CreateWalletAccountsIntent" + }, + "initUserEmailRecoveryIntent": { + "$ref": "#/definitions/v1InitUserEmailRecoveryIntent" + }, + "recoverUserIntent": { + "$ref": "#/definitions/v1RecoverUserIntent" + }, + "setOrganizationFeatureIntent": { + "$ref": "#/definitions/v1SetOrganizationFeatureIntent" + }, + "removeOrganizationFeatureIntent": { + "$ref": "#/definitions/v1RemoveOrganizationFeatureIntent" + }, + "signRawPayloadIntentV2": { + "$ref": "#/definitions/v1SignRawPayloadIntentV2" + }, + "signTransactionIntentV2": { + "$ref": "#/definitions/v1SignTransactionIntentV2" + }, + "exportPrivateKeyIntent": { + "$ref": "#/definitions/v1ExportPrivateKeyIntent" + }, + "exportWalletIntent": { + "$ref": "#/definitions/v1ExportWalletIntent" + }, + "createSubOrganizationIntentV4": { + "$ref": "#/definitions/v1CreateSubOrganizationIntentV4" + }, + "emailAuthIntent": { + "$ref": "#/definitions/v1EmailAuthIntent" + }, + "exportWalletAccountIntent": { + "$ref": "#/definitions/v1ExportWalletAccountIntent" + }, + "initImportWalletIntent": { + "$ref": "#/definitions/v1InitImportWalletIntent" + }, + "importWalletIntent": { + "$ref": "#/definitions/v1ImportWalletIntent" + }, + "initImportPrivateKeyIntent": { + "$ref": "#/definitions/v1InitImportPrivateKeyIntent" + }, + "importPrivateKeyIntent": { + "$ref": "#/definitions/v1ImportPrivateKeyIntent" + }, + "createPoliciesIntent": { + "$ref": "#/definitions/v1CreatePoliciesIntent" + }, + "signRawPayloadsIntent": { + "$ref": "#/definitions/v1SignRawPayloadsIntent" + }, + "createReadOnlySessionIntent": { + "$ref": "#/definitions/v1CreateReadOnlySessionIntent" + }, + "createOauthProvidersIntent": { + "$ref": "#/definitions/v1CreateOauthProvidersIntent" + }, + "deleteOauthProvidersIntent": { + "$ref": "#/definitions/v1DeleteOauthProvidersIntent" + }, + "createSubOrganizationIntentV5": { + "$ref": "#/definitions/v1CreateSubOrganizationIntentV5" + }, + "oauthIntent": { + "$ref": "#/definitions/v1OauthIntent" + }, + "createApiKeysIntentV2": { + "$ref": "#/definitions/v1CreateApiKeysIntentV2" + }, + "createReadWriteSessionIntent": { + "$ref": "#/definitions/v1CreateReadWriteSessionIntent" + }, + "emailAuthIntentV2": { + "$ref": "#/definitions/v1EmailAuthIntentV2" + }, + "createSubOrganizationIntentV6": { + "$ref": "#/definitions/v1CreateSubOrganizationIntentV6" + }, + "deletePrivateKeysIntent": { + "$ref": "#/definitions/v1DeletePrivateKeysIntent" + }, + "deleteWalletsIntent": { + "$ref": "#/definitions/v1DeleteWalletsIntent" + }, + "createReadWriteSessionIntentV2": { + "$ref": "#/definitions/v1CreateReadWriteSessionIntentV2" + }, + "deleteSubOrganizationIntent": { + "$ref": "#/definitions/v1DeleteSubOrganizationIntent" + }, + "initOtpAuthIntent": { + "$ref": "#/definitions/v1InitOtpAuthIntent" + }, + "otpAuthIntent": { + "$ref": "#/definitions/v1OtpAuthIntent" + }, + "createSubOrganizationIntentV7": { + "$ref": "#/definitions/v1CreateSubOrganizationIntentV7" + }, + "updateWalletIntent": { + "$ref": "#/definitions/v1UpdateWalletIntent" + }, + "updatePolicyIntentV2": { + "$ref": "#/definitions/v1UpdatePolicyIntentV2" + }, + "createUsersIntentV3": { + "$ref": "#/definitions/v1CreateUsersIntentV3" + }, + "initOtpAuthIntentV2": { + "$ref": "#/definitions/v1InitOtpAuthIntentV2" + }, + "initOtpIntent": { + "$ref": "#/definitions/v1InitOtpIntent" + }, + "verifyOtpIntent": { + "$ref": "#/definitions/v1VerifyOtpIntent" + }, + "otpLoginIntent": { + "$ref": "#/definitions/v1OtpLoginIntent" + }, + "stampLoginIntent": { + "$ref": "#/definitions/v1StampLoginIntent" + }, + "oauthLoginIntent": { + "$ref": "#/definitions/v1OauthLoginIntent" + }, + "updateUserNameIntent": { + "$ref": "#/definitions/v1UpdateUserNameIntent" + }, + "updateUserEmailIntent": { + "$ref": "#/definitions/v1UpdateUserEmailIntent" + }, + "updateUserPhoneNumberIntent": { + "$ref": "#/definitions/v1UpdateUserPhoneNumberIntent" + }, + "initFiatOnRampIntent": { + "$ref": "#/definitions/v1InitFiatOnRampIntent" + }, + "createSmartContractInterfaceIntent": { + "$ref": "#/definitions/v1CreateSmartContractInterfaceIntent" + }, + "deleteSmartContractInterfaceIntent": { + "$ref": "#/definitions/v1DeleteSmartContractInterfaceIntent" + }, + "enableAuthProxyIntent": { + "$ref": "#/definitions/v1EnableAuthProxyIntent" + }, + "disableAuthProxyIntent": { + "$ref": "#/definitions/v1DisableAuthProxyIntent" + }, + "updateAuthProxyConfigIntent": { + "$ref": "#/definitions/v1UpdateAuthProxyConfigIntent" + }, + "createOauth2CredentialIntent": { + "$ref": "#/definitions/v1CreateOauth2CredentialIntent" + }, + "updateOauth2CredentialIntent": { + "$ref": "#/definitions/v1UpdateOauth2CredentialIntent" + }, + "deleteOauth2CredentialIntent": { + "$ref": "#/definitions/v1DeleteOauth2CredentialIntent" + }, + "oauth2AuthenticateIntent": { + "$ref": "#/definitions/v1Oauth2AuthenticateIntent" + }, + "deleteWalletAccountsIntent": { + "$ref": "#/definitions/v1DeleteWalletAccountsIntent" + }, + "deletePoliciesIntent": { + "$ref": "#/definitions/v1DeletePoliciesIntent" + }, + "ethSendRawTransactionIntent": { + "$ref": "#/definitions/v1EthSendRawTransactionIntent" + }, + "ethSendTransactionIntent": { + "$ref": "#/definitions/v1EthSendTransactionIntent" + }, + "createFiatOnRampCredentialIntent": { + "$ref": "#/definitions/v1CreateFiatOnRampCredentialIntent" + }, + "updateFiatOnRampCredentialIntent": { + "$ref": "#/definitions/v1UpdateFiatOnRampCredentialIntent" + }, + "deleteFiatOnRampCredentialIntent": { + "$ref": "#/definitions/v1DeleteFiatOnRampCredentialIntent" + }, + "emailAuthIntentV3": { + "$ref": "#/definitions/v1EmailAuthIntentV3" + }, + "initUserEmailRecoveryIntentV2": { + "$ref": "#/definitions/v1InitUserEmailRecoveryIntentV2" + }, + "initOtpIntentV2": { + "$ref": "#/definitions/v1InitOtpIntentV2" + }, + "initOtpAuthIntentV3": { + "$ref": "#/definitions/v1InitOtpAuthIntentV3" + }, + "upsertGasUsageConfigIntent": { + "$ref": "#/definitions/v1UpsertGasUsageConfigIntent" + }, + "createTvcAppIntent": { + "$ref": "#/definitions/v1CreateTvcAppIntent" + }, + "createTvcDeploymentIntent": { + "$ref": "#/definitions/v1CreateTvcDeploymentIntent" + }, + "createTvcManifestApprovalsIntent": { + "$ref": "#/definitions/v1CreateTvcManifestApprovalsIntent" + }, + "solSendTransactionIntent": { + "$ref": "#/definitions/v1SolSendTransactionIntent" + }, + "initOtpIntentV3": { + "$ref": "#/definitions/v1InitOtpIntentV3" + }, + "verifyOtpIntentV2": { + "$ref": "#/definitions/v1VerifyOtpIntentV2" + }, + "otpLoginIntentV2": { + "$ref": "#/definitions/v1OtpLoginIntentV2" + }, + "updateOrganizationNameIntent": { + "$ref": "#/definitions/v1UpdateOrganizationNameIntent" + }, + "createSubOrganizationIntentV8": { + "$ref": "#/definitions/v1CreateSubOrganizationIntentV8" + }, + "createOauthProvidersIntentV2": { + "$ref": "#/definitions/v1CreateOauthProvidersIntentV2" + }, + "createUsersIntentV4": { + "$ref": "#/definitions/v1CreateUsersIntentV4" + }, + "createWebhookEndpointIntent": { + "$ref": "#/definitions/v1CreateWebhookEndpointIntent" + }, + "updateWebhookEndpointIntent": { + "$ref": "#/definitions/v1UpdateWebhookEndpointIntent" + }, + "deleteWebhookEndpointIntent": { + "$ref": "#/definitions/v1DeleteWebhookEndpointIntent" + }, + "setIpAllowlistIntent": { + "$ref": "#/definitions/v1SetIpAllowlistIntent" + }, + "removeIpAllowlistIntent": { + "$ref": "#/definitions/v1RemoveIpAllowlistIntent" + }, + "updateTvcAppLiveDeploymentIntent": { + "$ref": "#/definitions/v1UpdateTvcAppLiveDeploymentIntent" + }, + "deleteTvcDeploymentIntent": { + "$ref": "#/definitions/v1DeleteTvcDeploymentIntent" + }, + "deleteTvcAppAndDeploymentsIntent": { + "$ref": "#/definitions/v1DeleteTvcAppAndDeploymentsIntent" + }, + "restoreTvcDeploymentIntent": { + "$ref": "#/definitions/v1RestoreTvcDeploymentIntent" + }, + "sparkSignFrostIntent": { + "$ref": "#/definitions/v1SparkSignFrostIntent" + }, + "sparkPrepareTransferIntent": { + "$ref": "#/definitions/v1SparkPrepareTransferIntent" + }, + "sparkClaimTransferIntent": { + "$ref": "#/definitions/v1SparkClaimTransferIntent" + }, + "sparkPrepareLightningReceiveIntent": { + "$ref": "#/definitions/v1SparkPrepareLightningReceiveIntent" + }, + "postTvcQuorumKeyShareIntent": { + "$ref": "#/definitions/v1PostTvcQuorumKeyShareIntent" + }, + "ethSendTransactionIntentV2": { + "$ref": "#/definitions/v1EthSendTransactionIntentV2" + }, + "createMfaPolicyIntent": { + "$ref": "#/definitions/v1CreateMfaPolicyIntent" + }, + "updateMfaPolicyIntent": { + "$ref": "#/definitions/v1UpdateMfaPolicyIntent" + }, + "deleteMfaPolicyIntent": { + "$ref": "#/definitions/v1DeleteMfaPolicyIntent" + }, + "createSessionProfileIntent": { + "$ref": "#/definitions/v1CreateSessionProfileIntent" + }, + "earnDeployWrapperIntent": { + "$ref": "#/definitions/v1EarnDeployWrapperIntent" + }, + "earnDepositIntent": { + "$ref": "#/definitions/v1EarnDepositIntent" + }, + "earnWithdrawIntent": { + "$ref": "#/definitions/v1EarnWithdrawIntent" + }, + "executeSwapIntent": { + "$ref": "#/definitions/v1ExecuteSwapIntent" + }, + "upsertSwapConfigIntent": { + "$ref": "#/definitions/v1UpsertSwapConfigIntent" + }, + "createTvcOperatorIntent": { + "$ref": "#/definitions/v1CreateTvcOperatorIntent" + }, + "createTvcQuorumKeyIntent": { + "$ref": "#/definitions/v1CreateTvcQuorumKeyIntent" + }, + "reEncryptTvcQuorumKeyShareIntent": { + "$ref": "#/definitions/v1ReEncryptTvcQuorumKeyShareIntent" + }, + "initImportSecretsIntent": { + "$ref": "#/definitions/v1InitImportSecretsIntent" + }, + "solSendTransactionIntentV2": { + "$ref": "#/definitions/v1SolSendTransactionIntentV2" + }, + "claimSwapFeesIntent": { + "$ref": "#/definitions/v1ClaimSwapFeesIntent" + }, + "earnSetWrapperStateIntent": { + "$ref": "#/definitions/v1EarnSetWrapperStateIntent" + }, + "claimEarnFeesIntent": { + "$ref": "#/definitions/v1ClaimEarnFeesIntent" + }, + "updateWalletAccountNameIntent": { + "$ref": "#/definitions/v1UpdateWalletAccountNameIntent" + }, + "ethUndelegate7702Intent": { + "$ref": "#/definitions/v1EthUndelegate7702Intent" + }, + "executeSwapIntentV2": { + "$ref": "#/definitions/v1ExecuteSwapIntentV2" + }, + "createSwapQuoteIntent": { + "$ref": "#/definitions/v1CreateSwapQuoteIntent" + }, + "importSecretsIntent": { + "$ref": "#/definitions/v1ImportSecretsIntent" + }, + "exportSecretsIntent": { + "$ref": "#/definitions/v1ExportSecretsIntent" + }, + "createVelocityControlIntent": { + "$ref": "#/definitions/v1CreateVelocityControlIntent" + }, + "deleteVelocityControlsIntent": { + "$ref": "#/definitions/v1DeleteVelocityControlsIntent" + }, + "updatePaymentMethodIntent": { + "$ref": "#/definitions/billingUpdatePaymentMethodIntent" + }, + "createSwapQuoteIntentV2": { + "$ref": "#/definitions/v1CreateSwapQuoteIntentV2" + }, + "executeSwapIntentV3": { + "$ref": "#/definitions/v1ExecuteSwapIntentV3" + }, + "deleteSecretsIntent": { + "$ref": "#/definitions/v1DeleteSecretsIntent" + }, + "earnClaimRewardsIntent": { + "$ref": "#/definitions/v1EarnClaimRewardsIntent" + }, + "createSwapQuoteIntentV3": { + "$ref": "#/definitions/v1CreateSwapQuoteIntentV3" + }, + "upsertSwapFeeSponsorshipLimitConfigIntent": { + "$ref": "#/definitions/v1UpsertSwapFeeSponsorshipLimitConfigIntent" + }, + "upsertSwapFixedRateLimitConfigIntent": { + "$ref": "#/definitions/v1UpsertSwapFixedRateLimitConfigIntent" + } + } + }, + "v1InvitationParams": { + "type": "object", + "properties": { + "receiverUserName": { + "type": "string", + "description": "The name of the intended Invitation recipient." + }, + "receiverUserEmail": { + "type": "string", + "description": "The email address of the intended Invitation recipient." + }, + "receiverUserTags": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of tags assigned to the Invitation recipient. This field, if not needed, should be an empty array in your request body." + }, + "accessType": { + "$ref": "#/definitions/v1AccessType", + "description": "The User's permissible access method(s)." + }, + "senderUserId": { + "type": "string", + "description": "Unique identifier for the Sender of an Invitation." + } + }, + "required": [ + "receiverUserName", + "receiverUserEmail", + "receiverUserTags", + "accessType", + "senderUserId" + ] + }, + "v1IpAllowlistIntentRule": { + "type": "object", + "properties": { + "cidr": { + "type": "string", + "description": "CIDR block (e.g., '192.168.1.0/24', '2001:db8::/32')." + }, + "label": { + "type": "string", + "description": "Optional human-readable label for this rule (e.g., 'Office VPN')." + } + }, + "required": ["cidr"] + }, + "v1KeyValue": { + "type": "object", + "properties": { + "key": { + "type": "string" + }, + "value": { + "type": "string" + } + } + }, + "v1MfaPolicy": { + "type": "object", + "properties": { + "mfaPolicyId": { + "type": "string", + "description": "Unique identifier for a given MFA Policy." + }, + "mfaPolicyName": { + "type": "string", + "description": "Human-readable name for an MFA Policy." + }, + "condition": { + "type": "string", + "description": "A condition expression that evaluates to true or false, determining when this MFA policy applies." + }, + "requiredAuthenticationMethods": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RequiredAuthenticationMethod" + }, + "description": "An ordered list of authentication requirements. Each requirement must be satisfied sequentially to complete MFA." + }, + "order": { + "type": "integer", + "format": "int64", + "description": "The order in which this policy is evaluated relative to other MFA policies." + }, + "notes": { + "type": "string", + "description": "Optional human-readable notes added by a User to describe a particular MFA policy." + }, + "createdAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "updatedAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + } + }, + "required": [ + "mfaPolicyId", + "mfaPolicyName", + "condition", + "requiredAuthenticationMethods", + "order", + "createdAt", + "updatedAt" + ] + }, + "v1MnemonicLanguage": { + "type": "string", + "enum": [ + "MNEMONIC_LANGUAGE_ENGLISH", + "MNEMONIC_LANGUAGE_SIMPLIFIED_CHINESE", + "MNEMONIC_LANGUAGE_TRADITIONAL_CHINESE", + "MNEMONIC_LANGUAGE_CZECH", + "MNEMONIC_LANGUAGE_FRENCH", + "MNEMONIC_LANGUAGE_ITALIAN", + "MNEMONIC_LANGUAGE_JAPANESE", + "MNEMONIC_LANGUAGE_KOREAN", + "MNEMONIC_LANGUAGE_SPANISH" + ] + }, + "v1Oauth2AuthenticateIntent": { + "type": "object", + "properties": { + "oauth2CredentialId": { + "type": "string", + "description": "The OAuth 2.0 credential id whose client_id and client_secret will be used in the OAuth 2.0 flow" + }, + "authCode": { + "type": "string", + "description": "The auth_code provided by the OAuth 2.0 provider to the end user to be exchanged for a Bearer token in the OAuth 2.0 flow" + }, + "redirectUri": { + "type": "string", + "description": "The URI the user is redirected to after they have authenticated with the OAuth 2.0 provider" + }, + "codeVerifier": { + "type": "string", + "description": "The code verifier used by OAuth 2.0 PKCE providers" + }, + "nonce": { + "type": "string", + "description": "A nonce value set to sha256(publicKey), used to bind the OIDC token to a specific public key" + }, + "bearerTokenTargetPublicKey": { + "type": "string", + "description": "An optional P256 public key to which, if provided, the bearer token will be encrypted and returned via the `encrypted_bearer_token` claim of the OIDC Token" + } + }, + "required": [ + "oauth2CredentialId", + "authCode", + "redirectUri", + "codeVerifier", + "nonce" + ] + }, + "v1Oauth2AuthenticateResult": { + "type": "object", + "properties": { + "oidcToken": { + "type": "string", + "description": "Base64 encoded OIDC token issued by Turnkey to be used with the LoginWithOAuth activity" + } + }, + "required": ["oidcToken"] + }, + "v1Oauth2Provider": { + "type": "string", + "enum": ["OAUTH2_PROVIDER_X", "OAUTH2_PROVIDER_DISCORD"] + }, + "v1OauthIntent": { + "type": "object", + "properties": { + "oidcToken": { + "type": "string", + "description": "Base64 encoded OIDC token" + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the oauth bundle (credentials) will be encrypted." + }, + "apiKeyName": { + "type": "string", + "description": "Optional human-readable name for an API Key. If none provided, default to Oauth - \u003cTimestamp\u003e" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the API key is valid for. If not provided, a default of 15 minutes will be used." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated Oauth API keys" + } + }, + "required": ["oidcToken", "targetPublicKey"] + }, + "v1OauthLoginIntent": { + "type": "object", + "properties": { + "oidcToken": { + "type": "string", + "description": "Base64 encoded OIDC token" + }, + "publicKey": { + "type": "string", + "description": "Client-side public key generated by the user, which will be conditionally added to org data based on the validity of the oidc token associated with this request" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the Session is valid for. If not provided, a default of 15 minutes will be used." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated Login API keys" + }, + "sessionProfileId": { + "type": "string", + "description": "Optional session profile ID to specify which Session Profile to use for this login. If not provided, the default read/write session will be used." + } + }, + "required": ["oidcToken", "publicKey"] + }, + "v1OauthLoginResult": { + "type": "object", + "properties": { + "session": { + "type": "string", + "description": "Signed JWT containing an expiry, public key, session type, user id, and organization id" + } + }, + "required": ["session"] + }, + "v1OauthProvider": { + "type": "object", + "properties": { + "providerId": { + "type": "string", + "description": "Unique identifier for an OAuth Provider" + }, + "providerName": { + "type": "string", + "description": "Human-readable name to identify a Provider." + }, + "issuer": { + "type": "string", + "description": "The issuer of the token, typically a URL indicating the authentication server, e.g https://accounts.google.com" + }, + "audience": { + "type": "string", + "description": "Expected audience ('aud' attribute of the signed token) which represents the app ID" + }, + "subject": { + "type": "string", + "description": "Expected subject ('sub' attribute of the signed token) which represents the user ID" + }, + "createdAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "updatedAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + } + }, + "required": [ + "providerId", + "providerName", + "issuer", + "audience", + "subject", + "createdAt", + "updatedAt" + ] + }, + "v1OauthProviderParams": { + "type": "object", + "properties": { + "providerName": { + "type": "string", + "description": "Human-readable name to identify a Provider." + }, + "oidcToken": { + "type": "string", + "description": "Base64 encoded OIDC token" + } + }, + "required": ["providerName", "oidcToken"] + }, + "v1OauthProviderParamsV2": { + "type": "object", + "properties": { + "providerName": { + "type": "string", + "description": "Human-readable name to identify a Provider." + }, + "oidcToken": { + "type": "string", + "description": "Base64 encoded OIDC token" + }, + "oidcClaims": { + "$ref": "#/definitions/v1OidcClaims", + "description": "OIDC claims (iss, sub, aud) to uniquely identify the user" + } + }, + "required": ["providerName"] + }, + "v1OauthResult": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for the authenticating User." + }, + "apiKeyId": { + "type": "string", + "description": "Unique identifier for the created API key." + }, + "credentialBundle": { + "type": "string", + "description": "HPKE encrypted credential bundle" + } + }, + "required": ["userId", "apiKeyId", "credentialBundle"] + }, + "v1OidcClaims": { + "type": "object", + "properties": { + "iss": { + "type": "string", + "description": "The issuer identifier from the OIDC token (iss claim)" + }, + "sub": { + "type": "string", + "description": "The subject identifier from the OIDC token (sub claim)" + }, + "aud": { + "type": "string", + "description": "The audience from the OIDC token (aud claim)" + } + }, + "required": ["iss", "sub", "aud"] + }, + "v1Operator": { + "type": "string", + "enum": [ + "OPERATOR_EQUAL", + "OPERATOR_MORE_THAN", + "OPERATOR_MORE_THAN_OR_EQUAL", + "OPERATOR_LESS_THAN", + "OPERATOR_LESS_THAN_OR_EQUAL", + "OPERATOR_CONTAINS", + "OPERATOR_NOT_EQUAL", + "OPERATOR_IN", + "OPERATOR_NOT_IN", + "OPERATOR_CONTAINS_ONE", + "OPERATOR_CONTAINS_ALL" + ] + }, + "v1OtpAuthIntent": { + "type": "object", + "properties": { + "otpId": { + "type": "string", + "description": "ID representing the result of an init OTP activity." + }, + "otpCode": { + "type": "string", + "description": "OTP sent out to a user's contact (email or SMS)" + }, + "targetPublicKey": { + "type": "string", + "description": "Client-side public key generated by the user, to which the OTP bundle (credentials) will be encrypted." + }, + "apiKeyName": { + "type": "string", + "description": "Optional human-readable name for an API Key. If none provided, default to OTP Auth - \u003cTimestamp\u003e" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the API key is valid for. If not provided, a default of 15 minutes will be used." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated OTP Auth API keys" + } + }, + "required": ["otpId", "otpCode", "targetPublicKey"] + }, + "v1OtpAuthResult": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for the authenticating User." + }, + "apiKeyId": { + "type": "string", + "description": "Unique identifier for the created API key." + }, + "credentialBundle": { + "type": "string", + "description": "HPKE encrypted credential bundle" + } + }, + "required": ["userId"] + }, + "v1OtpLoginIntent": { + "type": "object", + "properties": { + "verificationToken": { + "type": "string", + "description": "Signed JWT containing a unique id, expiry, verification type, contact" + }, + "publicKey": { + "type": "string", + "description": "Client-side public key generated by the user, which will be conditionally added to org data based on the validity of the verification token" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the Session is valid for. If not provided, a default of 15 minutes will be used." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated Login API keys" + }, + "clientSignature": { + "$ref": "#/definitions/v1ClientSignature", + "description": "Optional signature proving authorization for this login. The signature is over the verification token ID and the public key. Only required if a public key was provided during the verification step." + }, + "sessionProfileId": { + "type": "string", + "description": "Optional session profile ID to specify which Session Profile to use for this login. If not provided, the default read/write session will be used." + } + }, + "required": ["verificationToken", "publicKey"] + }, + "v1OtpLoginIntentV2": { + "type": "object", + "properties": { + "verificationToken": { + "type": "string", + "description": "Signed Verification Token containing a unique id, expiry, verification type, contact" + }, + "publicKey": { + "type": "string", + "description": "Client-side public key generated by the user, used as the session public key upon successful login" + }, + "clientSignature": { + "$ref": "#/definitions/v1ClientSignature", + "description": "Required signature proving authorization for this login. The signature is over the verification token ID and the public key. Required for secure OTP login process." + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the Session is valid for. If not provided, a default of 15 minutes will be used." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated Login sessions" + }, + "sessionProfileId": { + "type": "string", + "description": "Optional session profile ID to specify which Session Profile to use for this login. If not provided, the default read/write session will be used." + } + }, + "required": ["verificationToken", "publicKey", "clientSignature"] + }, + "v1OtpLoginResult": { + "type": "object", + "properties": { + "session": { + "type": "string", + "description": "Signed JWT containing an expiry, public key, session type, user id, and organization id" + } + }, + "required": ["session"] + }, + "v1PathFormat": { + "type": "string", + "enum": ["PATH_FORMAT_BIP32"] + }, + "v1PostTvcQuorumKeyShareIntent": { + "type": "object", + "properties": { + "deploymentId": { + "type": "string", + "description": "Unique identifier of the TVC deployment receiving quorum key share" + }, + "ephemeralPublicKeyHex": { + "type": "string", + "description": "Hex-encoded ephemeral public key used to encrypt the quorum key share" + }, + "shareApprovalBundle": { + "$ref": "#/definitions/v1QuorumKeyShareApprovalBundle", + "description": "Re-encrypted quorum key share and approval" + } + }, + "required": [ + "deploymentId", + "ephemeralPublicKeyHex", + "shareApprovalBundle" + ] + }, + "v1PostTvcQuorumKeyShareResult": { + "type": "object", + "properties": { + "provisioningShareId": { + "type": "string", + "description": "The unique identifier for the provisioning quorum key share" + } + }, + "required": ["provisioningShareId"] + }, + "v1PrivateKeyParams": { + "type": "object", + "properties": { + "privateKeyName": { + "type": "string", + "description": "Human-readable name for a Private Key." + }, + "curve": { + "$ref": "#/definitions/v1Curve", + "description": "Cryptographic Curve used to generate a given Private Key." + }, + "privateKeyTags": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Private Key Tag IDs. This field, if not needed, should be an empty array in your request body." + }, + "addressFormats": { + "type": "array", + "items": { + "$ref": "#/definitions/v1AddressFormat" + }, + "description": "Cryptocurrency-specific formats for a derived address (e.g., Ethereum)." + } + }, + "required": [ + "privateKeyName", + "curve", + "privateKeyTags", + "addressFormats" + ] + }, + "v1PrivateKeyResult": { + "type": "object", + "properties": { + "privateKeyId": { + "type": "string" + }, + "addresses": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/immutableactivityv1Address" + } + } + } + }, + "v1PublicKeyCredentialWithAttestation": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "type": { + "type": "string", + "enum": ["public-key"] + }, + "rawId": { + "type": "string" + }, + "authenticatorAttachment": { + "type": "string", + "enum": ["cross-platform", "platform"], + "x-nullable": true + }, + "response": { + "$ref": "#/definitions/v1AuthenticatorAttestationResponse" + }, + "clientExtensionResults": { + "$ref": "#/definitions/v1SimpleClientExtensionResults" + } + }, + "required": ["id", "type", "rawId", "response", "clientExtensionResults"] + }, + "v1QuorumKeyShareApprovalBundle": { + "type": "object", + "properties": { + "operatorId": { + "type": "string", + "description": "Unique identifier of the operator providing this quorum key share" + }, + "reEncryptedShareHex": { + "type": "string", + "description": "Hex-encoded re-encrypted quorum key share" + }, + "signature": { + "type": "string", + "description": "Signature from the share set operator approving the manifest" + } + }, + "required": ["operatorId", "reEncryptedShareHex", "signature"] + }, + "v1ReEncryptTvcQuorumKeyShareIntent": { + "type": "object", + "properties": { + "attestationDocB64": { + "type": "string", + "description": "Base64-encoded attestation document for the TVC deployment provisioning enclave" + }, + "manifestB64": { + "type": "string", + "description": "Base64-encoded manifest for the TVC deployment" + }, + "operatorEncryptKey": { + "type": "string", + "description": "Operator encryption public key used to encrypt the hosted TVC quorum key share" + }, + "operatorSignKey": { + "type": "string", + "description": "Operator signing public key used to approve the TVC manifest" + }, + "deploymentId": { + "type": "string", + "description": "Unique identifier of the TVC deployment receiving the re-encrypted quorum key share" + }, + "appQuorumKey": { + "type": "string", + "description": "Quorum key for the TVC application" + } + }, + "required": [ + "attestationDocB64", + "manifestB64", + "operatorEncryptKey", + "operatorSignKey", + "deploymentId", + "appQuorumKey" + ] + }, + "v1ReEncryptTvcQuorumKeyShareResult": { + "type": "object", + "properties": { + "provisioningShareId": { + "type": "string", + "description": "The unique identifier for the provisioning quorum key share" + } + }, + "required": ["provisioningShareId"] + }, + "v1RecoverUserIntent": { + "type": "object", + "properties": { + "authenticator": { + "$ref": "#/definitions/v1AuthenticatorParamsV2", + "description": "The new authenticator to register." + }, + "userId": { + "type": "string", + "description": "Unique identifier for the user performing recovery." + } + }, + "required": ["authenticator", "userId"] + }, + "v1RecoverUserResult": { + "type": "object", + "properties": { + "authenticatorId": { + "type": "array", + "items": { + "type": "string" + }, + "description": "ID of the authenticator created." + } + }, + "required": ["authenticatorId"] + }, + "v1RejectActivityIntent": { + "type": "object", + "properties": { + "fingerprint": { + "type": "string", + "description": "An artifact verifying a User's action." + } + }, + "required": ["fingerprint"] + }, + "v1RemoveIpAllowlistIntent": { + "type": "object", + "properties": { + "publicKey": { + "type": "string", + "description": "The public component of an API key. If null, removes the organization-level IP allowlist. If set, removes the IP allowlist for this specific API key." + } + } + }, + "v1RemoveIpAllowlistResult": { + "type": "object" + }, + "v1RemoveOrganizationFeatureIntent": { + "type": "object", + "properties": { + "name": { + "$ref": "#/definitions/v1FeatureName", + "description": "Name of the feature to remove" + } + }, + "required": ["name"] + }, + "v1RemoveOrganizationFeatureResult": { + "type": "object", + "properties": { + "features": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1Feature" + }, + "description": "Resulting list of organization features." + } + }, + "required": ["features"] + }, + "v1RequiredAuthenticationMethod": { + "type": "object", + "properties": { + "any": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticationMethod" + }, + "description": "A list of authentication methods for this MFA step. If only one method is provided, it is required. If multiple are provided, the user must satisfy ANY one of them." + } + }, + "required": ["any"] + }, + "v1RequiredAuthenticationMethodParams": { + "type": "object", + "properties": { + "any": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticationMethodParams" + }, + "description": "A list of authentication methods for this MFA step. If only one method is provided, it is required. If multiple are provided, the user must satisfy ANY one of them." + } + }, + "required": ["any"] + }, + "v1RestoreTvcDeploymentIntent": { + "type": "object", + "properties": { + "deploymentId": { + "type": "string", + "description": "The unique identifier of the TVC deployment to restore." + } + }, + "required": ["deploymentId"] + }, + "v1RestoreTvcDeploymentResult": { + "type": "object", + "properties": { + "deploymentId": { + "type": "string", + "description": "The unique identifier of the restored TVC deployment." + } + }, + "required": ["deploymentId"] + }, + "v1Result": { + "type": "object", + "properties": { + "createOrganizationResult": { + "$ref": "#/definitions/v1CreateOrganizationResult" + }, + "createAuthenticatorsResult": { + "$ref": "#/definitions/v1CreateAuthenticatorsResult" + }, + "createUsersResult": { + "$ref": "#/definitions/v1CreateUsersResult" + }, + "createPrivateKeysResult": { + "$ref": "#/definitions/v1CreatePrivateKeysResult" + }, + "createInvitationsResult": { + "$ref": "#/definitions/v1CreateInvitationsResult" + }, + "acceptInvitationResult": { + "$ref": "#/definitions/v1AcceptInvitationResult" + }, + "signRawPayloadResult": { + "$ref": "#/definitions/v1SignRawPayloadResult" + }, + "createPolicyResult": { + "$ref": "#/definitions/v1CreatePolicyResult" + }, + "disablePrivateKeyResult": { + "$ref": "#/definitions/v1DisablePrivateKeyResult" + }, + "deleteUsersResult": { + "$ref": "#/definitions/v1DeleteUsersResult" + }, + "deleteAuthenticatorsResult": { + "$ref": "#/definitions/v1DeleteAuthenticatorsResult" + }, + "deleteInvitationResult": { + "$ref": "#/definitions/v1DeleteInvitationResult" + }, + "deleteOrganizationResult": { + "$ref": "#/definitions/v1DeleteOrganizationResult" + }, + "deletePolicyResult": { + "$ref": "#/definitions/v1DeletePolicyResult" + }, + "createUserTagResult": { + "$ref": "#/definitions/v1CreateUserTagResult" + }, + "deleteUserTagsResult": { + "$ref": "#/definitions/v1DeleteUserTagsResult" + }, + "signTransactionResult": { + "$ref": "#/definitions/v1SignTransactionResult" + }, + "deleteApiKeysResult": { + "$ref": "#/definitions/v1DeleteApiKeysResult" + }, + "createApiKeysResult": { + "$ref": "#/definitions/v1CreateApiKeysResult" + }, + "createPrivateKeyTagResult": { + "$ref": "#/definitions/v1CreatePrivateKeyTagResult" + }, + "deletePrivateKeyTagsResult": { + "$ref": "#/definitions/v1DeletePrivateKeyTagsResult" + }, + "setPaymentMethodResult": { + "$ref": "#/definitions/billingSetPaymentMethodResult" + }, + "activateBillingTierResult": { + "$ref": "#/definitions/billingActivateBillingTierResult" + }, + "deletePaymentMethodResult": { + "$ref": "#/definitions/billingDeletePaymentMethodResult" + }, + "createApiOnlyUsersResult": { + "$ref": "#/definitions/v1CreateApiOnlyUsersResult" + }, + "updateRootQuorumResult": { + "$ref": "#/definitions/v1UpdateRootQuorumResult" + }, + "updateUserTagResult": { + "$ref": "#/definitions/v1UpdateUserTagResult" + }, + "updatePrivateKeyTagResult": { + "$ref": "#/definitions/v1UpdatePrivateKeyTagResult" + }, + "createSubOrganizationResult": { + "$ref": "#/definitions/v1CreateSubOrganizationResult" + }, + "updateAllowedOriginsResult": { + "$ref": "#/definitions/v1UpdateAllowedOriginsResult" + }, + "createPrivateKeysResultV2": { + "$ref": "#/definitions/v1CreatePrivateKeysResultV2" + }, + "updateUserResult": { + "$ref": "#/definitions/v1UpdateUserResult" + }, + "updatePolicyResult": { + "$ref": "#/definitions/v1UpdatePolicyResult" + }, + "createSubOrganizationResultV3": { + "$ref": "#/definitions/v1CreateSubOrganizationResultV3" + }, + "createWalletResult": { + "$ref": "#/definitions/v1CreateWalletResult" + }, + "createWalletAccountsResult": { + "$ref": "#/definitions/v1CreateWalletAccountsResult" + }, + "initUserEmailRecoveryResult": { + "$ref": "#/definitions/v1InitUserEmailRecoveryResult" + }, + "recoverUserResult": { + "$ref": "#/definitions/v1RecoverUserResult" + }, + "setOrganizationFeatureResult": { + "$ref": "#/definitions/v1SetOrganizationFeatureResult" + }, + "removeOrganizationFeatureResult": { + "$ref": "#/definitions/v1RemoveOrganizationFeatureResult" + }, + "exportPrivateKeyResult": { + "$ref": "#/definitions/v1ExportPrivateKeyResult" + }, + "exportWalletResult": { + "$ref": "#/definitions/v1ExportWalletResult" + }, + "createSubOrganizationResultV4": { + "$ref": "#/definitions/v1CreateSubOrganizationResultV4" + }, + "emailAuthResult": { + "$ref": "#/definitions/v1EmailAuthResult" + }, + "exportWalletAccountResult": { + "$ref": "#/definitions/v1ExportWalletAccountResult" + }, + "initImportWalletResult": { + "$ref": "#/definitions/v1InitImportWalletResult" + }, + "importWalletResult": { + "$ref": "#/definitions/v1ImportWalletResult" + }, + "initImportPrivateKeyResult": { + "$ref": "#/definitions/v1InitImportPrivateKeyResult" + }, + "importPrivateKeyResult": { + "$ref": "#/definitions/v1ImportPrivateKeyResult" + }, + "createPoliciesResult": { + "$ref": "#/definitions/v1CreatePoliciesResult" + }, + "signRawPayloadsResult": { + "$ref": "#/definitions/v1SignRawPayloadsResult" + }, + "createReadOnlySessionResult": { + "$ref": "#/definitions/v1CreateReadOnlySessionResult" + }, + "createOauthProvidersResult": { + "$ref": "#/definitions/v1CreateOauthProvidersResult" + }, + "deleteOauthProvidersResult": { + "$ref": "#/definitions/v1DeleteOauthProvidersResult" + }, + "createSubOrganizationResultV5": { + "$ref": "#/definitions/v1CreateSubOrganizationResultV5" + }, + "oauthResult": { + "$ref": "#/definitions/v1OauthResult" + }, + "createReadWriteSessionResult": { + "$ref": "#/definitions/v1CreateReadWriteSessionResult" + }, + "createSubOrganizationResultV6": { + "$ref": "#/definitions/v1CreateSubOrganizationResultV6" + }, + "deletePrivateKeysResult": { + "$ref": "#/definitions/v1DeletePrivateKeysResult" + }, + "deleteWalletsResult": { + "$ref": "#/definitions/v1DeleteWalletsResult" + }, + "createReadWriteSessionResultV2": { + "$ref": "#/definitions/v1CreateReadWriteSessionResultV2" + }, + "deleteSubOrganizationResult": { + "$ref": "#/definitions/v1DeleteSubOrganizationResult" + }, + "initOtpAuthResult": { + "$ref": "#/definitions/v1InitOtpAuthResult" + }, + "otpAuthResult": { + "$ref": "#/definitions/v1OtpAuthResult" + }, + "createSubOrganizationResultV7": { + "$ref": "#/definitions/v1CreateSubOrganizationResultV7" + }, + "updateWalletResult": { + "$ref": "#/definitions/v1UpdateWalletResult" + }, + "updatePolicyResultV2": { + "$ref": "#/definitions/v1UpdatePolicyResultV2" + }, + "initOtpAuthResultV2": { + "$ref": "#/definitions/v1InitOtpAuthResultV2" + }, + "initOtpResult": { + "$ref": "#/definitions/v1InitOtpResult" + }, + "verifyOtpResult": { + "$ref": "#/definitions/v1VerifyOtpResult" + }, + "otpLoginResult": { + "$ref": "#/definitions/v1OtpLoginResult" + }, + "stampLoginResult": { + "$ref": "#/definitions/v1StampLoginResult" + }, + "oauthLoginResult": { + "$ref": "#/definitions/v1OauthLoginResult" + }, + "updateUserNameResult": { + "$ref": "#/definitions/v1UpdateUserNameResult" + }, + "updateUserEmailResult": { + "$ref": "#/definitions/v1UpdateUserEmailResult" + }, + "updateUserPhoneNumberResult": { + "$ref": "#/definitions/v1UpdateUserPhoneNumberResult" + }, + "initFiatOnRampResult": { + "$ref": "#/definitions/v1InitFiatOnRampResult" + }, + "createSmartContractInterfaceResult": { + "$ref": "#/definitions/v1CreateSmartContractInterfaceResult" + }, + "deleteSmartContractInterfaceResult": { + "$ref": "#/definitions/v1DeleteSmartContractInterfaceResult" + }, + "enableAuthProxyResult": { + "$ref": "#/definitions/v1EnableAuthProxyResult" + }, + "disableAuthProxyResult": { + "$ref": "#/definitions/v1DisableAuthProxyResult" + }, + "updateAuthProxyConfigResult": { + "$ref": "#/definitions/v1UpdateAuthProxyConfigResult" + }, + "createOauth2CredentialResult": { + "$ref": "#/definitions/v1CreateOauth2CredentialResult" + }, + "updateOauth2CredentialResult": { + "$ref": "#/definitions/v1UpdateOauth2CredentialResult" + }, + "deleteOauth2CredentialResult": { + "$ref": "#/definitions/v1DeleteOauth2CredentialResult" + }, + "oauth2AuthenticateResult": { + "$ref": "#/definitions/v1Oauth2AuthenticateResult" + }, + "deleteWalletAccountsResult": { + "$ref": "#/definitions/v1DeleteWalletAccountsResult" + }, + "deletePoliciesResult": { + "$ref": "#/definitions/v1DeletePoliciesResult" + }, + "ethSendRawTransactionResult": { + "$ref": "#/definitions/v1EthSendRawTransactionResult" + }, + "createFiatOnRampCredentialResult": { + "$ref": "#/definitions/v1CreateFiatOnRampCredentialResult" + }, + "updateFiatOnRampCredentialResult": { + "$ref": "#/definitions/v1UpdateFiatOnRampCredentialResult" + }, + "deleteFiatOnRampCredentialResult": { + "$ref": "#/definitions/v1DeleteFiatOnRampCredentialResult" + }, + "ethSendTransactionResult": { + "$ref": "#/definitions/v1EthSendTransactionResult" + }, + "upsertGasUsageConfigResult": { + "$ref": "#/definitions/v1UpsertGasUsageConfigResult" + }, + "createTvcAppResult": { + "$ref": "#/definitions/v1CreateTvcAppResult" + }, + "createTvcDeploymentResult": { + "$ref": "#/definitions/v1CreateTvcDeploymentResult" + }, + "createTvcManifestApprovalsResult": { + "$ref": "#/definitions/v1CreateTvcManifestApprovalsResult" + }, + "solSendTransactionResult": { + "$ref": "#/definitions/v1SolSendTransactionResult" + }, + "initOtpResultV2": { + "$ref": "#/definitions/v1InitOtpResultV2" + }, + "updateOrganizationNameResult": { + "$ref": "#/definitions/v1UpdateOrganizationNameResult" + }, + "createSubOrganizationResultV8": { + "$ref": "#/definitions/v1CreateSubOrganizationResultV8" + }, + "createOauthProvidersResultV2": { + "$ref": "#/definitions/v1CreateOauthProvidersResultV2" + }, + "createWebhookEndpointResult": { + "$ref": "#/definitions/v1CreateWebhookEndpointResult" + }, + "updateWebhookEndpointResult": { + "$ref": "#/definitions/v1UpdateWebhookEndpointResult" + }, + "deleteWebhookEndpointResult": { + "$ref": "#/definitions/v1DeleteWebhookEndpointResult" + }, + "setIpAllowlistResult": { + "$ref": "#/definitions/v1SetIpAllowlistResult" + }, + "removeIpAllowlistResult": { + "$ref": "#/definitions/v1RemoveIpAllowlistResult" + }, + "updateTvcAppLiveDeploymentResult": { + "$ref": "#/definitions/v1UpdateTvcAppLiveDeploymentResult" + }, + "deleteTvcDeploymentResult": { + "$ref": "#/definitions/v1DeleteTvcDeploymentResult" + }, + "deleteTvcAppAndDeploymentsResult": { + "$ref": "#/definitions/v1DeleteTvcAppAndDeploymentsResult" + }, + "restoreTvcDeploymentResult": { + "$ref": "#/definitions/v1RestoreTvcDeploymentResult" + }, + "sparkSignFrostResult": { + "$ref": "#/definitions/v1SparkSignFrostResult" + }, + "sparkPrepareTransferResult": { + "$ref": "#/definitions/v1SparkPrepareTransferResult" + }, + "sparkClaimTransferResult": { + "$ref": "#/definitions/v1SparkClaimTransferResult" + }, + "sparkPrepareLightningReceiveResult": { + "$ref": "#/definitions/v1SparkPrepareLightningReceiveResult" + }, + "postTvcQuorumKeyShareResult": { + "$ref": "#/definitions/v1PostTvcQuorumKeyShareResult" + }, + "ethSendTransactionResultV2": { + "$ref": "#/definitions/v1EthSendTransactionResultV2" + }, + "createMfaPolicyResult": { + "$ref": "#/definitions/v1CreateMfaPolicyResult" + }, + "updateMfaPolicyResult": { + "$ref": "#/definitions/v1UpdateMfaPolicyResult" + }, + "deleteMfaPolicyResult": { + "$ref": "#/definitions/v1DeleteMfaPolicyResult" + }, + "createSessionProfileResult": { + "$ref": "#/definitions/v1CreateSessionProfileResult" + }, + "earnDeployWrapperResult": { + "$ref": "#/definitions/v1EarnDeployWrapperResult" + }, + "earnDepositResult": { + "$ref": "#/definitions/v1EarnDepositResult" + }, + "earnWithdrawResult": { + "$ref": "#/definitions/v1EarnWithdrawResult" + }, + "executeSwapResult": { + "$ref": "#/definitions/v1ExecuteSwapResult" + }, + "upsertSwapConfigResult": { + "$ref": "#/definitions/v1UpsertSwapConfigResult" + }, + "createTvcOperatorResult": { + "$ref": "#/definitions/v1CreateTvcOperatorResult" + }, + "createTvcQuorumKeyResult": { + "$ref": "#/definitions/v1CreateTvcQuorumKeyResult" + }, + "reEncryptTvcQuorumKeyShareResult": { + "$ref": "#/definitions/v1ReEncryptTvcQuorumKeyShareResult" + }, + "initImportSecretsResult": { + "$ref": "#/definitions/v1InitImportSecretsResult" + }, + "solSendTransactionResultV2": { + "$ref": "#/definitions/v1SolSendTransactionResultV2" + }, + "claimSwapFeesResult": { + "$ref": "#/definitions/v1ClaimSwapFeesResult" + }, + "earnSetWrapperStateResult": { + "$ref": "#/definitions/v1EarnSetWrapperStateResult" + }, + "claimEarnFeesResult": { + "$ref": "#/definitions/v1ClaimEarnFeesResult" + }, + "updateWalletAccountNameResult": { + "$ref": "#/definitions/v1UpdateWalletAccountNameResult" + }, + "ethUndelegate7702Result": { + "$ref": "#/definitions/v1EthUndelegate7702Result" + }, + "createSwapQuoteResult": { + "$ref": "#/definitions/v1CreateSwapQuoteResult" + }, + "importSecretsResult": { + "$ref": "#/definitions/v1ImportSecretsResult" + }, + "exportSecretsResult": { + "$ref": "#/definitions/v1ExportSecretsResult" + }, + "createVelocityControlResult": { + "$ref": "#/definitions/v1CreateVelocityControlResult" + }, + "deleteVelocityControlsResult": { + "$ref": "#/definitions/v1DeleteVelocityControlsResult" + }, + "updatePaymentMethodResult": { + "$ref": "#/definitions/billingUpdatePaymentMethodResult" + }, + "deleteSecretsResult": { + "$ref": "#/definitions/v1DeleteSecretsResult" + }, + "earnClaimRewardsResult": { + "$ref": "#/definitions/v1EarnClaimRewardsResult" + }, + "createSwapQuoteResultV2": { + "$ref": "#/definitions/v1CreateSwapQuoteResultV2" + }, + "upsertSwapFeeSponsorshipLimitConfigResult": { + "$ref": "#/definitions/v1UpsertSwapFeeSponsorshipLimitConfigResult" + }, + "upsertSwapFixedRateLimitConfigResult": { + "$ref": "#/definitions/v1UpsertSwapFixedRateLimitConfigResult" + } + } + }, + "v1RootUserParams": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/apiApiKeyParams" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParamsV2" + }, + "description": "A list of Authenticator parameters. This field, if not needed, should be an empty array in your request body." + } + }, + "required": ["userName", "apiKeys", "authenticators"] + }, + "v1RootUserParamsV2": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/apiApiKeyParams" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParamsV2" + }, + "description": "A list of Authenticator parameters. This field, if not needed, should be an empty array in your request body." + }, + "oauthProviders": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1OauthProviderParams" + }, + "description": "A list of Oauth providers. This field, if not needed, should be an empty array in your request body." + } + }, + "required": ["userName", "apiKeys", "authenticators", "oauthProviders"] + }, + "v1RootUserParamsV3": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ApiKeyParamsV2" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParamsV2" + }, + "description": "A list of Authenticator parameters. This field, if not needed, should be an empty array in your request body." + }, + "oauthProviders": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1OauthProviderParams" + }, + "description": "A list of Oauth providers. This field, if not needed, should be an empty array in your request body." + } + }, + "required": ["userName", "apiKeys", "authenticators", "oauthProviders"] + }, + "v1RootUserParamsV4": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "userPhoneNumber": { + "type": "string", + "description": "The user's phone number in E.164 format e.g. +13214567890" + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ApiKeyParamsV2" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParamsV2" + }, + "description": "A list of Authenticator parameters. This field, if not needed, should be an empty array in your request body." + }, + "oauthProviders": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1OauthProviderParams" + }, + "description": "A list of Oauth providers. This field, if not needed, should be an empty array in your request body." + } + }, + "required": ["userName", "apiKeys", "authenticators", "oauthProviders"] + }, + "v1RootUserParamsV5": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "userPhoneNumber": { + "type": "string", + "description": "The user's phone number in E.164 format e.g. +13214567890" + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ApiKeyParamsV2" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParamsV2" + }, + "description": "A list of Authenticator parameters. This field, if not needed, should be an empty array in your request body." + }, + "oauthProviders": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1OauthProviderParamsV2" + }, + "description": "A list of Oauth providers. This field, if not needed, should be an empty array in your request body." + } + }, + "required": ["userName", "apiKeys", "authenticators", "oauthProviders"] + }, + "v1Selector": { + "type": "object", + "properties": { + "subject": { + "type": "string" + }, + "operator": { + "$ref": "#/definitions/v1Operator" + }, + "target": { + "type": "string" + } + } + }, + "v1SelectorV2": { + "type": "object", + "properties": { + "subject": { + "type": "string" + }, + "operator": { + "$ref": "#/definitions/v1Operator" + }, + "targets": { + "type": "array", + "items": { + "type": "string" + } + } + } + }, + "v1SetIpAllowlistIntent": { + "type": "object", + "properties": { + "publicKey": { + "type": "string", + "description": "The public component of an API key. If null, the IP allowlist applies at the organization level. If set, it applies only to this specific API key." + }, + "enabled": { + "type": "boolean", + "description": "Whether the IP allowlist is enabled. Only meaningful for organization-level allowlists. Omit for API key-level allowlists." + }, + "rules": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1IpAllowlistIntentRule" + }, + "description": "List of IP allowlist rules with CIDR blocks and optional labels." + }, + "onEvaluationError": { + "type": "string", + "description": "Behavior when an error occurs during IP allowlist evaluation. Valid values: ALLOW, DENY. Defaults to DENY." + } + } + }, + "v1SetIpAllowlistResult": { + "type": "object" + }, + "v1SetOrganizationFeatureIntent": { + "type": "object", + "properties": { + "name": { + "$ref": "#/definitions/v1FeatureName", + "description": "Name of the feature to set" + }, + "value": { + "type": "string", + "description": "Optional value for the feature. Will override existing values if feature is already set." + } + }, + "required": ["name", "value"] + }, + "v1SetOrganizationFeatureResult": { + "type": "object", + "properties": { + "features": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1Feature" + }, + "description": "Resulting list of organization features." + } + }, + "required": ["features"] + }, + "v1SignRawPayloadIntent": { + "type": "object", + "properties": { + "privateKeyId": { + "type": "string", + "description": "Unique identifier for a given Private Key." + }, + "payload": { + "type": "string", + "description": "Raw unsigned payload to be signed." + }, + "encoding": { + "$ref": "#/definitions/immutablecommonv1PayloadEncoding", + "description": "Encoding of the `payload` string. Turnkey uses this information to convert `payload` into bytes with the correct decoder (e.g. hex, utf8)." + }, + "hashFunction": { + "$ref": "#/definitions/immutablecommonv1HashFunction", + "description": "Hash function to apply to payload bytes before signing. This field must be set to HASH_FUNCTION_NOT_APPLICABLE for EdDSA/ed25519 signature requests; configurable payload hashing is not supported by RFC 8032." + } + }, + "required": ["privateKeyId", "payload", "encoding", "hashFunction"] + }, + "v1SignRawPayloadIntentV2": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "A Wallet account address, Private Key address, or Private Key identifier." + }, + "payload": { + "type": "string", + "description": "Raw unsigned payload to be signed." + }, + "encoding": { + "$ref": "#/definitions/immutablecommonv1PayloadEncoding", + "description": "Encoding of the `payload` string. Turnkey uses this information to convert `payload` into bytes with the correct decoder (e.g. hex, utf8)." + }, + "hashFunction": { + "$ref": "#/definitions/immutablecommonv1HashFunction", + "description": "Hash function to apply to payload bytes before signing. This field must be set to HASH_FUNCTION_NOT_APPLICABLE for EdDSA/ed25519 signature requests; configurable payload hashing is not supported by RFC 8032." + } + }, + "required": ["signWith", "payload", "encoding", "hashFunction"] + }, + "v1SignRawPayloadResult": { + "type": "object", + "properties": { + "r": { + "type": "string", + "description": "Component of a cryptographic signature, meaning varies based on signing scheme." + }, + "s": { + "type": "string", + "description": "Component of a cryptographic signature, meaning varies based on signing scheme." + }, + "v": { + "type": "string", + "description": "Recovery ID for ECDSA signatures, \"00\" otherwise." + } + }, + "required": ["r", "s", "v"] + }, + "v1SignRawPayloadsIntent": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "A Wallet account address, Private Key address, or Private Key identifier." + }, + "payloads": { + "type": "array", + "items": { + "type": "string" + }, + "description": "An array of raw unsigned payloads to be signed." + }, + "encoding": { + "$ref": "#/definitions/immutablecommonv1PayloadEncoding", + "description": "Encoding of the `payload` string. Turnkey uses this information to convert `payload` into bytes with the correct decoder (e.g. hex, utf8)." + }, + "hashFunction": { + "$ref": "#/definitions/immutablecommonv1HashFunction", + "description": "Hash function to apply to payload bytes before signing. This field must be set to HASH_FUNCTION_NOT_APPLICABLE for EdDSA/ed25519 signature requests; configurable payload hashing is not supported by RFC 8032." + } + }, + "required": ["signWith", "payloads", "encoding", "hashFunction"] + }, + "v1SignRawPayloadsResult": { + "type": "object", + "properties": { + "signatures": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SignRawPayloadResult" + } + } + } + }, + "v1SignTransactionIntent": { + "type": "object", + "properties": { + "privateKeyId": { + "type": "string", + "description": "Unique identifier for a given Private Key." + }, + "unsignedTransaction": { + "type": "string", + "description": "Raw unsigned transaction to be signed by a particular Private Key." + }, + "type": { + "$ref": "#/definitions/v1TransactionType" + } + }, + "required": ["privateKeyId", "unsignedTransaction", "type"] + }, + "v1SignTransactionIntentV2": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "A Wallet account address, Private Key address, or Private Key identifier." + }, + "unsignedTransaction": { + "type": "string", + "description": "Raw unsigned transaction to be signed" + }, + "type": { + "$ref": "#/definitions/v1TransactionType" + } + }, + "required": ["signWith", "unsignedTransaction", "type"] + }, + "v1SignTransactionResult": { + "type": "object", + "properties": { + "signedTransaction": { + "type": "string" + } + }, + "required": ["signedTransaction"] + }, + "v1SimpleClientExtensionResults": { + "type": "object", + "properties": { + "appid": { + "type": "boolean" + }, + "appidExclude": { + "type": "boolean" + }, + "credProps": { + "$ref": "#/definitions/v1CredPropsAuthenticationExtensionsClientOutputs" + } + } + }, + "v1SmartContractInterfaceType": { + "type": "string", + "enum": [ + "SMART_CONTRACT_INTERFACE_TYPE_ETHEREUM", + "SMART_CONTRACT_INTERFACE_TYPE_SOLANA" + ] + }, + "v1SmsCustomizationParams": { + "type": "object", + "properties": { + "template": { + "type": "string", + "description": "Template containing references to .OtpCode i.e Your OTP is {{.OtpCode}}" + } + } + }, + "v1SolSendTransactionIntent": { + "type": "object", + "properties": { + "unsignedTransaction": { + "type": "string", + "description": "Hex-encoded serialized unsigned Solana transaction in full wire format. Legacy/V0 transactions allow 1232 bytes. V1 allows 4096 bytes with up to 12 trailing 64-byte signature slots, including the paymaster for sponsored transactions. Fill unsigned slots with zeroes." + }, + "signWith": { + "type": "string", + "description": "A wallet or private key address to sign with. This does not support private key IDs." + }, + "sponsor": { + "type": "boolean", + "description": "Whether to sponsor this transaction via Gas Station." + }, + "caip2": { + "type": "string", + "enum": [ + "solana:mainnet", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdpKuc147dw2N9d", + "solana:devnet", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1wcaWoxPkrZBG" + ], + "description": "CAIP-2 chain ID (e.g., 'solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp' for Solana mainnet). Human-readable Solana aliases ('solana:mainnet', 'solana:devnet') are also accepted and normalized to canonical CAIP-2 values." + }, + "recentBlockhash": { + "type": "string", + "description": "user-provided blockhash for replay protection / deadline control. If omitted and sponsor=true, we fetch a fresh blockhash during execution" + } + }, + "required": ["unsignedTransaction", "signWith", "caip2"] + }, + "v1SolSendTransactionIntentV2": { + "type": "object", + "properties": { + "unsignedTransaction": { + "type": "string", + "description": "Hex-encoded serialized unsigned Solana transaction in full wire format. Legacy/V0 transactions allow 1232 bytes. V1 allows 4096 bytes with up to 12 trailing 64-byte signature slots, including the paymaster for sponsored transactions. Fill unsigned slots with zeroes." + }, + "signWiths": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Ordered Solana signer addresses Turnkey signs with. Between 1 and 16 signers for legacy/V0, or up to 12 for V1 (11 when sponsored). For sponsored transactions this must list every required signer of the transaction in transaction order." + }, + "sponsor": { + "type": "boolean", + "description": "Whether to sponsor this transaction via Gas Station." + }, + "caip2": { + "type": "string", + "enum": [ + "solana:mainnet", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdpKuc147dw2N9d", + "solana:devnet", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1wcaWoxPkrZBG" + ], + "description": "CAIP-2 chain ID (e.g., 'solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp' for Solana mainnet). Human-readable Solana aliases ('solana:mainnet', 'solana:devnet') are also accepted and normalized to canonical CAIP-2 values." + }, + "recentBlockhash": { + "type": "string", + "description": "User-provided blockhash for replay protection / deadline control. If provided, it is used as-is, including for sponsored transactions (the transaction is only broadcastable while the blockhash is current). If omitted and sponsor=true, a fresh blockhash is fetched during execution." + } + }, + "required": ["unsignedTransaction", "signWiths", "caip2"] + }, + "v1SolSendTransactionResult": { + "type": "object", + "properties": { + "sendTransactionStatusId": { + "type": "string", + "description": "The send_transaction_status ID associated with the transaction submission" + } + }, + "required": ["sendTransactionStatusId"] + }, + "v1SolSendTransactionResultV2": { + "type": "object", + "properties": { + "sendTransactionStatusId": { + "type": "string", + "description": "The send_transaction_status ID associated with the transaction submission" + } + }, + "required": ["sendTransactionStatusId"] + }, + "v1SolanaConfig": { + "type": "object", + "properties": { + "rentPrefundEnabled": { + "type": "boolean", + "description": "Whether Solana rent prefunding is enabled for the organization. When omitted, the existing rent-prefund state is left unchanged." + } + } + }, + "v1SparkClaimLeaf": { + "type": "object", + "properties": { + "leafId": { + "type": "string", + "description": "Leaf identifier (UUID)." + }, + "ciphertext": { + "type": "string", + "description": "ECIES ciphertext (hex-encoded) containing the inbound transfer secret. Decrypted inside the enclave using the wallet's Identity key." + }, + "senderSignature": { + "type": "string", + "description": "Hex-encoded 64-byte compact ECDSA signature binding (leaf_id, transfer_id, ciphertext) to the sender's identity key. Verified inside the enclave before decryption." + } + }, + "required": ["leafId", "ciphertext", "senderSignature"] + }, + "v1SparkClaimPackage": { + "type": "object", + "properties": { + "leaves": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkClaimLeaf" + }, + "description": "Leaves being claimed." + }, + "threshold": { + "type": "integer", + "format": "int64", + "description": "Shamir threshold for reconstructing the per-leaf claim secret." + }, + "operatorRecipients": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkOperatorRecipient" + }, + "description": "Operators that will receive Shamir shares." + }, + "transferId": { + "type": "string", + "description": "Spark transfer identifier (UUID). Used together with each leaf's sender_signature to verify the sender bound this ciphertext to this transfer." + }, + "senderIdentityPublicKey": { + "type": "string", + "description": "Sender's compressed secp256k1 identity public key (hex-encoded, 33 bytes). Used to verify the per-leaf sender_signature fields." + } + }, + "required": [ + "leaves", + "threshold", + "operatorRecipients", + "transferId", + "senderIdentityPublicKey" + ] + }, + "v1SparkClaimTransferIntent": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "A Spark wallet account address identifying the wallet." + }, + "claim": { + "$ref": "#/definitions/v1SparkClaimPackage", + "description": "Claim package parameters." + } + }, + "required": ["signWith", "claim"] + }, + "v1SparkClaimTransferResult": { + "type": "object", + "properties": { + "operatorPackages": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkEncryptedOperatorPackage" + }, + "description": "Per-operator ECIES-encrypted packages." + }, + "newLeafPublicKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkLeafPublicKey" + }, + "description": "Newly-derived SigningLeaf public keys, one per leaf, in input order." + } + }, + "required": ["operatorPackages", "newLeafPublicKeys"] + }, + "v1SparkDepositDerivation": { + "type": "object" + }, + "v1SparkEncryptedOperatorPackage": { + "type": "object", + "properties": { + "operatorId": { + "type": "string", + "description": "Spark operator identifier (UUID)." + }, + "encryptedPackage": { + "type": "string", + "description": "ECIES ciphertext (hex-encoded) opaque to Turnkey after emission." + } + }, + "required": ["operatorId", "encryptedPackage"] + }, + "v1SparkFrostCommitment": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "FROST participant identifier, hex-encoded (32-byte scalar)." + }, + "hiding": { + "type": "string", + "description": "Hiding commitment D, hex-encoded compressed secp256k1 point." + }, + "binding": { + "type": "string", + "description": "Binding commitment E, hex-encoded compressed secp256k1 point." + } + }, + "required": ["id", "hiding", "binding"] + }, + "v1SparkHtlcPreimageDerivation": { + "type": "object" + }, + "v1SparkIdentityDerivation": { + "type": "object" + }, + "v1SparkKeyDerivation": { + "type": "object", + "properties": { + "identity": { + "$ref": "#/definitions/v1SparkIdentityDerivation", + "description": "Spark identity key derivation." + }, + "signingLeaf": { + "$ref": "#/definitions/v1SparkSigningLeafDerivation", + "description": "Spark signing leaf key derivation, identified by leaf ID." + }, + "deposit": { + "$ref": "#/definitions/v1SparkDepositDerivation", + "description": "Spark deposit key derivation." + }, + "staticDeposit": { + "$ref": "#/definitions/v1SparkStaticDepositDerivation", + "description": "Spark static deposit key derivation, identified by index." + }, + "htlcPreimage": { + "$ref": "#/definitions/v1SparkHtlcPreimageDerivation", + "description": "Spark HTLC preimage key derivation." + } + } + }, + "v1SparkLeafPublicKey": { + "type": "object", + "properties": { + "leafId": { + "type": "string", + "description": "The Spark leaf_id this public key was derived for." + }, + "publicKey": { + "type": "string", + "description": "Hex-encoded compressed secp256k1 point (33 bytes) for the SigningLeaf derivation at leaf_id." + } + }, + "required": ["leafId", "publicKey"] + }, + "v1SparkLightningReceivePackage": { + "type": "object", + "properties": { + "threshold": { + "type": "integer", + "format": "int64", + "description": "Feldman VSS threshold for reconstructing the preimage." + }, + "operatorRecipients": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkOperatorRecipient" + }, + "description": "Operators that will receive Feldman shares of the preimage. Order must match the operators' numeric IDs in the Spark operator config - share index is the 1-based position in this list." + } + }, + "required": ["threshold", "operatorRecipients"] + }, + "v1SparkOperatorRecipient": { + "type": "object", + "properties": { + "operatorId": { + "type": "string", + "description": "Spark operator identifier (UUID)." + }, + "encryptionPublicKey": { + "type": "string", + "description": "Operator's ECIES encryption pubkey (hex-encoded compressed secp256k1 point)." + } + }, + "required": ["operatorId", "encryptionPublicKey"] + }, + "v1SparkPartialSignature": { + "type": "object", + "properties": { + "signatureShare": { + "type": "string", + "description": "Hex-encoded FROST partial signature." + }, + "hiding": { + "type": "string", + "description": "Turnkey's hiding commitment D (hex-encoded compressed secp256k1 point). Forward to the Spark Operator." + }, + "binding": { + "type": "string", + "description": "Turnkey's binding commitment E (hex-encoded compressed secp256k1 point). Forward to the Spark Operator." + } + }, + "required": ["signatureShare", "hiding", "binding"] + }, + "v1SparkPrepareLightningReceiveIntent": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "A Spark wallet account address identifying the wallet." + }, + "lightningReceive": { + "$ref": "#/definitions/v1SparkLightningReceivePackage", + "description": "Lightning receive package parameters: threshold and operator recipients." + } + }, + "required": ["signWith", "lightningReceive"] + }, + "v1SparkPrepareLightningReceiveResult": { + "type": "object", + "properties": { + "operatorPackages": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkEncryptedOperatorPackage" + }, + "description": "Per-operator ECIES-encrypted Feldman share packages." + }, + "paymentHash": { + "type": "string", + "description": "Hex-encoded SHA256(preimage). Forward to the Lightning node." + } + }, + "required": ["operatorPackages", "paymentHash"] + }, + "v1SparkPrepareTransferIntent": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "A Spark wallet account address identifying the wallet." + }, + "transfer": { + "$ref": "#/definitions/v1SparkTransferPackage", + "description": "Transfer package parameters for HD key tweak splitting." + } + }, + "required": ["signWith", "transfer"] + }, + "v1SparkPrepareTransferResult": { + "type": "object", + "properties": { + "operatorPackages": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkEncryptedOperatorPackage" + }, + "description": "Per-operator ECIES-encrypted packages." + }, + "transferUserSignature": { + "type": "string", + "description": "Hex-encoded ECDSA-DER signature of the TransferPackage signing payload, signed with the wallet's IDENTITY key." + }, + "newLeafPublicKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkLeafPublicKey" + }, + "description": "Newly-derived SigningLeaf public keys, one per leaf, in input order." + } + }, + "required": [ + "operatorPackages", + "transferUserSignature", + "newLeafPublicKeys" + ] + }, + "v1SparkSignFrostIntent": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "A Spark wallet account address identifying the wallet to sign with." + }, + "signatures": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkSignatureRequest" + }, + "description": "Batched sign requests. Each produces a partial signature plus Turnkey's public commitments." + } + }, + "required": ["signWith", "signatures"] + }, + "v1SparkSignFrostResult": { + "type": "object", + "properties": { + "signatures": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkPartialSignature" + }, + "description": "Partial signatures plus Turnkey commitments, one per request, in order." + } + }, + "required": ["signatures"] + }, + "v1SparkSignatureRequest": { + "type": "object", + "properties": { + "derivation": { + "$ref": "#/definitions/v1SparkKeyDerivation", + "description": "Which key to sign with." + }, + "message": { + "type": "string", + "description": "Hex-encoded 32-byte sighash to sign." + }, + "verifyingKey": { + "type": "string", + "description": "Aggregate group verifying key (hex-encoded compressed secp256k1 point), computed as P_ops + P_user. Bound into the nonce HMAC." + }, + "operatorCommitments": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkFrostCommitment" + }, + "description": "Commitments for every non-Turnkey participant. MUST NOT include an entry under Turnkey's identifier. Bound into the nonce HMAC." + }, + "adaptorPublicKey": { + "type": "string", + "description": "Optional adaptor point T (hex-encoded 33-byte compressed secp256k1 pubkey). When set, Turnkey produces a Schnorr adaptor pre-signature with the FROST challenge bound to `R+T` (where `R` is the aggregate group nonce commitment from FROST). The party holding the discrete log `t` completes the pre-sig to a valid BIP-340 signature by adding `t` (or `-t`, for parity) to the signature scalar `s`. This is primarily used by Spark leaves-swap and other adaptor-bound flows; absent or empty leads to plain FROST signing (the typical case)." + } + }, + "required": [ + "derivation", + "message", + "verifyingKey", + "operatorCommitments" + ] + }, + "v1SparkSigningLeafDerivation": { + "type": "object", + "properties": { + "leafId": { + "type": "string", + "description": "Unique identifier for the Spark signing leaf." + } + }, + "required": ["leafId"] + }, + "v1SparkStaticDepositDerivation": { + "type": "object", + "properties": { + "index": { + "type": "integer", + "format": "int64", + "description": "Index used to derive the static deposit key." + } + }, + "required": ["index"] + }, + "v1SparkTransferLeaf": { + "type": "object", + "properties": { + "leafId": { + "type": "string", + "description": "Leaf identifier (UUID)." + }, + "oldLeafDerivation": { + "$ref": "#/definitions/v1SparkKeyDerivation", + "description": "Derivation for the existing (pre-transfer) leaf key. Always a SigningLeaf derivation." + }, + "newLeafDerivation": { + "$ref": "#/definitions/v1SparkKeyDerivation", + "description": "Derivation for the new (post-transfer) leaf key. Always a SigningLeaf derivation. The enclave ECIES-encrypts this private key to receiver_public_key as the per-leaf secret_cipher; HD-derived rather than random so the sender can re-derive on retry (Turnkey's enclave is stateless)." + }, + "refundSignature": { + "type": "string", + "description": "Client-produced CPFP refund signature (hex-encoded), passed through verbatim into the per-operator SendLeafKeyTweak. Empty omits the field from the operator package." + }, + "directRefundSignature": { + "type": "string", + "description": "Client-produced direct refund signature (hex-encoded). Passed through verbatim." + }, + "directFromCpfpRefundSignature": { + "type": "string", + "description": "Client-produced direct-from-CPFP refund signature (hex-encoded). Passed through verbatim." + } + }, + "required": ["leafId", "oldLeafDerivation", "newLeafDerivation"] + }, + "v1SparkTransferPackage": { + "type": "object", + "properties": { + "transferId": { + "type": "string", + "description": "Spark transfer identifier (UUID)." + }, + "leaves": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkTransferLeaf" + }, + "description": "Leaves being transferred." + }, + "threshold": { + "type": "integer", + "format": "int64", + "description": "Feldman VSS threshold for reconstructing the per-leaf tweak scalar." + }, + "operatorRecipients": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SparkOperatorRecipient" + }, + "description": "Operators that will receive Feldman shares of the per-leaf tweak. Order must match the operators' numeric IDs in the Spark operator config - share index is the 1-based position in this list." + }, + "receiverPublicKey": { + "type": "string", + "description": "Recipient's identity pubkey (hex-encoded compressed secp256k1 point). Each leaf's new_priv is ECIES-encrypted to this key and embedded in the per-operator package for claim-time delivery." + } + }, + "required": [ + "transferId", + "leaves", + "threshold", + "operatorRecipients", + "receiverPublicKey" + ] + }, + "v1StampLoginIntent": { + "type": "object", + "properties": { + "publicKey": { + "type": "string", + "description": "Client-side public key generated by the user, which will be conditionally added to org data based on the passkey stamp associated with this request" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the Session is valid for. If not provided, a default of 15 minutes will be used." + }, + "invalidateExisting": { + "type": "boolean", + "description": "Invalidate all other previously generated Login API keys" + }, + "sessionProfileId": { + "type": "string", + "description": "Optional session profile ID to specify which Session Profile to use for this login. If not provided, the default read/write session will be used." + } + }, + "required": ["publicKey"] + }, + "v1StampLoginResult": { + "type": "object", + "properties": { + "session": { + "type": "string", + "description": "Signed JWT containing an expiry, public key, session type, user id, and organization id" + } + }, + "required": ["session"] + }, + "v1SwapQuote": { + "type": "object", + "properties": { + "quoteId": { + "type": "string", + "description": "Identifier for this provider quote. Pass this value to execute_swap_v2 to bind execution to this exact quote. The signer is derived from the quote; clients do not resupply sign_with on execute." + }, + "provider": { + "type": "string", + "description": "Swap provider that produced this quote." + }, + "outputAmount": { + "type": "string", + "description": "Estimated base-unit amount of the output asset." + }, + "minOutputAmount": { + "type": "string", + "description": "Minimum acceptable base-unit amount of the output asset after slippage." + }, + "expiresAt": { + "type": "string", + "description": "Quote expiration as a millisecond epoch string." + }, + "slippageBps": { + "type": "string", + "description": "Effective total slippage tolerance in basis points for this quote, taken from the provider response when present. When the request omits input slippage_bps, the provider may calculate this value." + }, + "clientFeeBps": { + "type": "string", + "description": "Client fee in basis points applied for this pair. Informational only; already reflected in output_amount and min_output_amount." + }, + "estimatedTimeSeconds": { + "type": "string", + "description": "Provider-estimated completion time in seconds, when available." + } + }, + "required": [ + "quoteId", + "provider", + "outputAmount", + "minOutputAmount", + "expiresAt", + "clientFeeBps" + ] + }, + "v1SwapQuoteV2": { + "type": "object", + "properties": { + "quoteId": { + "type": "string", + "description": "Identifier for this provider quote. Pass this value to execute_swap_v2 to bind execution to this exact quote. The signer is derived from the quote; clients do not resupply sign_with on execute." + }, + "provider": { + "type": "string", + "description": "Swap provider that produced this quote." + }, + "outputAmount": { + "type": "string", + "description": "Estimated base-unit amount of the output asset." + }, + "minOutputAmount": { + "type": "string", + "description": "Minimum acceptable base-unit amount of the output asset after slippage." + }, + "expiresAt": { + "type": "string", + "description": "Quote expiration as a millisecond epoch string." + }, + "slippageBps": { + "type": "string", + "description": "Effective total slippage tolerance in basis points for this quote, taken from the provider response when present. When the request omits input slippage_bps, the provider may calculate this value." + }, + "clientFeeBps": { + "type": "string", + "description": "Client fee in basis points applied for this pair. Informational only; already reflected in output_amount and min_output_amount." + }, + "estimatedTimeSeconds": { + "type": "string", + "description": "Provider-estimated completion time in seconds, when available." + }, + "feeSponsorship": { + "type": "boolean" + }, + "fixedRate": { + "type": "boolean" + }, + "turnkeyFeeCollection": { + "type": "string" + }, + "sponsoredFeeComponents": { + "type": "array", + "items": { + "type": "string" + } + }, + "remainingFeeComponents": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": [ + "quoteId", + "provider", + "outputAmount", + "minOutputAmount", + "expiresAt", + "clientFeeBps" + ] + }, + "v1TransactionType": { + "type": "string", + "enum": [ + "TRANSACTION_TYPE_ETHEREUM", + "TRANSACTION_TYPE_SOLANA", + "TRANSACTION_TYPE_TRON", + "TRANSACTION_TYPE_BITCOIN", + "TRANSACTION_TYPE_TEMPO" + ] + }, + "v1TransportEncryptionSuite": { + "type": "string", + "enum": ["TRANSPORT_ENCRYPTION_SUITE_ENCLAVE_ENCRYPT_V1"] + }, + "v1TvcHealthCheckType": { + "type": "string", + "enum": ["TVC_HEALTH_CHECK_TYPE_HTTP", "TVC_HEALTH_CHECK_TYPE_GRPC"] + }, + "v1TvcManifestApproval": { + "type": "object", + "properties": { + "operatorId": { + "type": "string", + "description": "Unique identifier of the operator providing this approval" + }, + "signature": { + "type": "string", + "description": "Signature from the operator approving the manifest" + } + }, + "required": ["operatorId", "signature"] + }, + "v1TvcOperatorParams": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "The name for this new operator" + }, + "publicKey": { + "type": "string", + "description": "Public key for this operator" + } + }, + "required": ["name", "publicKey"] + }, + "v1TvcOperatorSetParams": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "Short description for this new operator set" + }, + "newOperators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1TvcOperatorParams" + }, + "description": "Operators to create as part of this new operator set" + }, + "existingOperatorIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Existing operators to use as part of this new operator set" + }, + "threshold": { + "type": "integer", + "format": "int64", + "description": "The threshold of operators needed to reach consensus in this new Operator Set" + } + }, + "required": ["name", "threshold"] + }, + "v1UpdateAllowedOriginsIntent": { + "type": "object", + "properties": { + "allowedOrigins": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Additional origins requests are allowed from besides Turnkey origins" + } + }, + "required": ["allowedOrigins"] + }, + "v1UpdateAllowedOriginsResult": { + "type": "object" + }, + "v1UpdateAuthProxyConfigIntent": { + "type": "object", + "properties": { + "allowedOrigins": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Updated list of allowed origins for CORS." + }, + "allowedAuthMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Updated list of allowed proxy authentication methods." + }, + "sendFromEmailAddress": { + "type": "string", + "description": "Custom 'from' address for auth-related emails." + }, + "replyToEmailAddress": { + "type": "string", + "description": "Custom reply-to address for auth-related emails." + }, + "emailAuthTemplateId": { + "type": "string", + "description": "Template ID for email-auth messages." + }, + "otpTemplateId": { + "type": "string", + "description": "Template ID for OTP SMS messages." + }, + "emailCustomizationParams": { + "$ref": "#/definitions/v1EmailCustomizationParams", + "description": "Optional parameters for customizing emails. If not provided, the default email will be used." + }, + "smsCustomizationParams": { + "$ref": "#/definitions/v1SmsCustomizationParams", + "description": "Overrides for auth-related SMS content." + }, + "walletKitSettings": { + "$ref": "#/definitions/v1WalletKitSettingsParams", + "description": "Overrides for react wallet kit related settings." + }, + "otpExpirationSeconds": { + "type": "integer", + "format": "int32", + "description": "OTP code lifetime in seconds." + }, + "verificationTokenExpirationSeconds": { + "type": "integer", + "format": "int32", + "description": "Verification-token lifetime in seconds." + }, + "sessionExpirationSeconds": { + "type": "integer", + "format": "int32", + "description": "Session lifetime in seconds." + }, + "otpAlphanumeric": { + "type": "boolean", + "description": "Enable alphanumeric OTP codes." + }, + "otpLength": { + "type": "integer", + "format": "int32", + "description": "Desired OTP code length (6–9)." + }, + "sendFromEmailSenderName": { + "type": "string", + "description": "Custom 'from' email sender for auth-related emails." + }, + "verificationTokenRequiredForGetAccountPii": { + "type": "boolean", + "description": "Verification token required for get account with PII (email/phone number). Default false." + }, + "socialLinkingClientIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Whitelisted OAuth client IDs for social account linking. When a user authenticates via a social provider with an email matching an existing account, the accounts will be linked if the client ID is in this list and the issuer is considered a trusted provider." + }, + "captchaEnabled": { + "type": "boolean", + "description": "Whether captcha verification is required on sign up \u0026 otp init." + } + } + }, + "v1UpdateAuthProxyConfigResult": { + "type": "object", + "properties": { + "configId": { + "type": "string", + "description": "Unique identifier for a given User. (representing the turnkey signer user id)" + } + } + }, + "v1UpdateFiatOnRampCredentialIntent": { + "type": "object", + "properties": { + "fiatOnrampCredentialId": { + "type": "string", + "description": "The ID of the fiat on-ramp credential to update" + }, + "onrampProvider": { + "$ref": "#/definitions/v1FiatOnRampProvider", + "description": "The fiat on-ramp provider" + }, + "projectId": { + "type": "string", + "description": "Project ID for the on-ramp provider. Some providers, like Coinbase, require this additional identifier." + }, + "publishableApiKey": { + "type": "string", + "description": "Publishable API key for the on-ramp provider" + }, + "encryptedSecretApiKey": { + "type": "string", + "description": "Secret API key for the on-ramp provider encrypted to our on-ramp encryption public key" + }, + "encryptedPrivateApiKey": { + "type": "string", + "description": "Private API key for the on-ramp provider encrypted to our on-ramp encryption public key. Some providers, like Coinbase, require this additional key." + } + }, + "required": [ + "fiatOnrampCredentialId", + "onrampProvider", + "publishableApiKey", + "encryptedSecretApiKey" + ] + }, + "v1UpdateFiatOnRampCredentialResult": { + "type": "object", + "properties": { + "fiatOnRampCredentialId": { + "type": "string", + "description": "Unique identifier of the Fiat On-Ramp credential that was updated" + } + }, + "required": ["fiatOnRampCredentialId"] + }, + "v1UpdateMfaPolicyIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "The ID of the User to update the MFA Policy for." + }, + "mfaPolicyId": { + "type": "string", + "description": "Unique identifier for a given MFA Policy." + }, + "mfaPolicyName": { + "type": "string", + "description": "Human-readable name for a Policy." + }, + "condition": { + "type": "string", + "description": "A condition expression that evaluates to true or false, determining when this MFA policy applies." + }, + "requiredAuthenticationMethods": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1RequiredAuthenticationMethodParams" + }, + "description": "An ordered list of authentication requirements. Each requirement must be satisfied sequentially to complete MFA." + }, + "order": { + "type": "integer", + "format": "int64", + "description": "The order in which this MFA policy is evaluated, starting from 0, relative to other MFA policies. Lower order values are evaluated first." + }, + "notes": { + "type": "string", + "description": "Notes for an MFA Policy." + } + }, + "required": ["userId", "mfaPolicyId"] + }, + "v1UpdateMfaPolicyResult": { + "type": "object", + "properties": { + "mfaPolicyId": { + "type": "string", + "description": "Unique identifier for a given MFA Policy." + } + }, + "required": ["mfaPolicyId"] + }, + "v1UpdateOauth2CredentialIntent": { + "type": "object", + "properties": { + "oauth2CredentialId": { + "type": "string", + "description": "The ID of the OAuth 2.0 credential to update" + }, + "provider": { + "$ref": "#/definitions/v1Oauth2Provider", + "description": "The OAuth 2.0 provider" + }, + "clientId": { + "type": "string", + "description": "The Client ID issued by the OAuth 2.0 provider" + }, + "encryptedClientSecret": { + "type": "string", + "description": "The client secret issued by the OAuth 2.0 provider encrypted to the TLS Fetcher quorum key" + } + }, + "required": [ + "oauth2CredentialId", + "provider", + "clientId", + "encryptedClientSecret" + ] + }, + "v1UpdateOauth2CredentialResult": { + "type": "object", + "properties": { + "oauth2CredentialId": { + "type": "string", + "description": "Unique identifier of the OAuth 2.0 credential that was updated" + } + }, + "required": ["oauth2CredentialId"] + }, + "v1UpdateOrganizationNameIntent": { + "type": "object", + "properties": { + "organizationName": { + "type": "string", + "description": "New name for the Organization." + } + }, + "required": ["organizationName"] + }, + "v1UpdateOrganizationNameResult": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for the Organization." + }, + "organizationName": { + "type": "string", + "description": "The updated organization name." + } + }, + "required": ["organizationId", "organizationName"] + }, + "v1UpdatePolicyIntent": { + "type": "object", + "properties": { + "policyId": { + "type": "string", + "description": "Unique identifier for a given Policy." + }, + "policyName": { + "type": "string", + "description": "Human-readable name for a Policy." + }, + "policyEffect": { + "$ref": "#/definitions/v1Effect", + "description": "The instruction to DENY or ALLOW an activity (optional)." + }, + "policyCondition": { + "type": "string", + "description": "The condition expression that triggers the Effect (optional)." + }, + "policyConsensus": { + "type": "string", + "description": "The consensus expression that triggers the Effect (optional)." + }, + "policyNotes": { + "type": "string", + "description": "Accompanying notes for a Policy (optional)." + } + }, + "required": ["policyId"] + }, + "v1UpdatePolicyIntentV2": { + "type": "object", + "properties": { + "policyId": { + "type": "string", + "description": "Unique identifier for a given Policy." + }, + "policyName": { + "type": "string", + "description": "Human-readable name for a Policy." + }, + "policyEffect": { + "$ref": "#/definitions/v1Effect", + "description": "The instruction to DENY or ALLOW an activity (optional)." + }, + "policyCondition": { + "type": "string", + "description": "The condition expression that triggers the Effect (optional)." + }, + "policyConsensus": { + "type": "string", + "description": "The consensus expression that triggers the Effect (optional)." + }, + "policyNotes": { + "type": "string", + "description": "Accompanying notes for a Policy (optional)." + }, + "time": { + "type": "string", + "description": "The time expression that triggers the Effect (optional)." + } + }, + "required": ["policyId"] + }, + "v1UpdatePolicyResult": { + "type": "object", + "properties": { + "policyId": { + "type": "string", + "description": "Unique identifier for a given Policy." + } + }, + "required": ["policyId"] + }, + "v1UpdatePolicyResultV2": { + "type": "object", + "properties": { + "policyId": { + "type": "string", + "description": "Unique identifier for a given Policy." + } + }, + "required": ["policyId"] + }, + "v1UpdatePrivateKeyTagIntent": { + "type": "object", + "properties": { + "privateKeyTagId": { + "type": "string", + "description": "Unique identifier for a given Private Key Tag." + }, + "newPrivateKeyTagName": { + "type": "string", + "description": "The new, human-readable name for the tag with the given ID." + }, + "addPrivateKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Private Keys IDs to add this tag to." + }, + "removePrivateKeyIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of Private Key IDs to remove this tag from." + } + }, + "required": ["privateKeyTagId", "addPrivateKeyIds", "removePrivateKeyIds"] + }, + "v1UpdatePrivateKeyTagResult": { + "type": "object", + "properties": { + "privateKeyTagId": { + "type": "string", + "description": "Unique identifier for a given Private Key Tag." + } + }, + "required": ["privateKeyTagId"] + }, + "v1UpdateRootQuorumIntent": { + "type": "object", + "properties": { + "threshold": { + "type": "integer", + "format": "int32", + "description": "The threshold of unique approvals to reach quorum." + }, + "userIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The unique identifiers of users who comprise the quorum set." + } + }, + "required": ["threshold", "userIds"] + }, + "v1UpdateRootQuorumResult": { + "type": "object" + }, + "v1UpdateTvcAppLiveDeploymentIntent": { + "type": "object", + "properties": { + "deploymentId": { + "type": "string", + "description": "The unique identifier of the TVC deployment to set as live for the app." + } + }, + "required": ["deploymentId"] + }, + "v1UpdateTvcAppLiveDeploymentResult": { + "type": "object" + }, + "v1UpdateUserEmailIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address. Setting this to an empty string will remove the user's email." + }, + "verificationToken": { + "type": "string", + "description": "Signed JWT containing a unique id, expiry, verification type, contact" + } + }, + "required": ["userId", "userEmail"] + }, + "v1UpdateUserEmailResult": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier of the User whose email was updated." + } + }, + "required": ["userId"] + }, + "v1UpdateUserIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "userTagIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "An updated list of User Tags to apply to this User. This field, if not needed, should be an empty array in your request body." + }, + "userPhoneNumber": { + "type": "string", + "description": "The user's phone number in E.164 format e.g. +13214567890" + } + }, + "required": ["userId"] + }, + "v1UpdateUserNameIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "userName": { + "type": "string", + "description": "Human-readable name for a User." + } + }, + "required": ["userId", "userName"] + }, + "v1UpdateUserNameResult": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier of the User whose name was updated." + } + }, + "required": ["userId"] + }, + "v1UpdateUserPhoneNumberIntent": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "userPhoneNumber": { + "type": "string", + "description": "The user's phone number in E.164 format e.g. +13214567890. Setting this to an empty string will remove the user's phone number." + }, + "verificationToken": { + "type": "string", + "description": "Signed JWT containing a unique id, expiry, verification type, contact" + } + }, + "required": ["userId", "userPhoneNumber"] + }, + "v1UpdateUserPhoneNumberResult": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier of the User whose phone number was updated." + } + }, + "required": ["userId"] + }, + "v1UpdateUserResult": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "A User ID." + } + }, + "required": ["userId"] + }, + "v1UpdateUserTagIntent": { + "type": "object", + "properties": { + "userTagId": { + "type": "string", + "description": "Unique identifier for a given User Tag." + }, + "newUserTagName": { + "type": "string", + "description": "The new, human-readable name for the tag with the given ID." + }, + "addUserIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User IDs to add this tag to." + }, + "removeUserIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User IDs to remove this tag from." + } + }, + "required": ["userTagId", "addUserIds", "removeUserIds"] + }, + "v1UpdateUserTagResult": { + "type": "object", + "properties": { + "userTagId": { + "type": "string", + "description": "Unique identifier for a given User Tag." + } + }, + "required": ["userTagId"] + }, + "v1UpdateWalletAccountNameIntent": { + "type": "object", + "properties": { + "walletAccountId": { + "type": "string", + "description": "Unique identifier for a given Wallet Account." + }, + "name": { + "type": "string", + "description": "Human-readable name for this Wallet Account." + } + }, + "required": ["walletAccountId", "name"] + }, + "v1UpdateWalletAccountNameResult": { + "type": "object", + "properties": { + "walletAccountId": { + "type": "string", + "description": "Unique identifier for a given Wallet Account." + } + }, + "required": ["walletAccountId"] + }, + "v1UpdateWalletIntent": { + "type": "object", + "properties": { + "walletId": { + "type": "string", + "description": "Unique identifier for a given Wallet." + }, + "walletName": { + "type": "string", + "description": "Human-readable name for a Wallet." + } + }, + "required": ["walletId"] + }, + "v1UpdateWalletResult": { + "type": "object", + "properties": { + "walletId": { + "type": "string", + "description": "A Wallet ID." + } + }, + "required": ["walletId"] + }, + "v1UpdateWebhookEndpointIntent": { + "type": "object", + "properties": { + "endpointId": { + "type": "string", + "description": "Unique identifier of the webhook endpoint to update." + }, + "url": { + "type": "string", + "description": "Updated destination URL for webhook delivery." + }, + "name": { + "type": "string", + "description": "Updated human-readable name for this webhook endpoint." + }, + "isActive": { + "type": "boolean", + "description": "Whether this webhook endpoint is active." + } + }, + "required": ["endpointId"] + }, + "v1UpdateWebhookEndpointResult": { + "type": "object", + "properties": { + "endpointId": { + "type": "string", + "description": "Unique identifier of the updated webhook endpoint." + }, + "webhookEndpoint": { + "$ref": "#/definitions/v1WebhookEndpointData", + "description": "The updated webhook endpoint data." + } + }, + "required": ["endpointId", "webhookEndpoint"] + }, + "v1UpsertGasUsageConfigIntent": { + "type": "object", + "properties": { + "orgWindowLimitUsd": { + "type": "string", + "description": "Gas sponsorship USD limit for the billing organization window." + }, + "subOrgWindowLimitUsd": { + "type": "string", + "description": "Gas sponsorship USD limit for sub-organizations under the billing organization." + }, + "windowDurationMinutes": { + "type": "string", + "description": "Rolling sponsorship window duration, expressed in minutes. This value can't exceed 30 days (43200 minutes)." + }, + "enabled": { + "type": "boolean", + "description": "Whether gas sponsorship is enabled for the organization." + }, + "solanaConfig": { + "$ref": "#/definitions/v1SolanaConfig", + "description": "Optional Solana sponsorship settings. If omitted, the existing Solana sponsorship state is left unchanged." + } + }, + "required": [ + "orgWindowLimitUsd", + "subOrgWindowLimitUsd", + "windowDurationMinutes" + ] + }, + "v1UpsertGasUsageConfigResult": { + "type": "object", + "properties": { + "gasUsageConfigId": { + "type": "string", + "description": "Unique identifier for the gas usage configuration that was created or updated." + } + }, + "required": ["gasUsageConfigId"] + }, + "v1UpsertSwapConfigIntent": { + "type": "object", + "properties": { + "feeReceiverWalletAddress": { + "type": "string" + }, + "feeBps": { + "type": "string", + "description": "Client fee in basis points applied to swaps; used for all pairs unless stable_fee_bps is set." + }, + "stableFeeBps": { + "type": "string", + "description": "Optional Enterprise-only override applied when both swap assets are stablecoins; falls back to fee_bps when unset. Non-Enterprise orgs may only set fee_bps." + } + } + }, + "v1UpsertSwapConfigResult": { + "type": "object", + "properties": { + "feeReceiverWalletAddress": { + "type": "string" + }, + "feeBps": { + "type": "string" + }, + "stableFeeBps": { + "type": "string" + } + } + }, + "v1UpsertSwapFeeSponsorshipLimitConfigIntent": { + "type": "object", + "properties": { + "orgWindowLimitUsd": { + "type": "string", + "description": "Positive USD limit shared by the billing parent and its sub-organizations. At most 18 integer and 12 fractional digits." + }, + "subOrgWindowLimitUsd": { + "type": "string", + "description": "Positive USD limit for each sub-organization, no greater than the parent limit." + }, + "windowDurationMinutes": { + "type": "string", + "description": "Positive rolling window duration in minutes, at most 153722867." + }, + "enabled": { + "type": "boolean", + "description": "Whether this spending window permits new swaps. Setting false only turns the saved window off and keeps its limits; it doesn't require the signed permission. This does not grant or remove the signed organization permission." + } + }, + "required": [ + "orgWindowLimitUsd", + "subOrgWindowLimitUsd", + "windowDurationMinutes", + "enabled" + ] + }, + "v1UpsertSwapFeeSponsorshipLimitConfigResult": { + "type": "object", + "properties": { + "organizationId": { + "type": "string" + } + }, + "required": ["organizationId"] + }, + "v1UpsertSwapFixedRateLimitConfigIntent": { + "type": "object", + "properties": { + "orgWindowLimitUsd": { + "type": "string", + "description": "Positive USD limit shared by the billing parent and its sub-organizations. At most 18 integer and 12 fractional digits." + }, + "subOrgWindowLimitUsd": { + "type": "string", + "description": "Positive USD limit for each sub-organization, no greater than the parent limit." + }, + "windowDurationMinutes": { + "type": "string", + "description": "Positive rolling window duration in minutes, at most 153722867." + }, + "enabled": { + "type": "boolean", + "description": "Whether this spending window permits new swaps. Setting false only turns the saved window off and keeps its limits; it doesn't require the signed permission. This does not grant or remove the signed organization permission." + } + }, + "required": [ + "orgWindowLimitUsd", + "subOrgWindowLimitUsd", + "windowDurationMinutes", + "enabled" + ] + }, + "v1UpsertSwapFixedRateLimitConfigResult": { + "type": "object", + "properties": { + "organizationId": { + "type": "string" + } + }, + "required": ["organizationId"] + }, + "v1User": { + "type": "object", + "properties": { + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "userPhoneNumber": { + "type": "string", + "description": "The user's phone number in E.164 format e.g. +13214567890" + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1Authenticator" + }, + "description": "A list of Authenticator parameters." + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ApiKey" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "userTags": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User Tag IDs." + }, + "oauthProviders": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1OauthProvider" + }, + "description": "A list of Oauth Providers." + }, + "createdAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "updatedAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "mfaPolicies": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1MfaPolicy" + }, + "description": "A list of MFA Policies that define multi-factor authentication requirements for this user." + } + }, + "required": [ + "userId", + "userName", + "authenticators", + "apiKeys", + "userTags", + "oauthProviders", + "createdAt", + "updatedAt", + "mfaPolicies" + ] + }, + "v1UserParams": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "accessType": { + "$ref": "#/definitions/v1AccessType", + "description": "The User's permissible access method(s)." + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/apiApiKeyParams" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParams" + }, + "description": "A list of Authenticator parameters. This field, if not needed, should be an empty array in your request body." + }, + "userTags": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User Tag IDs. This field, if not needed, should be an empty array in your request body." + } + }, + "required": [ + "userName", + "accessType", + "apiKeys", + "authenticators", + "userTags" + ] + }, + "v1UserParamsV2": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/apiApiKeyParams" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParamsV2" + }, + "description": "A list of Authenticator parameters. This field, if not needed, should be an empty array in your request body." + }, + "userTags": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User Tag IDs. This field, if not needed, should be an empty array in your request body." + } + }, + "required": ["userName", "apiKeys", "authenticators", "userTags"] + }, + "v1UserParamsV3": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "userPhoneNumber": { + "type": "string", + "description": "The user's phone number in E.164 format e.g. +13214567890" + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ApiKeyParamsV2" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParamsV2" + }, + "description": "A list of Authenticator parameters. This field, if not needed, should be an empty array in your request body." + }, + "oauthProviders": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1OauthProviderParams" + }, + "description": "A list of Oauth providers. This field, if not needed, should be an empty array in your request body." + }, + "userTags": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User Tag IDs. This field, if not needed, should be an empty array in your request body." + } + }, + "required": [ + "userName", + "apiKeys", + "authenticators", + "oauthProviders", + "userTags" + ] + }, + "v1UserParamsV4": { + "type": "object", + "properties": { + "userName": { + "type": "string", + "description": "Human-readable name for a User." + }, + "userEmail": { + "type": "string", + "description": "The user's email address." + }, + "userPhoneNumber": { + "type": "string", + "description": "The user's phone number in E.164 format e.g. +13214567890" + }, + "apiKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ApiKeyParamsV2" + }, + "description": "A list of API Key parameters. This field, if not needed, should be an empty array in your request body." + }, + "authenticators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1AuthenticatorParamsV2" + }, + "description": "A list of Authenticator parameters. This field, if not needed, should be an empty array in your request body." + }, + "oauthProviders": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1OauthProviderParamsV2" + }, + "description": "A list of Oauth providers. This field, if not needed, should be an empty array in your request body." + }, + "userTags": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of User Tag IDs. This field, if not needed, should be an empty array in your request body." + } + }, + "required": [ + "userName", + "apiKeys", + "authenticators", + "oauthProviders", + "userTags" + ] + }, + "v1VelocityControlAggregation": { + "type": "object", + "properties": { + "method": { + "$ref": "#/definitions/v1VelocityControlAggregationMethod", + "description": "Method that aggregates matching data points." + }, + "operator": { + "$ref": "#/definitions/v1VelocityControlAggregationOperator", + "description": "Comparison between the aggregate and the threshold." + }, + "threshold": { + "type": "string", + "description": "Non-negative base-10 decimal string with at most 38 total digits and 18 fractional digits." + }, + "window": { + "$ref": "#/definitions/v1VelocityControlAggregationWindow", + "description": "Time window for the aggregation." + }, + "groupBy": { + "$ref": "#/definitions/v1VelocityControlAggregationGroupBy", + "description": "Scope that partitions matching data before aggregation." + } + }, + "required": ["method", "operator", "threshold", "window", "groupBy"] + }, + "v1VelocityControlAggregationGroupBy": { + "type": "object", + "properties": { + "organization": { + "$ref": "#/definitions/v1VelocityControlAggregationGroupByOrganization", + "description": "Uses one shared bucket for the Organization." + }, + "user": { + "$ref": "#/definitions/v1VelocityControlAggregationGroupByUser", + "description": "Uses one bucket for each User." + }, + "wallet": { + "$ref": "#/definitions/v1VelocityControlAggregationGroupByWallet", + "description": "Uses one bucket for each Wallet." + } + } + }, + "v1VelocityControlAggregationGroupByOrganization": { + "type": "object" + }, + "v1VelocityControlAggregationGroupByUser": { + "type": "object" + }, + "v1VelocityControlAggregationGroupByWallet": { + "type": "object" + }, + "v1VelocityControlAggregationMethod": { + "type": "string", + "enum": [ + "VELOCITY_CONTROL_AGGREGATION_METHOD_SUM", + "VELOCITY_CONTROL_AGGREGATION_METHOD_COUNT" + ] + }, + "v1VelocityControlAggregationOperator": { + "type": "string", + "enum": [ + "VELOCITY_CONTROL_AGGREGATION_OPERATOR_LESS_THAN", + "VELOCITY_CONTROL_AGGREGATION_OPERATOR_LESS_THAN_OR_EQUAL", + "VELOCITY_CONTROL_AGGREGATION_OPERATOR_EQUAL", + "VELOCITY_CONTROL_AGGREGATION_OPERATOR_GREATER_THAN_OR_EQUAL", + "VELOCITY_CONTROL_AGGREGATION_OPERATOR_GREATER_THAN" + ] + }, + "v1VelocityControlAggregationWindow": { + "type": "object", + "properties": { + "rolling": { + "$ref": "#/definitions/v1VelocityControlAggregationWindowRolling", + "description": "Uses a rolling time window." + }, + "infinite": { + "$ref": "#/definitions/v1VelocityControlAggregationWindowInfinite", + "description": "Uses all matching data without a time limit." + } + } + }, + "v1VelocityControlAggregationWindowInfinite": { + "type": "object" + }, + "v1VelocityControlAggregationWindowRolling": { + "type": "object", + "properties": { + "duration": { + "type": "integer", + "format": "int64", + "description": "Duration of the rolling window, in seconds." + } + }, + "required": ["duration"] + }, + "v1VelocityControlDataSource": { + "type": "object", + "properties": { + "chainAssetTransfer": { + "$ref": "#/definitions/v1VelocityControlDataSourceChainAssetTransfer", + "description": "Uses transfers of the listed on-chain assets as input data." + }, + "activityExecution": { + "$ref": "#/definitions/v1VelocityControlDataSourceActivityExecution", + "description": "Uses executed Turnkey activities as input data." + } + } + }, + "v1VelocityControlDataSourceActivityExecution": { + "type": "object", + "properties": { + "filter": { + "$ref": "#/definitions/v1VelocityControlDataSourceActivityExecutionFilter", + "description": "Filters activity executions by type." + } + } + }, + "v1VelocityControlDataSourceActivityExecutionFilter": { + "type": "object", + "properties": { + "activity": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1VelocityControlDataSourceFilterActivity" + }, + "description": "Activity types whose executions are included." + } + } + }, + "v1VelocityControlDataSourceChainAssetTransfer": { + "type": "object", + "properties": { + "definition": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1VelocityControlDataSourceChainAssetTransferDefinition" + }, + "description": "Assets whose transfers are included in the data source." + }, + "filter": { + "$ref": "#/definitions/v1VelocityControlDataSourceChainAssetTransferFilter", + "description": "Filters asset transfers by activity type." + }, + "phase": { + "$ref": "#/definitions/v1VelocityControlDataSourcePhase", + "description": "Selects when to measure an asset transfer." + } + }, + "required": ["definition"] + }, + "v1VelocityControlDataSourceChainAssetTransferDefinition": { + "type": "object", + "properties": { + "caip19": { + "type": "string", + "description": "CAIP-19 identifier for the asset." + }, + "decimals": { + "type": "integer", + "format": "int64", + "description": "Integer between 0 and 255 (inclusive) that specifies the number of decimal places for the asset." + } + }, + "required": ["caip19", "decimals"] + }, + "v1VelocityControlDataSourceChainAssetTransferFilter": { + "type": "object", + "properties": { + "activity": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1VelocityControlDataSourceFilterActivity" + }, + "description": "Activity types whose asset transfers are included." + } + } + }, + "v1VelocityControlDataSourceFilterActivity": { + "type": "object", + "properties": { + "activityType": { + "type": "string", + "description": "Name of an activity type to include, such as `ACTIVITY_TYPE_SOL_SEND_TRANSACTION`." + } + }, + "required": ["activityType"] + }, + "v1VelocityControlDataSourcePhase": { + "type": "object", + "properties": { + "signature": { + "$ref": "#/definitions/v1VelocityControlDataSourcePhaseSignature", + "description": "Measures the transfer when Turnkey signs the transaction and returns it to the user." + }, + "submission": { + "$ref": "#/definitions/v1VelocityControlDataSourcePhaseSubmission", + "description": "Reserved for future use. Measures the transfer after the transaction lands on chain." + } + } + }, + "v1VelocityControlDataSourcePhaseSignature": { + "type": "object" + }, + "v1VelocityControlDataSourcePhaseSubmission": { + "type": "object" + }, + "v1VerifyOtpIntent": { + "type": "object", + "properties": { + "otpId": { + "type": "string", + "description": "ID representing the result of an init OTP activity." + }, + "otpCode": { + "type": "string", + "description": "OTP sent out to a user's contact (email or SMS)" + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the verification token is valid for. If not provided, a default of 1 hour will be used. Maximum value is 86400 seconds (24 hours)" + }, + "publicKey": { + "type": "string", + "description": "Client-side public key generated by the user, which will be added to the JWT response and verified in subsequent requests via a client proof signature" + } + }, + "required": ["otpId", "otpCode"] + }, + "v1VerifyOtpIntentV2": { + "type": "object", + "properties": { + "otpId": { + "type": "string", + "description": "UUID representing an OTP flow. A new UUID is created for each init OTP activity." + }, + "encryptedOtpBundle": { + "type": "string", + "description": "Encrypted bundle containing the OTP code and a client-generated public key. Turnkey's secure enclaves will decrypt this bundle, verify the OTP code, and issue a new Verification Token. Encrypted using the target encryption key provided in the INIT_OTP activity result." + }, + "expirationSeconds": { + "type": "string", + "description": "Expiration window (in seconds) indicating how long the verification token is valid for. If not provided, a default of 1 hour will be used. Maximum value is 86400 seconds (24 hours)" + } + }, + "required": ["otpId", "encryptedOtpBundle"] + }, + "v1VerifyOtpResult": { + "type": "object", + "properties": { + "verificationToken": { + "type": "string", + "description": "Signed JWT containing a unique id, expiry, verification type, contact. Verification status of a user is updated when the token is consumed (in OTP_LOGIN requests)" + } + }, + "required": ["verificationToken"] + }, + "v1Vote": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "Unique identifier for a given Vote object." + }, + "userId": { + "type": "string", + "description": "Unique identifier for a given User." + }, + "user": { + "$ref": "#/definitions/v1User", + "description": "Web and/or API user within your Organization." + }, + "activityId": { + "type": "string", + "description": "Unique identifier for a given Activity object." + }, + "selection": { + "type": "string", + "enum": ["VOTE_SELECTION_APPROVED", "VOTE_SELECTION_REJECTED"] + }, + "message": { + "type": "string", + "description": "The raw message being signed within a Vote." + }, + "publicKey": { + "type": "string", + "description": "The public component of a cryptographic key pair used to sign messages and transactions." + }, + "signature": { + "type": "string", + "description": "The signature applied to a particular vote." + }, + "scheme": { + "type": "string", + "description": "Method used to produce a signature." + }, + "createdAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + } + }, + "required": [ + "id", + "userId", + "user", + "activityId", + "selection", + "message", + "publicKey", + "signature", + "scheme", + "createdAt" + ] + }, + "v1WalletAccountParams": { + "type": "object", + "properties": { + "curve": { + "$ref": "#/definitions/v1Curve", + "description": "Cryptographic curve used to generate a wallet Account." + }, + "pathFormat": { + "$ref": "#/definitions/v1PathFormat", + "description": "Path format used to generate a wallet Account." + }, + "path": { + "type": "string", + "description": "Path used to generate a wallet Account." + }, + "addressFormat": { + "$ref": "#/definitions/v1AddressFormat", + "description": "Address format used to generate a wallet Acccount." + }, + "name": { + "type": "string", + "description": "Optional human-readable name for the account." + } + }, + "required": ["curve", "pathFormat", "path", "addressFormat"] + }, + "v1WalletKitSettingsParams": { + "type": "object", + "properties": { + "enabledSocialProviders": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of enabled social login providers (e.g., 'apple', 'google', 'facebook')", + "title": "Enabled Social Providers" + }, + "oauthClientIds": { + "type": "object", + "additionalProperties": { + "type": "string" + }, + "description": "Mapping of social login providers to their Oauth client IDs.", + "title": "Oauth Client IDs" + }, + "oauthRedirectUrl": { + "type": "string", + "description": "Oauth redirect URL to be used for social login flows.", + "title": "Oauth Redirect URL" + } + } + }, + "v1WalletParams": { + "type": "object", + "properties": { + "walletName": { + "type": "string", + "description": "Human-readable name for a Wallet." + }, + "accounts": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1WalletAccountParams" + }, + "description": "A list of wallet Accounts. This field, if not needed, should be an empty array in your request body." + }, + "mnemonicLength": { + "type": "integer", + "format": "int32", + "description": "Length of mnemonic to generate the Wallet seed. Defaults to 12. Accepted values: 12, 15, 18, 21, 24." + } + }, + "required": ["walletName", "accounts"] + }, + "v1WalletResult": { + "type": "object", + "properties": { + "walletId": { + "type": "string" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of account addresses." + } + }, + "required": ["walletId", "addresses"] + }, + "v1WebhookEndpointData": { + "type": "object", + "properties": { + "endpointId": { + "type": "string", + "description": "Unique identifier of the webhook endpoint." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "url": { + "type": "string", + "description": "The destination URL for webhook delivery." + }, + "name": { + "type": "string", + "description": "Human-readable name for this webhook endpoint." + }, + "isActive": { + "type": "boolean", + "description": "Whether this webhook endpoint is active." + }, + "subscriptions": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1WebhookSubscriptionParams" + }, + "description": "Current subscriptions attached to this endpoint." + } + }, + "required": ["endpointId", "organizationId", "url", "name", "isActive"] + }, + "v1WebhookSubscriptionParams": { + "type": "object", + "properties": { + "eventType": { + "type": "string", + "description": "The event type to subscribe to (for example, ACTIVITY_UPDATES, BALANCE_CONFIRMED_UPDATES, or BALANCE_FINALIZED_UPDATES)." + }, + "filtersJson": { + "type": "string", + "description": "JSON-encoded filter criteria for this subscription." + }, + "isActive": { + "type": "boolean", + "description": "Whether this subscription is active." + } + }, + "required": ["eventType"] + } + } +} diff --git a/codegen/inputs/public_api.swagger.json b/codegen/inputs/public_api.swagger.json index 8399f97..31b3fdb 100644 --- a/codegen/inputs/public_api.swagger.json +++ b/codegen/inputs/public_api.swagger.json @@ -14,6 +14,10 @@ "name": "Organizations", "description": "An Organization is the highest level of hierarchy in Turnkey. It can contain many Users, Private Keys, and Policies managed by a Root Quorum. The Root Quorum consists of a set of Users with a consensus threshold. This consensus threshold must be reached by Quorum members in order for any actions to take place.\n\nSee [Root Quorum](../concepts/users/root-quorum) for more information" }, + { + "name": "Webhooks", + "description": "Webhooks let you subscribe to events on your Organization and receive HTTP notifications when they occur, such as when an Activity completes." + }, { "name": "Invitations", "description": "Invitations allow you to invite Users into your Organization via email. Alternatively, Users can be added directly without an Invitation if their ApiKey or Authenticator credentials are known ahead of time.\n\nSee [Users](./api#tag/Users) for more information" @@ -30,6 +34,10 @@ "name": "Signing", "description": "Signers allow you to create digital signatures. Signatures are used to validate the authenticity and integrity of a digital message. Turnkey makes it easy to produce signatures by allowing you to sign with an address. If Turnkey doesn't yet support an address format you need, you can generate and sign with the public key instead by using the address format `ADDRESS_FORMAT_COMPRESSED`." }, + { + "name": "Spark", + "description": "Spark operations support the Spark Bitcoin protocol, including preparing and claiming encrypted transfers and preparing Lightning receives.\n\nFROST partial signing for Spark wallets is performed via the Signing operations. See [Signing](./api#tag/Signing) for more information" + }, { "name": "Private Keys", "description": "Private Keys are cryptographic public / private key pairs that can be used for cryptocurrency needs or more generalized encryption. Turnkey securely holds all private key materials for you, but only you can access them.\n\nThe Private Key ID or any derived address can be used to create digital signatures. See [Signing](./api#tag/Signing) for more information" @@ -51,8 +59,8 @@ "description": "Authenticators are WebAuthN hardware devices, such as a Macbook TouchID or Yubikey, that can be used to authenticate requests." }, { - "name": "API Keys", - "description": "API Keys are used to authenticate requests\n\nSee our [CLI](https://github.com/tkhq/tkcli) for instructions on generating API Keys" + "name": "API keys", + "description": "API keys are used to authenticate requests\n\nSee our [CLI](https://github.com/tkhq/tkcli) for instructions on generating API keys" }, { "name": "Activities", @@ -72,6 +80,38 @@ "consumes": ["application/json"], "produces": ["application/json"], "paths": { + "/public/v1/query/get_active_policies": { + "post": { + "summary": "Get active policies", + "description": "For each policy in an organization, report whether it is currently active based on the enclave's trusted timestamp and the policy's time window (if any). Policies without a time field are always active.", + "operationId": "PublicApiService_GetActivePolicies", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1GetActivePoliciesResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1GetActivePoliciesRequest" + } + } + ], + "tags": ["Policies"] + } + }, "/public/v1/query/get_activity": { "post": { "summary": "Get activity", @@ -170,8 +210,8 @@ }, "/public/v1/query/get_app_status": { "post": { - "summary": "Get TVC App status", - "description": "Get live runtime status for a TVC App from the cluster.", + "summary": "Get TVC app status", + "description": "Get live runtime status for a TVC app from the cluster.", "operationId": "PublicApiService_GetAppStatus", "responses": { "200": { @@ -266,8 +306,8 @@ }, "/public/v1/query/get_boot_proof": { "post": { - "summary": "Get a specific boot proof", - "description": "Get the boot proof for a given ephemeral key.", + "summary": "Get a specific Boot Proof", + "description": "Get the Boot Proof for a given ephemeral key.", "operationId": "PublicApiService_GetBootProof", "responses": { "200": { @@ -328,6 +368,38 @@ "tags": ["Earn"] } }, + "/public/v1/query/get_earn_claim_rewards_status": { + "post": { + "summary": "Get Earn claim rewards status", + "description": "Poll the status of a rewards claim by its claim_request_id.", + "operationId": "PublicApiService_GetEarnClaimRewardsStatus", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1GetEarnClaimRewardsStatusResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1GetEarnClaimRewardsStatusRequest" + } + } + ], + "tags": ["Earn"] + } + }, "/public/v1/query/get_earn_deploy_status": { "post": { "summary": "Get Earn deploy status", @@ -490,8 +562,8 @@ }, "/public/v1/query/get_latest_boot_proof": { "post": { - "summary": "Get the latest boot proof for an app", - "description": "Get the latest boot proof for a given enclave app name.", + "summary": "Get the latest Boot Proof for an app", + "description": "Get the latest Boot Proof for a given enclave app name.", "operationId": "PublicApiService_GetLatestBootProof", "responses": { "200": { @@ -677,12 +749,12 @@ } } ], - "tags": ["PublicApiService"] + "tags": ["User Auth"] } }, "/public/v1/query/get_oauth_providers": { "post": { - "summary": "Get Oauth providers", + "summary": "Get OAuth providers", "description": "Get details about Oauth providers for a user.", "operationId": "PublicApiService_GetOauthProviders", "responses": { @@ -1000,9 +1072,41 @@ "tags": ["Policies"] } }, + "/public/v1/query/get_swap_sponsorship_usage": { + "post": { + "summary": "Get swap sponsorship usage", + "description": "Read each swap sponsorship feature's spending window and settled spending in the current rolling window. Parents see aggregate spending; children see their own spending. Pending swaps are not reserved.", + "operationId": "PublicApiService_GetSwapSponsorshipUsage", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1GetSwapSponsorshipUsageResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1GetSwapSponsorshipUsageRequest" + } + } + ], + "tags": ["Swaps"] + } + }, "/public/v1/query/get_swap_status": { "post": { - "summary": "Get swap status", + "summary": "Get Swap status", "description": "Poll the status of a swap by its swap_request_id. Covers same-chain and cross-chain swaps.", "operationId": "PublicApiService_GetSwapStatus", "responses": { @@ -1034,8 +1138,8 @@ }, "/public/v1/query/get_tvc_app": { "post": { - "summary": "Get TVC App", - "description": "Get details about a single TVC App", + "summary": "Get TVC app", + "description": "Get details about a single TVC app.", "operationId": "PublicApiService_GetTvcApp", "responses": { "200": { @@ -1066,8 +1170,8 @@ }, "/public/v1/query/get_tvc_deployment": { "post": { - "summary": "Get TVC Deployment", - "description": "Get details about a single TVC Deployment", + "summary": "Get TVC deployment", + "description": "Get details about a single TVC deployment.", "operationId": "PublicApiService_GetTvcDeployment", "responses": { "200": { @@ -1098,7 +1202,7 @@ }, "/public/v1/query/get_tvc_deployment_debug_logs": { "post": { - "summary": "Get TVC Deployment debug logs", + "summary": "Get TVC deployment debug logs", "description": "Get a bounded window of application logs from a debug-mode TVC deployment. Returned lines are collected from every running replica and sorted by platform timestamp.", "operationId": "PublicApiService_GetTvcDeploymentDebugLogs", "responses": { @@ -1128,16 +1232,16 @@ "tags": ["TVC"] } }, - "/public/v1/query/get_tvc_qos_versions": { + "/public/v1/query/get_tvc_deployment_provisioning_details": { "post": { - "summary": "Get TVC QOS versions", - "description": "List QOS versions supported for new TVC deployments and the latest recommended QOS version.", - "operationId": "PublicApiService_GetTvcQosVersions", + "summary": "Get TVC deployment's provisioning details", + "description": "Get the attestation document and manifest envelope of the provisioning enclave for a TVC deployment.", + "operationId": "PublicApiService_GetTvcDeploymentProvisioningDetails", "responses": { "200": { "description": "A successful response.", "schema": { - "$ref": "#/definitions/v1GetTvcQosVersionsResponse" + "$ref": "#/definitions/v1GetTvcDeploymentProvisioningDetailsResponse" } }, "default": { @@ -1153,23 +1257,23 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1GetTvcQosVersionsRequest" + "$ref": "#/definitions/v1GetTvcDeploymentProvisioningDetailsRequest" } } ], "tags": ["TVC"] } }, - "/public/v1/query/get_user": { + "/public/v1/query/get_tvc_qos_versions": { "post": { - "summary": "Get user", - "description": "Get details about a user.", - "operationId": "PublicApiService_GetUser", + "summary": "Get TVC QOS versions", + "description": "List QOS versions supported for new TVC deployments and the latest recommended QOS version.", + "operationId": "PublicApiService_GetTvcQosVersions", "responses": { "200": { "description": "A successful response.", "schema": { - "$ref": "#/definitions/v1GetUserResponse" + "$ref": "#/definitions/v1GetTvcQosVersionsResponse" } }, "default": { @@ -1185,23 +1289,23 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1GetUserRequest" + "$ref": "#/definitions/v1GetTvcQosVersionsRequest" } } ], - "tags": ["Users"] + "tags": ["TVC"] } }, - "/public/v1/query/get_velocity_control": { + "/public/v1/query/get_user": { "post": { - "summary": "Get velocity control", - "description": "Get details about a velocity control.", - "operationId": "PublicApiService_GetVelocityControl", + "summary": "Get user", + "description": "Get details about a user.", + "operationId": "PublicApiService_GetUser", "responses": { "200": { "description": "A successful response.", "schema": { - "$ref": "#/definitions/v1GetVelocityControlResponse" + "$ref": "#/definitions/v1GetUserResponse" } }, "default": { @@ -1217,11 +1321,11 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1GetVelocityControlRequest" + "$ref": "#/definitions/v1GetUserRequest" } } ], - "tags": ["Velocity Controls"] + "tags": ["Users"] } }, "/public/v1/query/get_wallet": { @@ -1448,6 +1552,38 @@ "tags": ["Earn"] } }, + "/public/v1/query/list_earn_rewards": { + "post": { + "summary": "List Earn rewards", + "description": "List the protocol rewards (e.g. MORPHO and third-party campaign tokens, distributed off-chain via Merkl) attributed to a wallet: claimable, lifetime claimed, and pending amounts per reward token.", + "operationId": "PublicApiService_ListEarnRewards", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1ListEarnRewardsResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1ListEarnRewardsRequest" + } + } + ], + "tags": ["Earn"] + } + }, "/public/v1/query/list_earn_vaults": { "post": { "summary": "Get Earn vault catalog", @@ -1546,7 +1682,7 @@ }, "/public/v1/query/list_fiat_on_ramp_credentials": { "post": { - "summary": "List Fiat On Ramp Credentials", + "summary": "List Fiat On Ramp credentials", "description": "List all fiat on ramp provider credentials within an organization.", "operationId": "PublicApiService_ListFiatOnRampCredentials", "responses": { @@ -1578,7 +1714,7 @@ }, "/public/v1/query/list_oauth2_credentials": { "post": { - "summary": "List OAuth 2.0 Credentials", + "summary": "List OAuth 2.0 credentials", "description": "List all OAuth 2.0 credentials within an organization.", "operationId": "PublicApiService_ListOauth2Credentials", "responses": { @@ -1803,7 +1939,7 @@ "/public/v1/query/list_suborgs": { "post": { "summary": "Get sub-organizations", - "description": "Get all suborg IDs associated given a parent org ID and an optional filter.", + "description": "Get all suborg IDs (verified and unverified) associated with a given parent organization ID and an optional filter.", "operationId": "PublicApiService_GetSubOrgIds", "responses": { "200": { @@ -1866,8 +2002,8 @@ }, "/public/v1/query/list_tvc_app_deployments": { "post": { - "summary": "List TVC Deployments", - "description": "List all deployments for a given TVC App", + "summary": "List TVC deployments", + "description": "List all deployments for a given TVC app.", "operationId": "PublicApiService_GetTvcAppDeployments", "responses": { "200": { @@ -1898,8 +2034,8 @@ }, "/public/v1/query/list_tvc_apps": { "post": { - "summary": "List TVC Apps", - "description": "List all TVC Apps within an organization.", + "summary": "List TVC apps", + "description": "List all TVC apps within an organization.", "operationId": "PublicApiService_GetTvcApps", "responses": { "200": { @@ -1928,16 +2064,16 @@ "tags": ["TVC"] } }, - "/public/v1/query/list_user_tags": { + "/public/v1/query/list_tvc_operators": { "post": { - "summary": "List user tags", - "description": "List all user tags within an organization.", - "operationId": "PublicApiService_ListUserTags", + "summary": "List TVC operators", + "description": "List all TVC operators within an organization, newest first.", + "operationId": "PublicApiService_GetTvcOperators", "responses": { "200": { "description": "A successful response.", "schema": { - "$ref": "#/definitions/v1ListUserTagsResponse" + "$ref": "#/definitions/v1GetTvcOperatorsResponse" } }, "default": { @@ -1953,23 +2089,23 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1ListUserTagsRequest" + "$ref": "#/definitions/v1GetTvcOperatorsRequest" } } ], - "tags": ["User Tags"] + "tags": ["TVC"] } }, - "/public/v1/query/list_users": { + "/public/v1/query/list_tvc_quorum_keys": { "post": { - "summary": "List users", - "description": "List all users within an organization.", - "operationId": "PublicApiService_GetUsers", + "summary": "List TVC Quorum Keys", + "description": "List all hosted TVC Quorum Keys within an organization, newest first.", + "operationId": "PublicApiService_GetTvcQuorumKeys", "responses": { "200": { "description": "A successful response.", "schema": { - "$ref": "#/definitions/v1GetUsersResponse" + "$ref": "#/definitions/v1GetTvcQuorumKeysResponse" } }, "default": { @@ -1985,23 +2121,55 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1GetUsersRequest" + "$ref": "#/definitions/v1GetTvcQuorumKeysRequest" } } ], - "tags": ["Users"] + "tags": ["TVC"] + } + }, + "/public/v1/query/list_user_tags": { + "post": { + "summary": "List user tags", + "description": "List all user tags within an organization.", + "operationId": "PublicApiService_ListUserTags", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1ListUserTagsResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1ListUserTagsRequest" + } + } + ], + "tags": ["User Tags"] } }, - "/public/v1/query/list_velocity_controls": { + "/public/v1/query/list_users": { "post": { - "summary": "List velocity controls", - "description": "List all velocity controls within an organization.", - "operationId": "PublicApiService_ListVelocityControls", + "summary": "List users", + "description": "List all users within an organization.", + "operationId": "PublicApiService_GetUsers", "responses": { "200": { "description": "A successful response.", "schema": { - "$ref": "#/definitions/v1ListVelocityControlsResponse" + "$ref": "#/definitions/v1GetUsersResponse" } }, "default": { @@ -2017,17 +2185,17 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1ListVelocityControlsRequest" + "$ref": "#/definitions/v1GetUsersRequest" } } ], - "tags": ["Velocity Controls"] + "tags": ["Users"] } }, "/public/v1/query/list_verified_suborgs": { "post": { "summary": "Get verified sub-organizations", - "description": "Get all email or phone verified suborg IDs associated given a parent org ID.", + "description": "Get all verified suborg IDs associated with a given parent organization ID and an optional filter.", "operationId": "PublicApiService_GetVerifiedSubOrgIds", "responses": { "200": { @@ -2149,13 +2317,13 @@ } } ], - "tags": ["Organizations"] + "tags": ["Webhooks"] } }, "/public/v1/query/validate_tvc_image": { "post": { - "summary": "Validate Container Image for TVC", - "description": "Validate a container image URL and pull secret for TVC deployment", + "summary": "Validate container image for TVC", + "description": "Validate a container image URL and pull secret for TVC deployment.", "operationId": "PublicApiService_ValidateTvcImage", "responses": { "200": { @@ -2187,7 +2355,7 @@ "/public/v1/query/whoami": { "post": { "summary": "Who am I?", - "description": "Get basic information about your current API or WebAuthN user and their organization. Affords sub-organization look ups via parent organization for WebAuthN or API key users.", + "description": "Get basic information about your current API or WebAuthn user and their organization. Affords sub-organization lookups via parent organization for WebAuthn or API key users.", "operationId": "PublicApiService_GetWhoami", "responses": { "200": { @@ -2250,7 +2418,7 @@ }, "/public/v1/submit/claim_earn_fees": { "post": { - "summary": "Claim earn fees", + "summary": "Claim Earn fees", "description": "Claim earn fees through the activity pipeline.", "operationId": "PublicApiService_ClaimEarnFees", "responses": { @@ -2282,7 +2450,7 @@ }, "/public/v1/submit/claim_swap_fees": { "post": { - "summary": "Claim swap fees", + "summary": "Claim Swap fees", "description": "Claim swap fees through the activity pipeline.", "operationId": "PublicApiService_ClaimSwapFees", "responses": { @@ -2341,7 +2509,7 @@ } } ], - "tags": ["API Keys"] + "tags": ["API keys"] } }, "/public/v1/submit/create_authenticators": { @@ -2378,8 +2546,8 @@ }, "/public/v1/submit/create_fiat_on_ramp_credential": { "post": { - "summary": "Create a Fiat On Ramp Credential", - "description": "Create a fiat on ramp provider credential", + "summary": "Create a Fiat On Ramp credential", + "description": "Create a fiat on ramp provider credential.", "operationId": "PublicApiService_CreateFiatOnRampCredential", "responses": { "200": { @@ -2474,8 +2642,8 @@ }, "/public/v1/submit/create_oauth2_credential": { "post": { - "summary": "Create an OAuth 2.0 Credential", - "description": "Enable authentication for end users with an OAuth 2.0 provider", + "summary": "Create an OAuth 2.0 credential", + "description": "Enable authentication for end users with an OAuth 2.0 provider.", "operationId": "PublicApiService_CreateOauth2Credential", "responses": { "200": { @@ -2506,7 +2674,7 @@ }, "/public/v1/submit/create_oauth_providers": { "post": { - "summary": "Create Oauth providers", + "summary": "Create OAuth providers", "description": "Create Oauth providers for a specified user.", "operationId": "PublicApiService_CreateOauthProviders", "responses": { @@ -2826,8 +2994,8 @@ }, "/public/v1/submit/create_swap_quote": { "post": { - "summary": "Get swap quote", - "description": "Get a swap quote. Asset chains are derived from CAIP-19 asset IDs; cross-chain quotes are supported.", + "summary": "Create Swap quote", + "description": "Create a swap quote. Asset chains are derived from CAIP-19 asset IDs; cross-chain quotes are supported.", "operationId": "PublicApiService_CreateSwapQuote", "responses": { "200": { @@ -2858,8 +3026,8 @@ }, "/public/v1/submit/create_tvc_app": { "post": { - "summary": "Create a TVC App", - "description": "Create a new TVC application", + "summary": "Create a TVC app", + "description": "Create a new TVC application.", "operationId": "PublicApiService_CreateTvcApp", "responses": { "200": { @@ -2890,8 +3058,8 @@ }, "/public/v1/submit/create_tvc_deployment": { "post": { - "summary": "Create a TVC Deployment", - "description": "Create a new TVC Deployment", + "summary": "Create a TVC deployment", + "description": "Create a new TVC deployment.", "operationId": "PublicApiService_CreateTvcDeployment", "responses": { "200": { @@ -2922,8 +3090,8 @@ }, "/public/v1/submit/create_tvc_manifest_approvals": { "post": { - "summary": "Create TVC Manifest Approvals", - "description": "Post one or more manifest approvals for a TVC Manifest", + "summary": "Create TVC manifest approvals", + "description": "Post one or more manifest approvals for a TVC manifest.", "operationId": "PublicApiService_CreateTvcManifestApprovals", "responses": { "200": { @@ -2952,11 +3120,11 @@ "tags": ["TVC"] } }, - "/public/v1/submit/create_user_tag": { + "/public/v1/submit/create_tvc_operator": { "post": { - "summary": "Create user tag", - "description": "Create a user tag and add it to users.", - "operationId": "PublicApiService_CreateUserTag", + "summary": "Create TVC operator", + "description": "Create a TVC operator backed by uncompressed P-256 Turnkey wallet accounts.", + "operationId": "PublicApiService_CreateTvcOperator", "responses": { "200": { "description": "A successful response.", @@ -2977,18 +3145,18 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1CreateUserTagRequest" + "$ref": "#/definitions/v1CreateTvcOperatorRequest" } } ], - "tags": ["User Tags"] + "tags": ["TVC"] } }, - "/public/v1/submit/create_users": { + "/public/v1/submit/create_tvc_quorum_key": { "post": { - "summary": "Create users", - "description": "Create users in an existing organization. Each user must have at least one valid credential: an API key, an authenticator, an OAuth provider, or an email or phone number with a login method enabled on the organization (email, email OTP, or SMS).", - "operationId": "PublicApiService_CreateUsers", + "summary": "Create TVC Quorum Key", + "description": "Create a hosted TVC Quorum Key and encrypted shares.", + "operationId": "PublicApiService_CreateTvcQuorumKey", "responses": { "200": { "description": "A successful response.", @@ -3009,18 +3177,50 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1CreateUsersRequest" + "$ref": "#/definitions/v1CreateTvcQuorumKeyRequest" } } ], - "tags": ["Users"] + "tags": ["TVC"] + } + }, + "/public/v1/submit/create_user_tag": { + "post": { + "summary": "Create user tag", + "description": "Create a user tag and add it to users.", + "operationId": "PublicApiService_CreateUserTag", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1ActivityResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1CreateUserTagRequest" + } + } + ], + "tags": ["User Tags"] } }, - "/public/v1/submit/create_velocity_control": { + "/public/v1/submit/create_users": { "post": { - "summary": "Create velocity control", - "description": "Create a new velocity control.", - "operationId": "PublicApiService_CreateVelocityControl", + "summary": "Create users", + "description": "Create users in an existing organization. Each user must have at least one valid credential: an API key, an authenticator, an OAuth provider, or an email or phone number with a login method enabled on the organization (email, email OTP, or SMS).", + "operationId": "PublicApiService_CreateUsers", "responses": { "200": { "description": "A successful response.", @@ -3041,11 +3241,11 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1CreateVelocityControlRequest" + "$ref": "#/definitions/v1CreateUsersRequest" } } ], - "tags": ["Velocity Controls"] + "tags": ["Users"] } }, "/public/v1/submit/create_wallet": { @@ -3141,13 +3341,13 @@ } } ], - "tags": ["Organizations"] + "tags": ["Webhooks"] } }, "/public/v1/submit/delete_api_keys": { "post": { "summary": "Delete API keys", - "description": "Remove api keys from a user.", + "description": "Remove API keys from a user.", "operationId": "PublicApiService_DeleteApiKeys", "responses": { "200": { @@ -3173,7 +3373,7 @@ } } ], - "tags": ["API Keys"] + "tags": ["API keys"] } }, "/public/v1/submit/delete_authenticators": { @@ -3210,8 +3410,8 @@ }, "/public/v1/submit/delete_fiat_on_ramp_credential": { "post": { - "summary": "Delete a Fiat On Ramp Credential", - "description": "Delete a fiat on ramp provider credential", + "summary": "Delete a Fiat On Ramp credential", + "description": "Delete a fiat on ramp provider credential.", "operationId": "PublicApiService_DeleteFiatOnRampCredential", "responses": { "200": { @@ -3306,8 +3506,8 @@ }, "/public/v1/submit/delete_oauth2_credential": { "post": { - "summary": "Delete an OAuth 2.0 Credential", - "description": "Disable authentication for end users with an OAuth 2.0 provider", + "summary": "Delete an OAuth 2.0 credential", + "description": "Disable authentication for end users with an OAuth 2.0 provider.", "operationId": "PublicApiService_DeleteOauth2Credential", "responses": { "200": { @@ -3338,7 +3538,7 @@ }, "/public/v1/submit/delete_oauth_providers": { "post": { - "summary": "Delete Oauth providers", + "summary": "Delete OAuth providers", "description": "Remove Oauth providers for a specified user.", "operationId": "PublicApiService_DeleteOauthProviders", "responses": { @@ -3496,11 +3696,11 @@ "tags": ["Private Keys"] } }, - "/public/v1/submit/delete_smart_contract_interface": { + "/public/v1/submit/delete_secrets": { "post": { - "summary": "Delete smart contract interface", - "description": "Delete a smart contract interface.", - "operationId": "PublicApiService_DeleteSmartContractInterface", + "summary": "Delete secrets", + "description": "Delete secrets by their unique identifiers. All secrets must belong to the organization.", + "operationId": "PublicApiService_DeleteSecrets", "responses": { "200": { "description": "A successful response.", @@ -3521,14 +3721,46 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1DeleteSmartContractInterfaceRequest" + "$ref": "#/definitions/v1DeleteSecretsRequest" } } ], - "tags": ["Policies"] + "tags": ["Secrets"] } }, - "/public/v1/submit/delete_sub_organization": { + "/public/v1/submit/delete_smart_contract_interface": { + "post": { + "summary": "Delete smart contract interface", + "description": "Delete a smart contract interface.", + "operationId": "PublicApiService_DeleteSmartContractInterface", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1ActivityResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1DeleteSmartContractInterfaceRequest" + } + } + ], + "tags": ["Policies"] + } + }, + "/public/v1/submit/delete_sub_organization": { "post": { "summary": "Delete sub-organization", "description": "Delete a sub-organization.", @@ -3562,8 +3794,8 @@ }, "/public/v1/submit/delete_tvc_app_and_deployments": { "post": { - "summary": "Delete a TVC App and all of its deployments", - "description": "Delete a TVC App and all of its deployments", + "summary": "Delete a TVC app and all of its deployments", + "description": "Delete a TVC app and all of its deployments.", "operationId": "PublicApiService_DeleteTvcAppAndDeployments", "responses": { "200": { @@ -3594,8 +3826,8 @@ }, "/public/v1/submit/delete_tvc_deployment": { "post": { - "summary": "Delete a TVC Deployment", - "description": "Delete a TVC Deployment", + "summary": "Delete a TVC deployment", + "description": "Delete a TVC deployment.", "operationId": "PublicApiService_DeleteTvcDeployment", "responses": { "200": { @@ -3688,11 +3920,11 @@ "tags": ["Users"] } }, - "/public/v1/submit/delete_velocity_control": { + "/public/v1/submit/delete_wallet_accounts": { "post": { - "summary": "Delete velocity control", - "description": "Delete an existing velocity control.", - "operationId": "PublicApiService_DeleteVelocityControl", + "summary": "Delete wallet accounts", + "description": "Delete wallet accounts for an organization.", + "operationId": "PublicApiService_DeleteWalletAccounts", "responses": { "200": { "description": "A successful response.", @@ -3713,18 +3945,18 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1DeleteVelocityControlRequest" + "$ref": "#/definitions/v1DeleteWalletAccountsRequest" } } ], - "tags": ["Velocity Controls"] + "tags": ["Wallets"] } }, - "/public/v1/submit/delete_wallet_accounts": { + "/public/v1/submit/delete_wallets": { "post": { - "summary": "Delete wallet accounts", - "description": "Delete wallet accounts for an organization.", - "operationId": "PublicApiService_DeleteWalletAccounts", + "summary": "Delete wallets", + "description": "Delete wallets for an organization.", + "operationId": "PublicApiService_DeleteWallets", "responses": { "200": { "description": "A successful response.", @@ -3745,18 +3977,18 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1DeleteWalletAccountsRequest" + "$ref": "#/definitions/v1DeleteWalletsRequest" } } ], "tags": ["Wallets"] } }, - "/public/v1/submit/delete_wallets": { + "/public/v1/submit/delete_webhook_endpoint": { "post": { - "summary": "Delete wallets", - "description": "Delete wallets for an organization.", - "operationId": "PublicApiService_DeleteWallets", + "summary": "Delete webhook endpoint", + "description": "Delete a webhook endpoint for an organization.", + "operationId": "PublicApiService_DeleteWebhookEndpoint", "responses": { "200": { "description": "A successful response.", @@ -3777,18 +4009,18 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1DeleteWalletsRequest" + "$ref": "#/definitions/v1DeleteWebhookEndpointRequest" } } ], - "tags": ["Wallets"] + "tags": ["Webhooks"] } }, - "/public/v1/submit/delete_webhook_endpoint": { + "/public/v1/submit/earn_claim_rewards": { "post": { - "summary": "Delete webhook endpoint", - "description": "Delete a webhook endpoint for an organization.", - "operationId": "PublicApiService_DeleteWebhookEndpoint", + "summary": "Claim Earn rewards", + "description": "Claim the Merkl protocol rewards attributed to a wallet's Earn positions. The claim is signed by the wallet itself and every reward token is transferred to it; see ListEarnRewards for what is claimable.", + "operationId": "PublicApiService_EarnClaimRewards", "responses": { "200": { "description": "A successful response.", @@ -3809,11 +4041,11 @@ "in": "body", "required": true, "schema": { - "$ref": "#/definitions/v1DeleteWebhookEndpointRequest" + "$ref": "#/definitions/v1EarnClaimRewardsRequest" } } ], - "tags": ["Organizations"] + "tags": ["Earn"] } }, "/public/v1/submit/earn_deploy_wrapper": { @@ -4042,7 +4274,7 @@ }, "/public/v1/submit/execute_swap": { "post": { - "summary": "Execute swap", + "summary": "Execute Swap", "description": "Execute the exact provider quote identified by quote_id through the activity pipeline and Turnkey broadcasting. Requests must use ACTIVITY_TYPE_EXECUTE_SWAP_V2.", "operationId": "PublicApiService_ExecuteSwap", "responses": { @@ -4298,7 +4530,7 @@ }, "/public/v1/submit/init_fiat_on_ramp": { "post": { - "summary": "Init fiat on ramp", + "summary": "Init Fiat On Ramp", "description": "Initiate a fiat on ramp flow.", "operationId": "PublicApiService_InitFiatOnRamp", "responses": { @@ -4522,7 +4754,7 @@ }, "/public/v1/submit/oauth": { "post": { - "summary": "Oauth", + "summary": "OAuth", "description": "Authenticate a user with an OIDC token (Oauth).", "operationId": "PublicApiService_Oauth", "responses": { @@ -4555,7 +4787,7 @@ "/public/v1/submit/oauth2_authenticate": { "post": { "summary": "OAuth 2.0 authentication", - "description": "Authenticate a user with an OAuth 2.0 provider and receive an OIDC token to use with the LoginWithOAuth or CreateSubOrganization activities", + "description": "Authenticate a user with an OAuth 2.0 provider and receive an OIDC token to use with the LoginWithOAuth or CreateSubOrganization activities.", "operationId": "PublicApiService_Oauth2Authenticate", "responses": { "200": { @@ -4586,7 +4818,7 @@ }, "/public/v1/submit/oauth_login": { "post": { - "summary": "Login with Oauth", + "summary": "Login with OAuth", "description": "Create an Oauth session for a user.", "operationId": "PublicApiService_OauthLogin", "responses": { @@ -4680,6 +4912,70 @@ "tags": ["Sessions"] } }, + "/public/v1/submit/post_tvc_quorum_key_share": { + "post": { + "summary": "Post TVC Quorum Key share", + "description": "Post re-encrypted Quorum Key share for a TVC deployment.", + "operationId": "PublicApiService_PostTvcQuorumKeyShare", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1ActivityResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1PostTvcQuorumKeyShareRequest" + } + } + ], + "tags": ["TVC"] + } + }, + "/public/v1/submit/re_encrypt_tvc_quorum_key_share": { + "post": { + "summary": "Re-encrypt TVC Quorum Key share", + "description": "Re-encrypt a hosted TVC Quorum Key share for a deployment.", + "operationId": "PublicApiService_ReEncryptTvcQuorumKeyShare", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1ActivityResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1ReEncryptTvcQuorumKeyShareRequest" + } + } + ], + "tags": ["TVC"] + } + }, "/public/v1/submit/recover_user": { "post": { "summary": "Recover a user", @@ -4810,8 +5106,8 @@ }, "/public/v1/submit/restore_tvc_deployment": { "post": { - "summary": "Restore a TVC Deployment", - "description": "Restore a deleted TVC Deployment", + "summary": "Restore a TVC deployment", + "description": "Restore a deleted TVC deployment.", "operationId": "PublicApiService_RestoreTvcDeployment", "responses": { "200": { @@ -4906,8 +5202,8 @@ }, "/public/v1/submit/set_tvc_app_live_deployment": { "post": { - "summary": "Set TVC App live deployment", - "description": "Set the live deployment for a TVC App", + "summary": "Set TVC app live deployment", + "description": "Set the live deployment for a TVC app.", "operationId": "PublicApiService_UpdateTvcAppLiveDeployment", "responses": { "200": { @@ -5093,7 +5389,7 @@ } } ], - "tags": ["Signing"] + "tags": ["Spark"] } }, "/public/v1/submit/spark_prepare_lightning_receive": { @@ -5125,7 +5421,7 @@ } } ], - "tags": ["Signing"] + "tags": ["Spark"] } }, "/public/v1/submit/spark_prepare_transfer": { @@ -5157,7 +5453,7 @@ } } ], - "tags": ["Signing"] + "tags": ["Spark"] } }, "/public/v1/submit/spark_sign_frost": { @@ -5226,8 +5522,8 @@ }, "/public/v1/submit/update_fiat_on_ramp_credential": { "post": { - "summary": "Update a Fiat On Ramp Credential", - "description": "Update a fiat on ramp provider credential", + "summary": "Update a Fiat On Ramp credential", + "description": "Update a fiat on ramp provider credential.", "operationId": "PublicApiService_UpdateFiatOnRampCredential", "responses": { "200": { @@ -5290,8 +5586,8 @@ }, "/public/v1/submit/update_oauth2_credential": { "post": { - "summary": "Update an OAuth 2.0 Credential", - "description": "Update an OAuth 2.0 provider credential", + "summary": "Update an OAuth 2.0 credential", + "description": "Update an OAuth 2.0 provider credential.", "operationId": "PublicApiService_UpdateOauth2Credential", "responses": { "200": { @@ -5669,12 +5965,12 @@ } } ], - "tags": ["Organizations"] + "tags": ["Webhooks"] } }, "/public/v1/submit/upsert_swap_config": { "post": { - "summary": "Upsert swap config", + "summary": "Upsert Swap config", "description": "Enable or disable swap configuration for an organization.", "operationId": "PublicApiService_UpsertSwapConfig", "responses": { @@ -5704,6 +6000,70 @@ "tags": ["Swaps"] } }, + "/public/v1/submit/upsert_swap_fee_sponsorship_limit_config": { + "post": { + "summary": "Upsert swap fee sponsorship limits", + "description": "Replace this feature's spending window. Requires the billing parent's signed permission and activity authorization.", + "operationId": "PublicApiService_UpsertSwapFeeSponsorshipLimitConfig", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1ActivityResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1UpsertSwapFeeSponsorshipLimitConfigRequest" + } + } + ], + "tags": ["Swaps"] + } + }, + "/public/v1/submit/upsert_swap_fixed_rate_limit_config": { + "post": { + "summary": "Upsert swap fixed rate limits", + "description": "Replace this feature's spending window. Requires the billing parent's signed permission and activity authorization.", + "operationId": "PublicApiService_UpsertSwapFixedRateLimitConfig", + "responses": { + "200": { + "description": "A successful response.", + "schema": { + "$ref": "#/definitions/v1ActivityResponse" + } + }, + "default": { + "description": "An unexpected error response.", + "schema": { + "$ref": "#/definitions/rpcStatus" + } + } + }, + "parameters": [ + { + "name": "body", + "in": "body", + "required": true, + "schema": { + "$ref": "#/definitions/v1UpsertSwapFixedRateLimitConfigRequest" + } + } + ], + "tags": ["Swaps"] + } + }, "/public/v1/submit/verify_otp": { "post": { "summary": "Verify generic OTP", @@ -5738,6 +6098,8 @@ }, "/tkhq/api/v1/noop-codegen-anchor": { "post": { + "summary": "Internal codegen anchor (no-op)", + "description": "Internal no-op endpoint used to force generation of types not otherwise referenced by a public request or response. Not intended for use.", "operationId": "PublicApiService_NOOPCodegenAnchor", "responses": { "200": { @@ -5753,7 +6115,7 @@ } } }, - "tags": ["PublicApiService"] + "tags": ["Internal"] } } }, @@ -5892,6 +6254,26 @@ }, "required": ["lastFour", "cardHolderName", "cardHolderEmail"] }, + "billingUpdatePaymentMethodIntent": { + "type": "object", + "properties": { + "paymentEmail": { + "type": "string", + "description": "The email that will receive invoices for the payment method." + } + }, + "required": ["paymentEmail"] + }, + "billingUpdatePaymentMethodResult": { + "type": "object", + "properties": { + "paymentEmail": { + "type": "string", + "description": "The email address associated with the payment method." + } + }, + "required": ["paymentEmail"] + }, "datav1Tag": { "type": "object", "properties": { @@ -6171,6 +6553,32 @@ "type": "string", "enum": ["ACCESS_TYPE_WEB", "ACCESS_TYPE_API", "ACCESS_TYPE_ALL"] }, + "v1ActivePolicyStatus": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for the organization the policy belongs to." + }, + "policyId": { + "type": "string", + "description": "Unique identifier for a given policy." + }, + "active": { + "type": "boolean", + "description": "Whether the policy is currently active. A policy without a time window is always active." + }, + "timeExpr": { + "type": "string", + "description": "The policy's time expression, absent when the policy has no time window." + }, + "error": { + "type": "string", + "description": "Set when the policy's time expression could not be evaluated; the policy is reported inactive." + } + }, + "required": ["organizationId", "policyId", "active"] + }, "v1Activity": { "type": "object", "properties": { @@ -6438,7 +6846,15 @@ "ACTIVITY_TYPE_IMPORT_SECRETS", "ACTIVITY_TYPE_EXPORT_SECRETS", "ACTIVITY_TYPE_CREATE_VELOCITY_CONTROL", - "ACTIVITY_TYPE_DELETE_VELOCITY_CONTROL" + "ACTIVITY_TYPE_DELETE_VELOCITY_CONTROLS", + "ACTIVITY_TYPE_UPDATE_PAYMENT_METHOD", + "ACTIVITY_TYPE_CREATE_SWAP_QUOTE_V2", + "ACTIVITY_TYPE_EXECUTE_SWAP_V3", + "ACTIVITY_TYPE_DELETE_SECRETS", + "ACTIVITY_TYPE_EARN_CLAIM_REWARDS", + "ACTIVITY_TYPE_CREATE_SWAP_QUOTE_V3", + "ACTIVITY_TYPE_UPSERT_SWAP_FEE_SPONSORSHIP_LIMIT_CONFIG", + "ACTIVITY_TYPE_UPSERT_SWAP_FIXED_RATE_LIMIT_CONFIG" ] }, "v1AddressFormat": { @@ -6683,6 +7099,10 @@ "name": { "type": "string", "description": "The asset name" + }, + "tokenProgram": { + "type": "string", + "description": "Solana token program address that owns this mint, inferred from getTokenAccountsByOwner. TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA for classic SPL Token, TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb for Token-2022. Empty for native SOL and non-Solana assets." } } }, @@ -8759,52 +9179,130 @@ }, "required": ["signWith", "inputToken", "outputToken", "inputAmount"] }, - "v1CreateSwapQuoteRequest": { + "v1CreateSwapQuoteIntentV2": { "type": "object", "properties": { - "type": { + "signWith": { "type": "string", - "enum": ["ACTIVITY_TYPE_CREATE_SWAP_QUOTE"] + "description": "Wallet account address used to price the executable provider quote. Private Key identifiers are not supported." }, - "timestampMs": { + "inputToken": { "type": "string", - "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + "description": "CAIP-19 asset ID for the input asset. The chain is derived from this value." }, - "organizationId": { + "outputToken": { "type": "string", - "description": "Unique identifier for a given Organization." + "description": "CAIP-19 asset ID for the output asset." }, - "parameters": { - "$ref": "#/definitions/v1CreateSwapQuoteIntent" + "inputAmount": { + "type": "string", + "description": "Base-unit amount of the input asset." }, - "generateAppProofs": { - "type": "boolean" - } - }, - "required": ["type", "timestampMs", "organizationId", "parameters"] - }, - "v1CreateSwapQuoteResult": { - "type": "object", - "properties": { - "quotes": { - "type": "array", - "items": { - "type": "object", - "$ref": "#/definitions/v1SwapQuote" - }, - "description": "One or more provider quotes for this request. Today this contains a single Relay quote; pass quotes[i].quoteId to execute_swap_v2 to bind execution." + "slippageBps": { + "type": "string", + "description": "Provider-neutral maximum allowed slippage in basis points. Turnkey converts this value to each provider's request format. When omitted, each provider applies its default slippage behavior." + }, + "destinationAddress": { + "type": "string", + "description": "Raw public address that receives the output asset. Required for cross-protocol swaps. The address must match the output token protocol. Wallet account IDs, private key IDs, and CAIP account or asset identifiers are not supported." } }, - "required": ["quotes"] + "required": ["signWith", "inputToken", "outputToken", "inputAmount"] }, - "v1CreateTvcAppIntent": { + "v1CreateSwapQuoteIntentV3": { "type": "object", "properties": { - "name": { + "signWith": { "type": "string", - "description": "The name of the new TVC application" + "description": "Wallet account address used to price the executable provider quote. Private Key identifiers are not supported." }, - "quorumPublicKey": { + "inputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the input asset. The chain is derived from this value." + }, + "outputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the output asset." + }, + "inputAmount": { + "type": "string", + "description": "Base-unit amount of the input asset." + }, + "slippageBps": { + "type": "string", + "description": "Provider-neutral maximum allowed slippage in basis points. Turnkey converts this value to each provider's request format. When omitted, each provider applies its default slippage behavior." + }, + "destinationAddress": { + "type": "string", + "description": "Raw public address that receives the output asset. Required for cross-protocol swaps. The address must match the output token protocol. Wallet account IDs, private key IDs, and CAIP account or asset identifiers are not supported." + }, + "feeSponsorship": { + "type": "boolean" + }, + "fixedRate": { + "type": "boolean" + } + }, + "required": ["signWith", "inputToken", "outputToken", "inputAmount"] + }, + "v1CreateSwapQuoteRequest": { + "type": "object", + "properties": { + "type": { + "type": "string", + "enum": ["ACTIVITY_TYPE_CREATE_SWAP_QUOTE"] + }, + "timestampMs": { + "type": "string", + "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "parameters": { + "$ref": "#/definitions/v1CreateSwapQuoteIntent" + }, + "generateAppProofs": { + "type": "boolean" + } + }, + "required": ["type", "timestampMs", "organizationId", "parameters"] + }, + "v1CreateSwapQuoteResult": { + "type": "object", + "properties": { + "quotes": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SwapQuote" + }, + "description": "One or more provider quotes for this request. Today this contains a single Relay quote; pass quotes[i].quoteId to execute_swap_v2 to bind execution." + } + }, + "required": ["quotes"] + }, + "v1CreateSwapQuoteResultV2": { + "type": "object", + "properties": { + "quotes": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1SwapQuoteV2" + } + } + } + }, + "v1CreateTvcAppIntent": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "The name of the new TVC application" + }, + "quorumPublicKey": { "type": "string", "description": "Quorum public key to use for this application" }, @@ -8967,6 +9465,16 @@ "type": "integer", "format": "int64", "description": "Optional desired replica count for this deployment." + }, + "instanceSizeCpus": { + "type": "integer", + "format": "int64", + "description": "Optional desired instance cpu count." + }, + "instanceSizeRam": { + "type": "integer", + "format": "int64", + "description": "Optional desired instance memory size in GiB." } }, "required": [ @@ -9090,6 +9598,30 @@ }, "required": ["path", "operatorName"] }, + "v1CreateTvcOperatorRequest": { + "type": "object", + "properties": { + "type": { + "type": "string", + "enum": ["ACTIVITY_TYPE_CREATE_TVC_OPERATOR"] + }, + "timestampMs": { + "type": "string", + "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "parameters": { + "$ref": "#/definitions/v1CreateTvcOperatorIntent" + }, + "generateAppProofs": { + "type": "boolean" + } + }, + "required": ["type", "timestampMs", "organizationId", "parameters"] + }, "v1CreateTvcOperatorResult": { "type": "object", "properties": { @@ -9135,6 +9667,30 @@ }, "required": ["threshold", "operatorEncryptKeys"] }, + "v1CreateTvcQuorumKeyRequest": { + "type": "object", + "properties": { + "type": { + "type": "string", + "enum": ["ACTIVITY_TYPE_CREATE_TVC_QUORUM_KEY"] + }, + "timestampMs": { + "type": "string", + "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "parameters": { + "$ref": "#/definitions/v1CreateTvcQuorumKeyIntent" + }, + "generateAppProofs": { + "type": "boolean" + } + }, + "required": ["type", "timestampMs", "organizationId", "parameters"] + }, "v1CreateTvcQuorumKeyResult": { "type": "object", "properties": { @@ -9329,30 +9885,6 @@ }, "required": ["name", "dataSource", "aggregation", "identifier"] }, - "v1CreateVelocityControlRequest": { - "type": "object", - "properties": { - "type": { - "type": "string", - "enum": ["ACTIVITY_TYPE_CREATE_VELOCITY_CONTROL"] - }, - "timestampMs": { - "type": "string", - "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." - }, - "organizationId": { - "type": "string", - "description": "Unique identifier for a given Organization." - }, - "parameters": { - "$ref": "#/definitions/v1CreateVelocityControlIntent" - }, - "generateAppProofs": { - "type": "boolean" - } - }, - "required": ["type", "timestampMs", "organizationId", "parameters"] - }, "v1CreateVelocityControlResult": { "type": "object", "properties": { @@ -10150,6 +10682,53 @@ }, "required": ["privateKeyIds"] }, + "v1DeleteSecretsIntent": { + "type": "object", + "properties": { + "secretIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Unique identifiers of the secrets to delete. Must contain between 1 and 32 distinct UUIDs. All secrets must belong to the organization." + } + }, + "required": ["secretIds"] + }, + "v1DeleteSecretsRequest": { + "type": "object", + "properties": { + "type": { + "type": "string", + "enum": ["ACTIVITY_TYPE_DELETE_SECRETS"] + }, + "timestampMs": { + "type": "string", + "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "parameters": { + "$ref": "#/definitions/v1DeleteSecretsIntent" + } + }, + "required": ["type", "timestampMs", "organizationId", "parameters"] + }, + "v1DeleteSecretsResult": { + "type": "object", + "properties": { + "secretIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Unique identifiers of the deleted secrets, in the order requested." + } + }, + "required": ["secretIds"] + }, "v1DeleteSmartContractInterfaceIntent": { "type": "object", "properties": { @@ -10432,47 +11011,31 @@ }, "required": ["userIds"] }, - "v1DeleteVelocityControlIntent": { - "type": "object", - "properties": { - "velocityControlId": { - "type": "string" - } - }, - "required": ["velocityControlId"] - }, - "v1DeleteVelocityControlRequest": { + "v1DeleteVelocityControlsIntent": { "type": "object", "properties": { - "type": { - "type": "string", - "enum": ["ACTIVITY_TYPE_DELETE_VELOCITY_CONTROL"] - }, - "timestampMs": { - "type": "string", - "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." - }, - "organizationId": { - "type": "string", - "description": "Unique identifier for a given Organization." - }, - "parameters": { - "$ref": "#/definitions/v1DeleteVelocityControlIntent" - }, - "generateAppProofs": { - "type": "boolean" + "velocityControlIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of unique identifiers for Velocity Controls within an Organization." } }, - "required": ["type", "timestampMs", "organizationId", "parameters"] + "required": ["velocityControlIds"] }, - "v1DeleteVelocityControlResult": { + "v1DeleteVelocityControlsResult": { "type": "object", "properties": { - "velocityControlId": { - "type": "string" + "velocityControlIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A list of unique identifiers for the deleted Velocity Controls." } }, - "required": ["velocityControlId"] + "required": ["velocityControlIds"] }, "v1DeleteWalletAccountsIntent": { "type": "object", @@ -10656,7 +11219,8 @@ "deploymentId", "readyReplicas", "desiredReplicas", - "lastUpdatedTime" + "lastUpdatedTime", + "provisioningState" ] }, "v1DisableAuthProxyIntent": { @@ -10685,6 +11249,58 @@ }, "required": ["privateKeyId"] }, + "v1EarnClaimRewardsIntent": { + "type": "object", + "properties": { + "signWith": { + "type": "string", + "description": "A Turnkey-managed wallet address the rewards are attributed to. The claim transaction is signed by this wallet and the Merkl Distributor transfers every reward token to it." + }, + "caip2": { + "type": "string", + "description": "CAIP-2 chain to claim rewards on (e.g. 'eip155:8453'). Rewards accrue per chain; see ListEarnRewards." + }, + "sponsor": { + "type": "boolean", + "description": "Whether to sponsor this transaction via Gas Station." + } + }, + "required": ["signWith", "caip2"] + }, + "v1EarnClaimRewardsRequest": { + "type": "object", + "properties": { + "type": { + "type": "string", + "enum": ["ACTIVITY_TYPE_EARN_CLAIM_REWARDS"] + }, + "timestampMs": { + "type": "string", + "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "parameters": { + "$ref": "#/definitions/v1EarnClaimRewardsIntent" + }, + "generateAppProofs": { + "type": "boolean" + } + }, + "required": ["type", "timestampMs", "organizationId", "parameters"] + }, + "v1EarnClaimRewardsResult": { + "type": "object", + "properties": { + "claimRequestId": { + "type": "string", + "description": "Identifier to poll claim status and tx hash via GetEarnClaimRewardsStatus." + } + }, + "required": ["claimRequestId"] + }, "v1EarnDeployWrapperIntent": { "type": "object", "properties": { @@ -10692,7 +11308,7 @@ "type": "string", "description": "Address of the underlying yield vault to wrap (from the ListEarnVaults catalog)." }, - "chainCaip2": { + "caip2": { "type": "string", "enum": [ "eip155:1", @@ -10700,7 +11316,11 @@ "eip155:42161", "eip155:137", "eip155:56", - "eip155:4217" + "eip155:4217", + "solana:mainnet", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", + "solana:devnet", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1" ], "description": "CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base)." }, @@ -10713,12 +11333,7 @@ "description": "The wallet address that receives the client's fee payouts on-chain. Must be a Turnkey-managed wallet address." } }, - "required": [ - "vaultAddress", - "chainCaip2", - "clientFeeBps", - "clientFeeWallet" - ] + "required": ["vaultAddress", "caip2", "clientFeeBps", "clientFeeWallet"] }, "v1EarnDeployWrapperRequest": { "type": "object", @@ -10777,7 +11392,7 @@ "type": "string", "description": "Amount of the underlying asset to deposit, in raw on-chain units (e.g., '1000000' for 1 USDC at 6 decimals)." }, - "chainCaip2": { + "caip2": { "type": "string", "enum": [ "eip155:1", @@ -10785,7 +11400,11 @@ "eip155:42161", "eip155:137", "eip155:56", - "eip155:4217" + "eip155:4217", + "solana:mainnet", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", + "solana:devnet", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1" ], "description": "CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base)." }, @@ -10794,7 +11413,7 @@ "description": "Whether to sponsor this transaction via Gas Station." } }, - "required": ["wrapperAddress", "signWith", "assets", "chainCaip2"] + "required": ["wrapperAddress", "signWith", "assets", "caip2"] }, "v1EarnDepositRequest": { "type": "object", @@ -10908,6 +11527,26 @@ "$ref": "#/definitions/v1EarnVaultExposure" }, "description": "The underlying markets the vault allocates into, ranked by supplied amount descending. Only populated when the request sets include_exposure, and only for providers that expose an allocation breakdown (Morpho)." + }, + "forceDeallocatableLiquidity": { + "type": "string", + "description": "Additional assets withdrawable from the underlying vault by force-deallocating its non-liquidity adapters at zero penalty, in raw on-chain units of the underlying asset. Additive to liquidity. Empty when the provider does not report it." + }, + "forceDeallocatableLiquidityDisplay": { + "$ref": "#/definitions/v1EarnValueDisplay", + "description": "Normalized force-deallocatable liquidity values for display purposes only (usd + crypto). Do not do arithmetic with these; use force_deallocatable_liquidity instead." + }, + "deployStatus": { + "type": "string", + "description": "On-chain status of the wrapper deployment: PENDING, COMPLETED, or FAILED. Only a COMPLETED wrapper is usable. Empty when no deploy is recorded for the wrapper." + }, + "deployRequestId": { + "type": "string", + "description": "Request id of the wrapper's most recent deploy, for polling GetEarnDeployStatus. Empty when no deploy is recorded." + }, + "deployError": { + "type": "string", + "description": "Failure detail when deploy_status is FAILED." } } }, @@ -10983,7 +11622,78 @@ }, "v1EarnProvider": { "type": "string", - "enum": ["EARN_PROVIDER_MORPHO", "EARN_PROVIDER_AAVE"] + "enum": [ + "EARN_PROVIDER_MORPHO", + "EARN_PROVIDER_AAVE", + "EARN_PROVIDER_KAMINO" + ] + }, + "v1EarnReward": { + "type": "object", + "properties": { + "caip2": { + "type": "string", + "description": "CAIP-2 chain the reward is claimable on (e.g. 'eip155:8453')." + }, + "caip19": { + "type": "string", + "description": "CAIP-19 asset ID of the reward token (e.g. 'eip155:8453/erc20:0xBAa5...'). Reward tokens are campaign-specific and unrelated to the position's underlying asset." + }, + "symbol": { + "type": "string", + "description": "Symbol of the reward token (e.g. 'MORPHO'), as reported by Merkl." + }, + "decimals": { + "type": "integer", + "format": "int32", + "description": "Decimals of the reward token." + }, + "claimable": { + "type": "string", + "description": "Amount claimable now, in raw on-chain units of the reward token." + }, + "claimed": { + "type": "string", + "description": "Lifetime amount already claimed, in raw on-chain units of the reward token." + }, + "pending": { + "type": "string", + "description": "Amount accrued but not yet claimable (not yet in a live on-chain merkle root; roots update roughly every 8 hours), in raw on-chain units of the reward token." + }, + "display": { + "$ref": "#/definitions/v1EarnRewardDisplay", + "description": "USD + crypto renderings for display only. Do not do arithmetic with these." + } + } + }, + "v1EarnRewardDisplay": { + "type": "object", + "properties": { + "claimableUsd": { + "type": "string", + "description": "Claimable amount in USD, for display only. Empty when the token is unpriced." + }, + "claimableCrypto": { + "type": "string", + "description": "Claimable amount in the reward token's own units, for display only." + }, + "claimedUsd": { + "type": "string", + "description": "Lifetime claimed amount in USD, for display only. Empty when the token is unpriced." + }, + "claimedCrypto": { + "type": "string", + "description": "Lifetime claimed amount in the reward token's own units, for display only." + }, + "pendingUsd": { + "type": "string", + "description": "Pending amount in USD, for display only. Empty when the token is unpriced." + }, + "pendingCrypto": { + "type": "string", + "description": "Pending amount in the reward token's own units, for display only." + } + } }, "v1EarnSetWrapperStateIntent": { "type": "object", @@ -11096,6 +11806,14 @@ "liquidityDisplay": { "$ref": "#/definitions/v1EarnValueDisplay", "description": "Normalized liquidity values for display purposes only (usd + crypto). Do not do arithmetic with these; use liquidity instead." + }, + "forceDeallocatableLiquidity": { + "type": "string", + "description": "Additional assets withdrawable from the vault by force-deallocating its non-liquidity adapters at zero penalty, in raw on-chain units of the underlying asset. Additive to liquidity. Empty when the provider does not report it." + }, + "forceDeallocatableLiquidityDisplay": { + "$ref": "#/definitions/v1EarnValueDisplay", + "description": "Normalized force-deallocatable liquidity values for display purposes only (usd + crypto). Do not do arithmetic with these; use force_deallocatable_liquidity instead." } } }, @@ -11143,7 +11861,7 @@ "type": "string", "description": "A Wallet account address or Private Key address to withdraw to and sign with. Must be an on-chain address; Private Key identifiers are not supported." }, - "chainCaip2": { + "caip2": { "type": "string", "enum": [ "eip155:1", @@ -11151,7 +11869,11 @@ "eip155:42161", "eip155:137", "eip155:56", - "eip155:4217" + "eip155:4217", + "solana:mainnet", + "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", + "solana:devnet", + "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1" ], "description": "CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base)." }, @@ -11164,7 +11886,7 @@ "description": "The amount of the underlying asset to withdraw, in raw on-chain units. Pass 'MAX' to withdraw the entire position." } }, - "required": ["wrapperAddress", "signWith", "chainCaip2", "amountValue"] + "required": ["wrapperAddress", "signWith", "caip2", "amountValue"] }, "v1EarnWithdrawRequest": { "type": "object", @@ -11599,7 +12321,11 @@ "eip155:42161", "eip155:4217", "eip155:42431", - "eip155:421614" + "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" ], "description": "CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." } @@ -11645,7 +12371,11 @@ "eip155:42161", "eip155:4217", "eip155:42431", - "eip155:421614" + "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" ], "description": "CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." }, @@ -11713,7 +12443,11 @@ "eip155:42161", "eip155:4217", "eip155:42431", - "eip155:421614" + "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" ], "description": "CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." }, @@ -11852,6 +12586,10 @@ "turnkey": { "$ref": "#/definitions/v1TransactionHistoryTurnkey", "description": "Turnkey-specific metadata for transactions originated by Turnkey." + }, + "executionFailed": { + "type": "boolean", + "description": "Whether the transaction failed during on-chain execution. Omitted when execution outcome is unavailable." } }, "required": [ @@ -11887,7 +12625,11 @@ "eip155:143", "eip155:10143", "eip155:42161", - "eip155:421614" + "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" ], "description": "CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." }, @@ -12042,6 +12784,64 @@ "sponsor" ] }, + "v1ExecuteSwapIntentV3": { + "type": "object", + "properties": { + "quoteId": { + "type": "string", + "description": "Quote identifier returned by create_swap_quote. Execution is bound to this quote; the signer is derived from the quote and must not be resupplied." + }, + "inputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the input asset." + }, + "inputAmount": { + "type": "string", + "description": "Exact base-unit amount of the input asset committed by the quote." + }, + "outputToken": { + "type": "string", + "description": "CAIP-19 asset ID for the output asset." + }, + "quotedOutputAmount": { + "type": "string", + "description": "Exact quoted base-unit output amount committed by the quote." + }, + "minOutputAmount": { + "type": "string", + "description": "Exact minimum base-unit output committed by the quote." + }, + "sponsor": { + "type": "boolean", + "description": "Whether the quoted transaction is sponsored." + }, + "evmNonce": { + "type": "string", + "description": "Exact EVM sender (EOA account) nonce. Valid only for a non-sponsored EVM swap. Honored for already-delegated (Type-2) batch swaps and single-call swaps; ignored for not-yet-delegated EIP-7702 (Type-4) batches where the outer nonce is derived from the authorization. Prefer gas_station_nonce for batch replay protection and use the nonces endpoint to fetch it. Omit to auto-fetch." + }, + "recentBlockhash": { + "type": "string", + "description": "Exact Solana recent blockhash. Valid only for a Solana swap, including sponsored swaps. Omit to auto-fetch." + }, + "gasStationNonce": { + "type": "string", + "description": "Exact gas station delegate contract nonce used in the BatchExecution EIP-712 message. Valid for sponsored EVM swaps and non-sponsored EVM swaps that execute as a multi-call batch (for example ERC-20 approve + swap). This is the replay-protection nonce for gas-station batches; use the nonces endpoint to fetch it. Omit to auto-fetch." + }, + "destinationAddress": { + "type": "string", + "description": "Raw public address that receives the output asset. Required for cross-protocol swaps. The address must match the output token protocol. Wallet account IDs, private key IDs, and CAIP account or asset identifiers are not supported." + } + }, + "required": [ + "quoteId", + "inputToken", + "inputAmount", + "outputToken", + "quotedOutputAmount", + "minOutputAmount", + "sponsor" + ] + }, "v1ExecuteSwapRequest": { "type": "object", "properties": { @@ -12150,6 +12950,14 @@ "encryptionSuite": { "$ref": "#/definitions/v1TransportEncryptionSuite", "description": "Transport encryption suite used for the exported secret." + }, + "requestContext": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1KeyValue" + }, + "description": "Bind metadata to the request." } }, "required": ["secretId", "targetPublicKey", "encryptionSuite"] @@ -12334,7 +13142,9 @@ "FEATURE_NAME_AUTH_PROXY", "FEATURE_NAME_SOLANA_RENT_PREFUND_ENABLED", "FEATURE_NAME_SWAP_CONFIG", - "FEATURE_NAME_EARN_CONFIG" + "FEATURE_NAME_EARN_CONFIG", + "FEATURE_NAME_SWAP_FEE_SPONSORSHIP", + "FEATURE_NAME_SWAP_FIXED_RATE" ] }, "v1FiatOnRampBlockchainNetwork": { @@ -12471,6 +13281,35 @@ "FIAT_ON_RAMP_PROVIDER_MOONPAY" ] }, + "v1GetActivePoliciesRequest": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given organization." + } + }, + "required": ["organizationId"] + }, + "v1GetActivePoliciesResponse": { + "type": "object", + "properties": { + "statuses": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1ActivePolicyStatus" + }, + "description": "The active/inactive status of every policy in the organization." + }, + "evaluatedAtMs": { + "type": "string", + "format": "uint64", + "description": "The enclave's trusted timestamp (Unix epoch milliseconds) used to evaluate every policy." + } + }, + "required": ["statuses", "evaluatedAtMs"] + }, "v1GetActivitiesRequest": { "type": "object", "properties": { @@ -12687,16 +13526,49 @@ "properties": { "organizationId": { "type": "string", - "description": "Unique identifier for a given Organization." + "description": "Unique identifier for a given Organization." + }, + "ephemeralKey": { + "type": "string", + "description": "Hex encoded ephemeral public key." + } + }, + "required": ["organizationId", "ephemeralKey"] + }, + "v1GetClaimEarnFeesStatusRequest": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "claimRequestId": { + "type": "string", + "description": "The claim_request_id returned by ClaimEarnFees." + } + }, + "required": ["organizationId", "claimRequestId"] + }, + "v1GetClaimEarnFeesStatusResponse": { + "type": "object", + "properties": { + "status": { + "type": "string", + "enum": ["PENDING", "COMPLETED", "FAILED"], + "description": "Status of the fee claim." }, - "ephemeralKey": { + "claimTxHash": { "type": "string", - "description": "Hex encoded ephemeral public key." + "description": "Transaction hash of the fee claim, once available." + }, + "error": { + "type": "string", + "description": "Reason the fee claim transaction failed, when status is FAILED." } }, - "required": ["organizationId", "ephemeralKey"] + "required": ["status"] }, - "v1GetClaimEarnFeesStatusRequest": { + "v1GetEarnClaimRewardsStatusRequest": { "type": "object", "properties": { "organizationId": { @@ -12705,26 +13577,26 @@ }, "claimRequestId": { "type": "string", - "description": "The claim_request_id returned by ClaimEarnFees." + "description": "The claim_request_id returned by EarnClaimRewards." } }, "required": ["organizationId", "claimRequestId"] }, - "v1GetClaimEarnFeesStatusResponse": { + "v1GetEarnClaimRewardsStatusResponse": { "type": "object", "properties": { "status": { "type": "string", "enum": ["PENDING", "COMPLETED", "FAILED"], - "description": "Status of the fee claim." + "description": "Status of the rewards claim." }, "claimTxHash": { "type": "string", - "description": "Transaction hash of the fee claim, once available." + "description": "Transaction hash of the rewards claim, once available." }, "error": { "type": "string", - "description": "Reason the fee claim transaction failed, when status is FAILED." + "description": "Reason the rewards claim transaction failed, when status is FAILED." } }, "required": ["status"] @@ -13011,7 +13883,11 @@ "eip155:42161", "eip155:4217", "eip155:42431", - "eip155:421614" + "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" ], "description": "CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." }, @@ -13434,6 +14310,27 @@ }, "required": ["organizationIds"] }, + "v1GetSwapSponsorshipUsageRequest": { + "type": "object", + "properties": { + "organizationId": { + "type": "string" + } + }, + "required": ["organizationId"] + }, + "v1GetSwapSponsorshipUsageResponse": { + "type": "object", + "properties": { + "feeSponsorship": { + "$ref": "#/definitions/v1SwapSponsorshipFeature" + }, + "fixedRate": { + "$ref": "#/definitions/v1SwapSponsorshipFeature" + } + }, + "required": ["feeSponsorship", "fixedRate"] + }, "v1GetSwapStatusRequest": { "type": "object", "properties": { @@ -13501,6 +14398,10 @@ "error": { "$ref": "#/definitions/v1SwapError", "description": "Normalized failure details, present whenever status is FAILED." + }, + "destinationAddress": { + "type": "string", + "description": "Address that receives the output asset." } }, "required": [ @@ -13571,6 +14472,10 @@ "organizationId": { "type": "string", "description": "Unique identifier for a given organization." + }, + "isLive": { + "type": "boolean", + "description": "Filter TVC Apps by whether they have a live deployment. If omitted, all TVC Apps are returned." } }, "required": ["organizationId"] @@ -13627,6 +14532,40 @@ }, "required": ["entries"] }, + "v1GetTvcDeploymentProvisioningDetailsRequest": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "deploymentId": { + "type": "string", + "description": "Unique identifier for a given TVC Deployment." + } + }, + "required": ["organizationId", "deploymentId"] + }, + "v1GetTvcDeploymentProvisioningDetailsResponse": { + "type": "object", + "properties": { + "attestationDocument": { + "type": "string", + "format": "byte", + "description": "The attestation document of the provisioning enclave. Present only when a deployment is awaiting provisioning." + }, + "manifestEnvelope": { + "type": "string", + "format": "byte", + "description": "The manifest envelope containing the TVC deployment's manifest and signatures. Present only when a deployment is awaiting provisioning." + }, + "provisioningState": { + "$ref": "#/definitions/v1ProvisioningState", + "description": "Current provisioning state." + } + }, + "required": ["provisioningState"] + }, "v1GetTvcDeploymentRequest": { "type": "object", "properties": { @@ -13651,6 +14590,29 @@ }, "required": ["tvcDeployment"] }, + "v1GetTvcOperatorsRequest": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given organization." + } + }, + "required": ["organizationId"] + }, + "v1GetTvcOperatorsResponse": { + "type": "object", + "properties": { + "tvcOperators": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1TvcOperator" + } + } + }, + "required": ["tvcOperators"] + }, "v1GetTvcQosVersionsRequest": { "type": "object", "properties": { @@ -13678,6 +14640,29 @@ }, "required": ["availableVersions", "latestVersion"] }, + "v1GetTvcQuorumKeysRequest": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given organization." + } + }, + "required": ["organizationId"] + }, + "v1GetTvcQuorumKeysResponse": { + "type": "object", + "properties": { + "tvcQuorumKeys": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1TvcQuorumKey" + } + } + }, + "required": ["tvcQuorumKeys"] + }, "v1GetUserRequest": { "type": "object", "properties": { @@ -13726,27 +14711,6 @@ }, "required": ["users"] }, - "v1GetVelocityControlRequest": { - "type": "object", - "properties": { - "organizationId": { - "type": "string" - }, - "velocityControlId": { - "type": "string" - } - }, - "required": ["organizationId", "velocityControlId"] - }, - "v1GetVelocityControlResponse": { - "type": "object", - "properties": { - "velocityControl": { - "$ref": "#/definitions/v1VelocityControl" - } - }, - "required": ["velocityControl"] - }, "v1GetVerifiedSubOrgIdsRequest": { "type": "object", "properties": { @@ -13756,7 +14720,7 @@ }, "filterType": { "type": "string", - "description": "Specifies the type of filter to apply, i.e 'EMAIL', 'PHONE_NUMBER'." + "description": "Specifies the type of filter to apply, i.e 'EMAIL', 'PHONE_NUMBER', 'OIDC_TOKEN', 'OAUTH_CLAIM', or 'PUBLIC_KEY'" }, "filterValue": { "type": "string", @@ -13880,6 +14844,10 @@ "eip155:4217", "eip155:42431", "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002", "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1" ], @@ -15433,8 +16401,32 @@ "createVelocityControlIntent": { "$ref": "#/definitions/v1CreateVelocityControlIntent" }, - "deleteVelocityControlIntent": { - "$ref": "#/definitions/v1DeleteVelocityControlIntent" + "deleteVelocityControlsIntent": { + "$ref": "#/definitions/v1DeleteVelocityControlsIntent" + }, + "updatePaymentMethodIntent": { + "$ref": "#/definitions/billingUpdatePaymentMethodIntent" + }, + "createSwapQuoteIntentV2": { + "$ref": "#/definitions/v1CreateSwapQuoteIntentV2" + }, + "executeSwapIntentV3": { + "$ref": "#/definitions/v1ExecuteSwapIntentV3" + }, + "deleteSecretsIntent": { + "$ref": "#/definitions/v1DeleteSecretsIntent" + }, + "earnClaimRewardsIntent": { + "$ref": "#/definitions/v1EarnClaimRewardsIntent" + }, + "createSwapQuoteIntentV3": { + "$ref": "#/definitions/v1CreateSwapQuoteIntentV3" + }, + "upsertSwapFeeSponsorshipLimitConfigIntent": { + "$ref": "#/definitions/v1UpsertSwapFeeSponsorshipLimitConfigIntent" + }, + "upsertSwapFixedRateLimitConfigIntent": { + "$ref": "#/definitions/v1UpsertSwapFixedRateLimitConfigIntent" } } }, @@ -15608,6 +16600,37 @@ } } }, + "v1ListEarnRewardsRequest": { + "type": "object", + "properties": { + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "walletAddress": { + "type": "string", + "description": "The wallet address to return rewards for." + }, + "caip2": { + "type": "string", + "description": "Optional filter: only return rewards on this chain (e.g. 'eip155:8453'). When unset, every chain the organization has deployed Earn wrappers on is queried." + } + }, + "required": ["organizationId", "walletAddress"] + }, + "v1ListEarnRewardsResponse": { + "type": "object", + "properties": { + "rewards": { + "type": "array", + "items": { + "type": "object", + "$ref": "#/definitions/v1EarnReward" + }, + "description": "The wallet's rewards, one entry per (chain, reward token), sorted by chain then token. Entries where every amount is zero are omitted." + } + } + }, "v1ListEarnVaultsRequest": { "type": "object", "properties": { @@ -15708,7 +16731,11 @@ "eip155:42431", "eip155:421614", "eip155:56", - "eip155:97" + "eip155:97", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002" ], "description": "EVM CAIP-2 chain ID (e.g., 'eip155:1' for Ethereum mainnet)." }, @@ -15905,6 +16932,10 @@ "eip155:4217", "eip155:42431", "eip155:421614", + "eip155:4663", + "eip155:46630", + "eip155:5042", + "eip155:5042002", "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp", "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1" ], @@ -15950,34 +16981,6 @@ }, "required": ["userTags"] }, - "v1ListVelocityControlsRequest": { - "type": "object", - "properties": { - "organizationId": { - "type": "string" - }, - "paginationOptions": { - "$ref": "#/definitions/v1Pagination" - } - }, - "required": ["organizationId"] - }, - "v1ListVelocityControlsResponse": { - "type": "object", - "properties": { - "velocityControls": { - "type": "array", - "items": { - "type": "object", - "$ref": "#/definitions/v1VelocityControl" - } - }, - "pageInfo": { - "$ref": "#/definitions/v1PageInfo" - } - }, - "required": ["velocityControls", "pageInfo"] - }, "v1ListWebhookEndpointsRequest": { "type": "object", "properties": { @@ -16803,6 +17806,27 @@ "shareApprovalBundle" ] }, + "v1PostTvcQuorumKeyShareRequest": { + "type": "object", + "properties": { + "type": { + "type": "string", + "enum": ["ACTIVITY_TYPE_POST_TVC_QUORUM_KEY_SHARE"] + }, + "timestampMs": { + "type": "string", + "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "parameters": { + "$ref": "#/definitions/v1PostTvcQuorumKeyShareIntent" + } + }, + "required": ["type", "timestampMs", "organizationId", "parameters"] + }, "v1PostTvcQuorumKeyShareResult": { "type": "object", "properties": { @@ -17013,6 +18037,30 @@ "appQuorumKey" ] }, + "v1ReEncryptTvcQuorumKeyShareRequest": { + "type": "object", + "properties": { + "type": { + "type": "string", + "enum": ["ACTIVITY_TYPE_RE_ENCRYPT_TVC_QUORUM_KEY_SHARE"] + }, + "timestampMs": { + "type": "string", + "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "parameters": { + "$ref": "#/definitions/v1ReEncryptTvcQuorumKeyShareIntent" + }, + "generateAppProofs": { + "type": "boolean" + } + }, + "required": ["type", "timestampMs", "organizationId", "parameters"] + }, "v1ReEncryptTvcQuorumKeyShareResult": { "type": "object", "properties": { @@ -17687,8 +18735,26 @@ "createVelocityControlResult": { "$ref": "#/definitions/v1CreateVelocityControlResult" }, - "deleteVelocityControlResult": { - "$ref": "#/definitions/v1DeleteVelocityControlResult" + "deleteVelocityControlsResult": { + "$ref": "#/definitions/v1DeleteVelocityControlsResult" + }, + "updatePaymentMethodResult": { + "$ref": "#/definitions/billingUpdatePaymentMethodResult" + }, + "deleteSecretsResult": { + "$ref": "#/definitions/v1DeleteSecretsResult" + }, + "earnClaimRewardsResult": { + "$ref": "#/definitions/v1EarnClaimRewardsResult" + }, + "createSwapQuoteResultV2": { + "$ref": "#/definitions/v1CreateSwapQuoteResultV2" + }, + "upsertSwapFeeSponsorshipLimitConfigResult": { + "$ref": "#/definitions/v1UpsertSwapFeeSponsorshipLimitConfigResult" + }, + "upsertSwapFixedRateLimitConfigResult": { + "$ref": "#/definitions/v1UpsertSwapFixedRateLimitConfigResult" } } }, @@ -18184,15 +19250,15 @@ "properties": { "r": { "type": "string", - "description": "Component of an ECSDA signature." + "description": "Component of a cryptographic signature, meaning varies based on signing scheme." }, "s": { "type": "string", - "description": "Component of an ECSDA signature." + "description": "Component of a cryptographic signature, meaning varies based on signing scheme." }, "v": { "type": "string", - "description": "Component of an ECSDA signature." + "description": "Recovery ID for ECDSA signatures, \"00\" otherwise." } }, "required": ["r", "s", "v"] @@ -18424,7 +19490,7 @@ "properties": { "unsignedTransaction": { "type": "string", - "description": "Base64-encoded serialized unsigned Solana transaction" + "description": "Hex-encoded serialized unsigned Solana transaction in full wire format. Legacy/V0 transactions allow 1232 bytes. V1 allows 4096 bytes with up to 12 trailing 64-byte signature slots, including the paymaster for sponsored transactions. Fill unsigned slots with zeroes." }, "signWith": { "type": "string", @@ -18458,14 +19524,14 @@ "properties": { "unsignedTransaction": { "type": "string", - "description": "Hex-encoded serialized unsigned Solana transaction (full wire format with zeroed signature placeholders)" + "description": "Hex-encoded serialized unsigned Solana transaction in full wire format. Legacy/V0 transactions allow 1232 bytes. V1 allows 4096 bytes with up to 12 trailing 64-byte signature slots, including the paymaster for sponsored transactions. Fill unsigned slots with zeroes." }, "signWiths": { "type": "array", "items": { "type": "string" }, - "description": "Ordered Solana signer addresses Turnkey signs with. Between 1 and 16 signers. For sponsored transactions this must list every required signer of the transaction in transaction order." + "description": "Ordered Solana signer addresses Turnkey signs with. Between 1 and 16 signers for legacy/V0, or up to 12 for V1 (11 when sponsored). For sponsored transactions this must list every required signer of the transaction in transaction order." }, "sponsor": { "type": "boolean", @@ -18581,6 +19647,10 @@ "turnkey": { "$ref": "#/definitions/v1TransactionHistoryTurnkey", "description": "Turnkey-specific metadata for transactions originated by Turnkey." + }, + "executionFailed": { + "type": "boolean", + "description": "Whether the transaction failed during on-chain execution. Omitted when execution outcome is unavailable." } }, "required": [ @@ -19280,14 +20350,59 @@ "$ref": "#/definitions/v1TxError", "description": "Origin-chain transaction failure details, present when reason is ORIGIN_TRANSACTION_FAILED and details are available." }, - "providerReason": { + "providerReason": { + "type": "string", + "description": "Optional detail from the swap provider about why the fill did not complete, when available." + } + }, + "required": ["reason", "message"] + }, + "v1SwapQuote": { + "type": "object", + "properties": { + "quoteId": { + "type": "string", + "description": "Identifier for this provider quote. Pass this value to execute_swap_v2 to bind execution to this exact quote. The signer is derived from the quote; clients do not resupply sign_with on execute." + }, + "provider": { + "type": "string", + "description": "Swap provider that produced this quote." + }, + "outputAmount": { + "type": "string", + "description": "Estimated base-unit amount of the output asset." + }, + "minOutputAmount": { + "type": "string", + "description": "Minimum acceptable base-unit amount of the output asset after slippage." + }, + "expiresAt": { + "type": "string", + "description": "Quote expiration as a millisecond epoch string." + }, + "slippageBps": { + "type": "string", + "description": "Effective total slippage tolerance in basis points for this quote, taken from the provider response when present. When the request omits input slippage_bps, the provider may calculate this value." + }, + "clientFeeBps": { + "type": "string", + "description": "Client fee in basis points applied for this pair. Informational only; already reflected in output_amount and min_output_amount." + }, + "estimatedTimeSeconds": { "type": "string", - "description": "Optional detail from the swap provider about why the fill did not complete, when available." + "description": "Provider-estimated completion time in seconds, when available." } }, - "required": ["reason", "message"] + "required": [ + "quoteId", + "provider", + "outputAmount", + "minOutputAmount", + "expiresAt", + "clientFeeBps" + ] }, - "v1SwapQuote": { + "v1SwapQuoteV2": { "type": "object", "properties": { "quoteId": { @@ -19321,6 +20436,27 @@ "estimatedTimeSeconds": { "type": "string", "description": "Provider-estimated completion time in seconds, when available." + }, + "feeSponsorship": { + "type": "boolean" + }, + "fixedRate": { + "type": "boolean" + }, + "turnkeyFeeCollection": { + "type": "string" + }, + "sponsoredFeeComponents": { + "type": "array", + "items": { + "type": "string" + } + }, + "remainingFeeComponents": { + "type": "array", + "items": { + "type": "string" + } } }, "required": [ @@ -19350,6 +20486,55 @@ }, "required": ["asset", "amount"] }, + "v1SwapSpendingWindow": { + "type": "object", + "properties": { + "windowDurationMinutes": { + "type": "integer", + "format": "int32" + }, + "windowLimitUsd": { + "type": "string", + "description": "The parent's window limit, or the per-child limit when queried by a sub-organization." + }, + "usageUsd": { + "type": "string", + "description": "Settled spending in the current window. Fixed-rate usage stays zero until final fixed-rate costs are recorded." + }, + "remainingUsd": { + "type": "string", + "description": "Remaining spending capacity, clamped to zero. For children, also capped by remaining parent capacity. Zero when the window is disabled. This is not a reservation or a guarantee of feature eligibility." + }, + "enabled": { + "type": "boolean" + }, + "subOrgWindowLimitUsd": { + "type": "string", + "description": "Configured per-child limit. Returned only when querying the billing parent." + } + }, + "required": [ + "windowDurationMinutes", + "windowLimitUsd", + "usageUsd", + "remainingUsd", + "enabled" + ] + }, + "v1SwapSponsorshipFeature": { + "type": "object", + "properties": { + "permitted": { + "type": "boolean", + "description": "Whether the billing parent holds this feature's signed permission. Quotes can use the feature only when it is permitted and its window is enabled." + }, + "window": { + "$ref": "#/definitions/v1SwapSpendingWindow", + "description": "Absent until the billing parent saves a spending window." + } + }, + "required": ["permitted"] + }, "v1TagType": { "type": "string", "enum": ["TAG_TYPE_USER", "TAG_TYPE_PRIVATE_KEY"] @@ -19672,6 +20857,16 @@ "debugMode": { "type": "boolean", "description": "Whether this deployment is running in debug mode. Debug-mode deployments expose enclave logs and cannot be remotely attested." + }, + "instanceSizeCpus": { + "type": "integer", + "format": "int64", + "description": "The instance cpu count for this enclave." + }, + "instanceSizeRam": { + "type": "integer", + "format": "int64", + "description": "The instance memory size in GiB for this enclave." } }, "required": [ @@ -19763,9 +20958,29 @@ }, "updatedAt": { "$ref": "#/definitions/externaldatav1Timestamp" + }, + "encryptPublicKey": { + "type": "string", + "description": "Encryption public key for this TVC Operator." + }, + "signPublicKey": { + "type": "string", + "description": "Signing public key for this TVC Operator." + }, + "keySource": { + "type": "string", + "description": "Source of the operator keys: EXTERNAL_KEY or ORG_WALLET_ACCOUNT. Absent for legacy operators whose source was not recorded." } }, - "required": ["id", "name", "publicKey", "createdAt", "updatedAt"] + "required": [ + "id", + "name", + "publicKey", + "createdAt", + "updatedAt", + "encryptPublicKey", + "signPublicKey" + ] }, "v1TvcOperatorApproval": { "type": "object", @@ -19892,6 +21107,41 @@ }, "required": ["name", "threshold"] }, + "v1TvcQuorumKey": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "publicKey": { + "type": "string" + }, + "threshold": { + "type": "integer", + "format": "int64" + }, + "operatorIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "createdAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + }, + "updatedAt": { + "$ref": "#/definitions/externaldatav1Timestamp" + } + }, + "required": [ + "id", + "publicKey", + "threshold", + "operatorIds", + "createdAt", + "updatedAt" + ] + }, "v1TxError": { "type": "object", "properties": { @@ -21048,6 +22298,120 @@ } } }, + "v1UpsertSwapFeeSponsorshipLimitConfigIntent": { + "type": "object", + "properties": { + "orgWindowLimitUsd": { + "type": "string", + "description": "Positive USD limit shared by the billing parent and its sub-organizations. At most 18 integer and 12 fractional digits." + }, + "subOrgWindowLimitUsd": { + "type": "string", + "description": "Positive USD limit for each sub-organization, no greater than the parent limit." + }, + "windowDurationMinutes": { + "type": "string", + "description": "Positive rolling window duration in minutes, at most 153722867." + }, + "enabled": { + "type": "boolean", + "description": "Whether this spending window permits new swaps. Setting false only turns the saved window off and keeps its limits; it doesn't require the signed permission. This does not grant or remove the signed organization permission." + } + }, + "required": [ + "orgWindowLimitUsd", + "subOrgWindowLimitUsd", + "windowDurationMinutes", + "enabled" + ] + }, + "v1UpsertSwapFeeSponsorshipLimitConfigRequest": { + "type": "object", + "properties": { + "type": { + "type": "string", + "enum": ["ACTIVITY_TYPE_UPSERT_SWAP_FEE_SPONSORSHIP_LIMIT_CONFIG"] + }, + "timestampMs": { + "type": "string", + "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "parameters": { + "$ref": "#/definitions/v1UpsertSwapFeeSponsorshipLimitConfigIntent" + } + }, + "required": ["type", "timestampMs", "organizationId", "parameters"] + }, + "v1UpsertSwapFeeSponsorshipLimitConfigResult": { + "type": "object", + "properties": { + "organizationId": { + "type": "string" + } + }, + "required": ["organizationId"] + }, + "v1UpsertSwapFixedRateLimitConfigIntent": { + "type": "object", + "properties": { + "orgWindowLimitUsd": { + "type": "string", + "description": "Positive USD limit shared by the billing parent and its sub-organizations. At most 18 integer and 12 fractional digits." + }, + "subOrgWindowLimitUsd": { + "type": "string", + "description": "Positive USD limit for each sub-organization, no greater than the parent limit." + }, + "windowDurationMinutes": { + "type": "string", + "description": "Positive rolling window duration in minutes, at most 153722867." + }, + "enabled": { + "type": "boolean", + "description": "Whether this spending window permits new swaps. Setting false only turns the saved window off and keeps its limits; it doesn't require the signed permission. This does not grant or remove the signed organization permission." + } + }, + "required": [ + "orgWindowLimitUsd", + "subOrgWindowLimitUsd", + "windowDurationMinutes", + "enabled" + ] + }, + "v1UpsertSwapFixedRateLimitConfigRequest": { + "type": "object", + "properties": { + "type": { + "type": "string", + "enum": ["ACTIVITY_TYPE_UPSERT_SWAP_FIXED_RATE_LIMIT_CONFIG"] + }, + "timestampMs": { + "type": "string", + "description": "Timestamp (in milliseconds) of the request, used to verify liveness of user requests." + }, + "organizationId": { + "type": "string", + "description": "Unique identifier for a given Organization." + }, + "parameters": { + "$ref": "#/definitions/v1UpsertSwapFixedRateLimitConfigIntent" + } + }, + "required": ["type", "timestampMs", "organizationId", "parameters"] + }, + "v1UpsertSwapFixedRateLimitConfigResult": { + "type": "object", + "properties": { + "organizationId": { + "type": "string" + } + }, + "required": ["organizationId"] + }, "v1UsageType": { "type": "string", "enum": ["USAGE_TYPE_SIGNUP", "USAGE_TYPE_LOGIN"] @@ -21349,53 +22713,6 @@ } } }, - "v1VelocityControl": { - "type": "object", - "properties": { - "velocityControlId": { - "type": "string", - "description": "Unique identifier for the Velocity Control." - }, - "organizationId": { - "type": "string", - "description": "Identifier of the Organization that owns the Velocity Control." - }, - "name": { - "type": "string", - "description": "Human-readable name for the Velocity Control." - }, - "dataSource": { - "$ref": "#/definitions/v1VelocityControlDataSource", - "description": "Data source for the Velocity Control." - }, - "aggregation": { - "$ref": "#/definitions/v1VelocityControlAggregation", - "description": "Aggregation expression that the Velocity Control evaluates." - }, - "createdAt": { - "$ref": "#/definitions/externaldatav1Timestamp", - "description": "Time when the Velocity Control was created." - }, - "updatedAt": { - "$ref": "#/definitions/externaldatav1Timestamp", - "description": "Time when the Velocity Control was last updated." - }, - "identifier": { - "type": "string", - "description": "Identifier for the Velocity Control. Policies reference it as `controls.\u003cidentifier\u003e`. It must be unique within the Organization." - } - }, - "required": [ - "velocityControlId", - "organizationId", - "name", - "dataSource", - "aggregation", - "createdAt", - "updatedAt", - "identifier" - ] - }, "v1VelocityControlAggregation": { "type": "object", "properties": { @@ -21485,8 +22802,9 @@ "type": "object", "properties": { "duration": { - "type": "string", - "description": "Duration of the rolling window, in seconds, as a base-10 integer string." + "type": "integer", + "format": "int64", + "description": "Duration of the rolling window, in seconds." } }, "required": ["duration"] @@ -21556,8 +22874,9 @@ "description": "CAIP-19 identifier for the asset." }, "decimals": { - "type": "string", - "description": "Base-10 integer string from 0 through 255 that specifies the number of decimal places for the asset." + "type": "integer", + "format": "int64", + "description": "Integer between 0 and 255 (inclusive) that specifies the number of decimal places for the asset." } }, "required": ["caip19", "decimals"] @@ -22041,6 +23360,7 @@ "name": "ORGANIZATIONS", "tags": [ "Organizations", + "Webhooks", "Invitations", "Policies", "Features", @@ -22049,7 +23369,13 @@ }, { "name": "WALLETS AND PRIVATE KEYS", - "tags": ["Wallets", "Signing", "Private Keys", "Private Key Tags"] + "tags": [ + "Wallets", + "Signing", + "Spark", + "Private Keys", + "Private Key Tags" + ] }, { "name": "USERS", @@ -22057,7 +23383,7 @@ }, { "name": "CREDENTIALS", - "tags": ["Authenticators", "API Keys", "Sessions"] + "tags": ["Authenticators", "API keys", "Sessions"] }, { "name": "ACTIVITIES", diff --git a/codegen/main.go b/codegen/main.go index c30dbbd..4149fc5 100644 --- a/codegen/main.go +++ b/codegen/main.go @@ -11,6 +11,9 @@ import ( func main() { publicSwagger := flag.String("swagger", defaultInputPath("codegen/inputs/public_api.swagger.json", "inputs/public_api.swagger.json"), "path to public API swagger") authProxySwagger := flag.String("auth-proxy-swagger", defaultInputPath("codegen/inputs/auth_proxy.swagger.json", "inputs/auth_proxy.swagger.json"), "path to auth proxy swagger") + externalSignerSwagger := flag.String("external-signer-swagger", + defaultInputPath("codegen/inputs/external_signer_api.swagger.json", "inputs/external_signer_api.swagger.json"), + "path to external signer swagger") activitiesPath := flag.String("activities", defaultInputPath("codegen/inputs/activities.json", "inputs/activities.json"), "path to activities config JSON") outDir := flag.String("out", ".", "generated Go package output directory") all := flag.Bool("all", false, "generate methods for all historical activity versions in addition to the current ones") @@ -18,11 +21,12 @@ func main() { flag.Parse() written, err := generators.Generate(generators.Options{ - PublicSwaggerPath: *publicSwagger, - AuthProxySwaggerPath: *authProxySwagger, - ActivitiesPath: *activitiesPath, - OutDir: *outDir, - AllVersions: *all, + PublicSwaggerPath: *publicSwagger, + AuthProxySwaggerPath: *authProxySwagger, + ExternalSignerSwaggerPath: *externalSignerSwagger, + ActivitiesPath: *activitiesPath, + OutDir: *outDir, + AllVersions: *all, }) if err != nil { fatal(err) diff --git a/crypto/enclave.go b/crypto/enclave.go index 27fdb77..8eda507 100644 --- a/crypto/enclave.go +++ b/crypto/enclave.go @@ -147,6 +147,40 @@ func EncryptPrivateKeyToBundle(privateKey, keyFormat, importBundle, organization return encryptImportBundle(plaintext, []byte(importBundle), organizationID, userID, signerKey) } +// EncryptSecretToBundle verifies the target's signature and org, then returns encrypted ClientSendMsg JSON and its hex target key. +// dangerouslyOverrideSignerKey replaces the production quorum key (non-production only). +func EncryptSecretToBundle(plaintext []byte, targetBundle, organizationID string, dangerouslyOverrideSignerKey ...*ecdsa.PublicKey) (string, string, error) { + signerKey, err := resolveSignerKey(dangerouslyOverrideSignerKey...) + if err != nil { + return "", "", err + } + + var msg ServerTargetMsgV1 + if err := json.Unmarshal([]byte(targetBundle), &msg); err != nil { + return "", "", err + } + + if err := verifyEnclaveSignature(msg.EnclaveQuorumPublic, msg.DataSignature, msg.Data, signerKey); err != nil { + return "", "", err + } + + var signedData ServerTargetData + if err := json.Unmarshal(msg.Data, &signedData); err != nil { + return "", "", err + } + + if signedData.OrganizationID != organizationID { + return "", "", fmt.Errorf("organization id does not match expected value. Expected: %s. Found: %s", organizationID, signedData.OrganizationID) + } + + payload, err := hpkeEncryptToTarget(signedData.TargetPublic, plaintext) + if err != nil { + return "", "", err + } + + return payload, hex.EncodeToString(signedData.TargetPublic), nil +} + // EncryptOtpCodeToBundle encrypts an OTP code and a client public key to the target bundle // returned by InitOtp. Verifies the enclave signature using ProductionTLSFetcherSigningPublicKey. // Pass dangerouslyOverrideSignerPublicKeyHex to use a custom signer key (non-production only). diff --git a/crypto/secret_test.go b/crypto/secret_test.go new file mode 100644 index 0000000..657c95b --- /dev/null +++ b/crypto/secret_test.go @@ -0,0 +1,73 @@ +package crypto + +import ( + "crypto/ecdsa" + "crypto/elliptic" + "crypto/rand" + "encoding/hex" + "encoding/json" + "testing" + + "github.com/stretchr/testify/require" +) + +func TestEncryptSecretToBundle(t *testing.T) { + const organizationID = "8a1e6f5c-0000-4000-8000-000000000001" + + quorumKey, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader) + require.NoError(t, err) + + targetPublicHex, _, err := GenerateEncryptionKeyPair() + require.NoError(t, err) + + targetPublic, err := hex.DecodeString(targetPublicHex) + require.NoError(t, err) + + data, err := json.Marshal(ServerTargetData{ + TargetPublic: targetPublic, + OrganizationID: organizationID, + }) + require.NoError(t, err) + + signature, err := P256Sign(quorumKey, data) + require.NoError(t, err) + + quorumPublicKey, err := quorumKey.PublicKey.ECDH() + require.NoError(t, err) + + bundleBytes, err := json.Marshal(ServerTargetMsgV1{ + Version: "v1.0.0", + Data: data, + DataSignature: signature, + EnclaveQuorumPublic: quorumPublicKey.Bytes(), + }) + require.NoError(t, err) + + bundle := string(bundleBytes) + plaintext := []byte("super secret") + + t.Run("organizationMismatch", func(t *testing.T) { + _, _, err := EncryptSecretToBundle(plaintext, bundle, "0e51e13c-0000-4000-8000-000000000002", &quorumKey.PublicKey) + require.ErrorContains(t, err, "organization id does not match") + }) + + t.Run("wrongQuorumKey", func(t *testing.T) { + otherKey, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader) + require.NoError(t, err) + + _, _, err = EncryptSecretToBundle(plaintext, bundle, organizationID, &otherKey.PublicKey) + require.ErrorContains(t, err, "enclave quorum public keys from client and message do not match") + }) + + t.Run("tamperedSignature", func(t *testing.T) { + var msg ServerTargetMsgV1 + require.NoError(t, json.Unmarshal([]byte(bundle), &msg)) + msg.Data[len(msg.Data)-1] ^= 0xff + + tampered, err := json.Marshal(msg) + require.NoError(t, err) + + _, _, err = EncryptSecretToBundle(plaintext, string(tampered), organizationID, &quorumKey.PublicKey) + require.ErrorContains(t, err, "invalid enclave auth key signature") + }) +} diff --git a/go.work.sum b/go.work.sum index f4f8c32..82be0bd 100644 --- a/go.work.sum +++ b/go.work.sum @@ -90,7 +90,6 @@ github.com/coreos/go-systemd/v22 v22.3.2 h1:D9/bQk5vlXQFZ6Kwuu6zaiXJ9oTPe68++AzA github.com/coreos/go-systemd/v22 v22.3.2/go.mod h1:Y58oyj3AT4RCenI/lSvhwexgC+NSVTIJ3seZv2GcEnc= github.com/cpuguy83/go-md2man/v2 v2.0.6 h1:XJtiaUW6dEEqVuZiMTn1ldk455QWwEIsMIJlo5vtkx0= github.com/creack/pty v1.1.9 h1:uDmaGzcdjhF4i/plgjmEsriH11Y0o7RKapEf/LDaM3w= -github.com/creack/pty v1.1.9/go.mod h1:oKZEueFk5CKHvIhNR5MUki03XCEU+Q6VDXinZuGJ33E= github.com/cristalhq/acmd v0.12.0 h1:RdlKnxjN+txbQosg8p/TRNZ+J1Rdne43MVQZ1zDhGWk= github.com/cristalhq/acmd v0.12.0/go.mod h1:LG5oa43pE/BbxtfMoImHCQN++0Su7dzipdgBjMCBVDQ= github.com/daaku/go.zipexe v1.0.0 h1:VSOgZtH418pH9L16hC/JrgSNJbbAL26pj7lmD1+CGdY= @@ -232,6 +231,7 @@ github.com/google/renameio v0.1.0 h1:GOZbcHa3HfsPKPlmyPyN2KEohoMXOhdMbHrvbpl2QaA github.com/google/s2a-go v0.1.9 h1:LGD7gtMgezd8a/Xak7mEWL0PjoTQFvpRudN895yqKW0= github.com/google/s2a-go v0.1.9/go.mod h1:YA0Ei2ZQL3acow2O62kdp9UlnvMmU7kA6Eutn0dXayM= github.com/google/uuid v1.1.1/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= +github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= github.com/googleapis/enterprise-certificate-proxy v0.3.6 h1:GW/XbdyBFQ8Qe+YAmFU9uHLo7OnF5tL52HFAgMmyrf4= github.com/googleapis/enterprise-certificate-proxy v0.3.6/go.mod h1:MkHOF77EYAE7qfSuSS9PU6g4Nt4e11cnsDUowfwewLA= github.com/googleapis/gax-go/v2 v2.0.5 h1:sjZBwGj9Jlw33ImPtvFviGYvseOtDM7hkSKB7+Tv3SM= @@ -297,7 +297,6 @@ github.com/konsorten/go-windows-terminal-sequences v1.0.2 h1:DB17ag19krx9CFsz4o3 github.com/konsorten/go-windows-terminal-sequences v1.0.2/go.mod h1:T0+1ngSBFLxvqU3pZ+m/2kptfBszLMUkC4ZK/EgS/cQ= github.com/konsorten/go-windows-terminal-sequences v1.0.3 h1:CE8S1cTafDpPvMhIxNJKvHsGVBgn1xWYf1NbHQhywc8= github.com/kr/logfmt v0.0.0-20140226030751-b84e30acd515 h1:T+h1c/A9Gawja4Y9mFVWj2vyii2bbUNDw3kt9VxK2EY= -github.com/kr/pretty v0.2.1/go.mod h1:ipq/a2n7PKx3OHsz4KJII5eveXtPO4qwEXGdVfWzfnI= github.com/kr/pty v1.1.1 h1:VkoXIwSboBpnk99O/KFauAEILuNHv5DVFKZMBN/gUgw= github.com/lib/pq v1.12.3 h1:tTWxr2YLKwIvK90ZXEw8GP7UFHtcbTtty8zsI+YjrfQ= github.com/lib/pq v1.12.3/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA= @@ -364,7 +363,6 @@ github.com/pelletier/go-toml v1.7.0/go.mod h1:vwGMzjaWMwyfHwgIBhI2YUM4fB6nL6lVAv github.com/phayes/checkstyle v0.0.0-20170904204023-bfd46e6a821d h1:CdDQnGF8Nq9ocOS/xlSptM1N3BbrA6/kmaep5ggwaIA= github.com/phayes/checkstyle v0.0.0-20170904204023-bfd46e6a821d/go.mod h1:3OzsM7FXDQlpCiw2j81fOmAwQLnZnLGXVKUzeKQXIAw= github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e h1:aoZm08cpOy4WuID//EZDgcC4zIxODThtZNPirFr42+A= -github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e/go.mod h1:pJLUxLENpZxwdsKMEsNbx1VGcRFpLqf3715MtcvvzbA= github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4= github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55 h1:o4JXh1EVt9k/+g42oCprj/FisM4qX9L3sZB3upGN2ZU= github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55/go.mod h1:OmDBASR4679mdNQnz2pUhc2G8CO2JrUAVFDRBDP/hJE= @@ -372,7 +370,6 @@ github.com/quasilyte/go-ruleguard/rules v0.0.0-20211022131956-028d6511ab71 h1:CN github.com/quasilyte/go-ruleguard/rules v0.0.0-20211022131956-028d6511ab71/go.mod h1:4cgAphtvu7Ftv7vOT2ZOYhC6CvBxZixcasr8qIOTA50= github.com/rogpeppe/go-internal v1.1.0/go.mod h1:M8bDsm7K2OlrFYOpmOWEs/qY81heoFRclV5y23lUDJ4= github.com/rogpeppe/go-internal v1.2.2/go.mod h1:M8bDsm7K2OlrFYOpmOWEs/qY81heoFRclV5y23lUDJ4= -github.com/rogpeppe/go-internal v1.9.0/go.mod h1:WtVeX8xhTBvf0smdhujwtBcq4Qrzq/fJaraNFVN+nFs= github.com/russross/blackfriday/v2 v2.1.0 h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf35Ld67mk= github.com/ryanuber/columnize v0.0.0-20160712163229-9b3edd62028f h1:UFr9zpz4xgTnIE5yIMtWAMngCdZ9p/+q6lTbgelo80M= github.com/ryanuber/columnize v0.0.0-20160712163229-9b3edd62028f/go.mod h1:sm1tb6uqfes/u+d4ooFouqFdy9/2g9QGwK3SQygK0Ts= @@ -587,4 +584,4 @@ gopkg.in/yaml.v3 v3.0.0-20200615113413-eeeca48fe776/go.mod h1:K4uyk7z7BCEPqu6E+C gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= rsc.io/binaryregexp v0.2.0 h1:HfqmD5MEmC0zvwBuF187nq9mdnXjXsSivRiXN7SmRkE= rsc.io/quote/v3 v3.1.0 h1:9JKUTTIUgS6kzR9mK1YuGKv6Nl+DijDNIc0ghT58FaY= -rsc.io/sampler v1.3.0 h1:7uVkIFmeBqHfdjD+gZwtXXI+RODJ2Wc4O7MPEh/QiW4= \ No newline at end of file +rsc.io/sampler v1.3.0 h1:7uVkIFmeBqHfdjD+gZwtXXI+RODJ2Wc4O7MPEh/QiW4= diff --git a/secrets_test.go b/secrets_test.go new file mode 100644 index 0000000..b383cf6 --- /dev/null +++ b/secrets_test.go @@ -0,0 +1,196 @@ +package turnkey + +import ( + "context" + "crypto/ecdsa" + "crypto/elliptic" + "crypto/rand" + "encoding/hex" + "encoding/json" + "net/http" + "net/http/httptest" + "testing" + + "github.com/cloudflare/circl/kem" + "github.com/stretchr/testify/assert" + "github.com/stretchr/testify/require" + + "github.com/tkhq/go-sdk/crypto" +) + +// secretsMockEnclave creates signed import and export bundles with a test quorum key. +type secretsMockEnclave struct { + t *testing.T + quorumKey *ecdsa.PrivateKey +} + +func newSecretsMockEnclave(t *testing.T) *secretsMockEnclave { + t.Helper() + + quorumKey, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader) + require.NoError(t, err) + + return &secretsMockEnclave{t: t, quorumKey: quorumKey} +} + +func (e *secretsMockEnclave) signedBundle(payload any) string { + data, err := json.Marshal(payload) + require.NoError(e.t, err) + + signature, err := crypto.P256Sign(e.quorumKey, data) + require.NoError(e.t, err) + + quorumPublicKey, err := e.quorumKey.PublicKey.ECDH() + require.NoError(e.t, err) + + bundle, err := json.Marshal(crypto.ServerTargetMsgV1{ + Version: "v1.0.0", + Data: data, + DataSignature: signature, + EnclaveQuorumPublic: quorumPublicKey.Bytes(), + }) + require.NoError(e.t, err) + + return string(bundle) +} + +// targetBundle returns a signed ingress bundle and its private key. +func (e *secretsMockEnclave) targetBundle(organizationID string) (string, kem.PrivateKey) { + targetPublicHex, kemPrivate, err := crypto.GenerateEncryptionKeyPair() + require.NoError(e.t, err) + + targetPublic, err := hex.DecodeString(targetPublicHex) + require.NoError(e.t, err) + + return e.signedBundle(crypto.ServerTargetData{ + TargetPublic: targetPublic, + OrganizationID: organizationID, + }), kemPrivate +} + +// exportBundle encrypts to the client's target key and signs the result. +func (e *secretsMockEnclave) exportBundle(plaintext []byte, targetPublicKeyHex, organizationID string) string { + targetPublic, err := hex.DecodeString(targetPublicKeyHex) + require.NoError(e.t, err) + + kemPublic, err := crypto.KemID.Scheme().UnmarshalBinaryPublicKey(targetPublic) + require.NoError(e.t, err) + + ciphertext, encappedPublic, err := crypto.HPKEEncrypt(&kemPublic, plaintext) + require.NoError(e.t, err) + + return e.signedBundle(crypto.ServerSendData{ + EncappedPublic: encappedPublic, + Ciphertext: ciphertext, + OrganizationID: organizationID, + }) +} + +func completedActivity(resultField string, result any) map[string]any { + return map[string]any{ + "activity": map[string]any{ + "id": "11111111-1111-4111-8111-111111111111", + "status": string(ActivityStatusCompleted), + "result": map[string]any{resultField: result}, + }, + } +} + +func newSecretsTestClient(t *testing.T, baseURL, organizationID string) *Client { + t.Helper() + + stamper, err := NewAPIKeyStamper(testPrivateKey(t)) + require.NoError(t, err) + + client, err := NewClient(stamper, organizationID, WithBaseURL(baseURL)) + require.NoError(t, err) + + return client +} + +func TestSecretWrappersImportSecret(t *testing.T) { + const organizationID = "8a1e6f5c-0000-4000-8000-000000000001" + + enclave := newSecretsMockEnclave(t) + bundle, targetKey := enclave.targetBundle(organizationID) + + var importedParams []ImportSecretParams + + server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + switch r.URL.Path { + case "/public/v1/submit/init_import_secrets": + require.NoError(t, json.NewEncoder(w).Encode(completedActivity("initImportSecretsResult", InitImportSecretsResult{ + EnclaveTargetMessages: []string{bundle}, + }))) + case "/public/v1/submit/import_secrets": + var body struct { + Parameters ImportSecretsIntent `json:"parameters"` + } + require.NoError(t, json.NewDecoder(r.Body).Decode(&body)) + importedParams = body.Parameters.Secrets + + require.NoError(t, json.NewEncoder(w).Encode(completedActivity("importSecretsResult", ImportSecretsResult{ + SecretIds: []string{"22222222-2222-4222-8222-222222222222"}, + }))) + default: + t.Fatalf("unexpected request path %s", r.URL.Path) + } + })) + defer server.Close() + + client := newSecretsTestClient(t, server.URL, organizationID) + + name := "wrapped-secret" + plaintext := []byte("wrapper plaintext") + + secretID, err := client.ImportSecret(context.Background(), organizationID, &name, plaintext, + map[string]string{"kind": "test", "environment": "sandbox"}, &enclave.quorumKey.PublicKey) + require.NoError(t, err) + assert.Equal(t, "22222222-2222-4222-8222-222222222222", secretID) + + // Decrypt the submitted payload to verify the imported plaintext. + require.Len(t, importedParams, 1) + require.Len(t, importedParams[0].StaticProperties, 2) + assert.Equal(t, []string{"environment", "kind"}, []string{*importedParams[0].StaticProperties[0].Key, *importedParams[0].StaticProperties[1].Key}) + assert.Equal(t, []string{"sandbox", "test"}, []string{*importedParams[0].StaticProperties[0].Value, *importedParams[0].StaticProperties[1].Value}) + + var msg crypto.ClientSendMsg + require.NoError(t, json.Unmarshal([]byte(importedParams[0].SecretPayload), &msg)) + + decrypted, err := crypto.HPKEDecrypt(*msg.EncappedPublic, targetKey, *msg.Ciphertext) + require.NoError(t, err) + assert.Equal(t, plaintext, decrypted) +} + +func TestSecretWrappersExportSecret(t *testing.T) { + const organizationID = "8a1e6f5c-0000-4000-8000-000000000001" + + const secretID = "33333333-3333-4333-8333-333333333333" + + enclave := newSecretsMockEnclave(t) + plaintext := []byte("export plaintext") + + server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + require.Equal(t, "/public/v1/submit/export_secrets", r.URL.Path) + + var body struct { + Parameters ExportSecretsIntent `json:"parameters"` + } + require.NoError(t, json.NewDecoder(r.Body).Decode(&body)) + require.Len(t, body.Parameters.Secrets, 1) + + param := body.Parameters.Secrets[0] + require.Equal(t, secretID, param.SecretID) + + require.NoError(t, json.NewEncoder(w).Encode(completedActivity("exportSecretsResult", ExportSecretsResult{ + SecretPayloads: []string{enclave.exportBundle(plaintext, param.TargetPublicKey, organizationID)}, + }))) + })) + defer server.Close() + + client := newSecretsTestClient(t, server.URL, organizationID) + + exported, err := client.ExportSecret(context.Background(), organizationID, secretID, &enclave.quorumKey.PublicKey) + require.NoError(t, err) + assert.Equal(t, plaintext, exported) +} diff --git a/types_gen.go b/types_gen.go index 90c0387..c62ea2d 100644 --- a/types_gen.go +++ b/types_gen.go @@ -4,6 +4,14 @@ package turnkey import "encoding/json" +type ExternalCryptoV1SignatureScheme string + +const ( + ExternalCryptoV1SignatureSchemeSignatureSchemeTkApip256 ExternalCryptoV1SignatureScheme = "SIGNATURE_SCHEME_TK_API_P256" + ExternalCryptoV1SignatureSchemeSignatureSchemeTkWebauthn ExternalCryptoV1SignatureScheme = "SIGNATURE_SCHEME_TK_WEBAUTHN" + ExternalCryptoV1SignatureSchemeSignatureSchemeTkQuorumP256 ExternalCryptoV1SignatureScheme = "SIGNATURE_SCHEME_TK_QUORUM_P256" +) + type ExternalDataV1SignatureScheme string const ( @@ -33,170 +41,178 @@ const ( type ActivityType string const ( - ActivityTypeCreateAPIKeys ActivityType = "ACTIVITY_TYPE_CREATE_API_KEYS" - ActivityTypeCreateUsers ActivityType = "ACTIVITY_TYPE_CREATE_USERS" - ActivityTypeCreatePrivateKeys ActivityType = "ACTIVITY_TYPE_CREATE_PRIVATE_KEYS" - ActivityTypeSignRawPayload ActivityType = "ACTIVITY_TYPE_SIGN_RAW_PAYLOAD" - ActivityTypeCreateInvitations ActivityType = "ACTIVITY_TYPE_CREATE_INVITATIONS" - ActivityTypeAcceptInvitation ActivityType = "ACTIVITY_TYPE_ACCEPT_INVITATION" - ActivityTypeCreatePolicy ActivityType = "ACTIVITY_TYPE_CREATE_POLICY" - ActivityTypeDisablePrivateKey ActivityType = "ACTIVITY_TYPE_DISABLE_PRIVATE_KEY" - ActivityTypeDeleteUsers ActivityType = "ACTIVITY_TYPE_DELETE_USERS" - ActivityTypeDeleteAPIKeys ActivityType = "ACTIVITY_TYPE_DELETE_API_KEYS" - ActivityTypeDeleteInvitation ActivityType = "ACTIVITY_TYPE_DELETE_INVITATION" - ActivityTypeDeleteOrganization ActivityType = "ACTIVITY_TYPE_DELETE_ORGANIZATION" - ActivityTypeDeletePolicy ActivityType = "ACTIVITY_TYPE_DELETE_POLICY" - ActivityTypeCreateUserTag ActivityType = "ACTIVITY_TYPE_CREATE_USER_TAG" - ActivityTypeDeleteUserTags ActivityType = "ACTIVITY_TYPE_DELETE_USER_TAGS" - ActivityTypeCreateOrganization ActivityType = "ACTIVITY_TYPE_CREATE_ORGANIZATION" - ActivityTypeSignTransaction ActivityType = "ACTIVITY_TYPE_SIGN_TRANSACTION" - ActivityTypeApproveActivity ActivityType = "ACTIVITY_TYPE_APPROVE_ACTIVITY" - ActivityTypeRejectActivity ActivityType = "ACTIVITY_TYPE_REJECT_ACTIVITY" - ActivityTypeDeleteAuthenticators ActivityType = "ACTIVITY_TYPE_DELETE_AUTHENTICATORS" - ActivityTypeCreateAuthenticators ActivityType = "ACTIVITY_TYPE_CREATE_AUTHENTICATORS" - ActivityTypeCreatePrivateKeyTag ActivityType = "ACTIVITY_TYPE_CREATE_PRIVATE_KEY_TAG" - ActivityTypeDeletePrivateKeyTags ActivityType = "ACTIVITY_TYPE_DELETE_PRIVATE_KEY_TAGS" - ActivityTypeSetPaymentMethod ActivityType = "ACTIVITY_TYPE_SET_PAYMENT_METHOD" - ActivityTypeActivateBillingTier ActivityType = "ACTIVITY_TYPE_ACTIVATE_BILLING_TIER" - ActivityTypeDeletePaymentMethod ActivityType = "ACTIVITY_TYPE_DELETE_PAYMENT_METHOD" - ActivityTypeCreatePolicyV2 ActivityType = "ACTIVITY_TYPE_CREATE_POLICY_V2" - ActivityTypeCreatePolicyV3 ActivityType = "ACTIVITY_TYPE_CREATE_POLICY_V3" - ActivityTypeCreateAPIOnlyUsers ActivityType = "ACTIVITY_TYPE_CREATE_API_ONLY_USERS" - ActivityTypeUpdateRootQuorum ActivityType = "ACTIVITY_TYPE_UPDATE_ROOT_QUORUM" - ActivityTypeUpdateUserTag ActivityType = "ACTIVITY_TYPE_UPDATE_USER_TAG" - ActivityTypeUpdatePrivateKeyTag ActivityType = "ACTIVITY_TYPE_UPDATE_PRIVATE_KEY_TAG" - ActivityTypeCreateAuthenticatorsV2 ActivityType = "ACTIVITY_TYPE_CREATE_AUTHENTICATORS_V2" - ActivityTypeCreateOrganizationV2 ActivityType = "ACTIVITY_TYPE_CREATE_ORGANIZATION_V2" - ActivityTypeCreateUsersV2 ActivityType = "ACTIVITY_TYPE_CREATE_USERS_V2" - ActivityTypeAcceptInvitationV2 ActivityType = "ACTIVITY_TYPE_ACCEPT_INVITATION_V2" - ActivityTypeCreateSubOrganization ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION" - ActivityTypeCreateSubOrganizationV2 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V2" - ActivityTypeUpdateAllowedOrigins ActivityType = "ACTIVITY_TYPE_UPDATE_ALLOWED_ORIGINS" - ActivityTypeCreatePrivateKeysV2 ActivityType = "ACTIVITY_TYPE_CREATE_PRIVATE_KEYS_V2" - ActivityTypeUpdateUser ActivityType = "ACTIVITY_TYPE_UPDATE_USER" - ActivityTypeUpdatePolicy ActivityType = "ACTIVITY_TYPE_UPDATE_POLICY" - ActivityTypeSetPaymentMethodV2 ActivityType = "ACTIVITY_TYPE_SET_PAYMENT_METHOD_V2" - ActivityTypeCreateSubOrganizationV3 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V3" - ActivityTypeCreateWallet ActivityType = "ACTIVITY_TYPE_CREATE_WALLET" - ActivityTypeCreateWalletAccounts ActivityType = "ACTIVITY_TYPE_CREATE_WALLET_ACCOUNTS" - ActivityTypeInitUserEmailRecovery ActivityType = "ACTIVITY_TYPE_INIT_USER_EMAIL_RECOVERY" - ActivityTypeRecoverUser ActivityType = "ACTIVITY_TYPE_RECOVER_USER" - ActivityTypeSetOrganizationFeature ActivityType = "ACTIVITY_TYPE_SET_ORGANIZATION_FEATURE" - ActivityTypeRemoveOrganizationFeature ActivityType = "ACTIVITY_TYPE_REMOVE_ORGANIZATION_FEATURE" - ActivityTypeSignRawPayloadV2 ActivityType = "ACTIVITY_TYPE_SIGN_RAW_PAYLOAD_V2" - ActivityTypeSignTransactionV2 ActivityType = "ACTIVITY_TYPE_SIGN_TRANSACTION_V2" - ActivityTypeExportPrivateKey ActivityType = "ACTIVITY_TYPE_EXPORT_PRIVATE_KEY" - ActivityTypeExportWallet ActivityType = "ACTIVITY_TYPE_EXPORT_WALLET" - ActivityTypeCreateSubOrganizationV4 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V4" - ActivityTypeEmailAuth ActivityType = "ACTIVITY_TYPE_EMAIL_AUTH" - ActivityTypeExportWalletAccount ActivityType = "ACTIVITY_TYPE_EXPORT_WALLET_ACCOUNT" - ActivityTypeInitImportWallet ActivityType = "ACTIVITY_TYPE_INIT_IMPORT_WALLET" - ActivityTypeImportWallet ActivityType = "ACTIVITY_TYPE_IMPORT_WALLET" - ActivityTypeInitImportPrivateKey ActivityType = "ACTIVITY_TYPE_INIT_IMPORT_PRIVATE_KEY" - ActivityTypeImportPrivateKey ActivityType = "ACTIVITY_TYPE_IMPORT_PRIVATE_KEY" - ActivityTypeCreatePolicies ActivityType = "ACTIVITY_TYPE_CREATE_POLICIES" - ActivityTypeSignRawPayloads ActivityType = "ACTIVITY_TYPE_SIGN_RAW_PAYLOADS" - ActivityTypeCreateReadOnlySession ActivityType = "ACTIVITY_TYPE_CREATE_READ_ONLY_SESSION" - ActivityTypeCreateOAuthProviders ActivityType = "ACTIVITY_TYPE_CREATE_OAUTH_PROVIDERS" - ActivityTypeDeleteOAuthProviders ActivityType = "ACTIVITY_TYPE_DELETE_OAUTH_PROVIDERS" - ActivityTypeCreateSubOrganizationV5 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V5" - ActivityTypeOAuth ActivityType = "ACTIVITY_TYPE_OAUTH" - ActivityTypeCreateAPIKeysV2 ActivityType = "ACTIVITY_TYPE_CREATE_API_KEYS_V2" - ActivityTypeCreateReadWriteSession ActivityType = "ACTIVITY_TYPE_CREATE_READ_WRITE_SESSION" - ActivityTypeEmailAuthV2 ActivityType = "ACTIVITY_TYPE_EMAIL_AUTH_V2" - ActivityTypeCreateSubOrganizationV6 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V6" - ActivityTypeDeletePrivateKeys ActivityType = "ACTIVITY_TYPE_DELETE_PRIVATE_KEYS" - ActivityTypeDeleteWallets ActivityType = "ACTIVITY_TYPE_DELETE_WALLETS" - ActivityTypeCreateReadWriteSessionV2 ActivityType = "ACTIVITY_TYPE_CREATE_READ_WRITE_SESSION_V2" - ActivityTypeDeleteSubOrganization ActivityType = "ACTIVITY_TYPE_DELETE_SUB_ORGANIZATION" - ActivityTypeInitOTPAuth ActivityType = "ACTIVITY_TYPE_INIT_OTP_AUTH" - ActivityTypeOTPAuth ActivityType = "ACTIVITY_TYPE_OTP_AUTH" - ActivityTypeCreateSubOrganizationV7 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V7" - ActivityTypeUpdateWallet ActivityType = "ACTIVITY_TYPE_UPDATE_WALLET" - ActivityTypeUpdatePolicyV2 ActivityType = "ACTIVITY_TYPE_UPDATE_POLICY_V2" - ActivityTypeCreateUsersV3 ActivityType = "ACTIVITY_TYPE_CREATE_USERS_V3" - ActivityTypeInitOTPAuthV2 ActivityType = "ACTIVITY_TYPE_INIT_OTP_AUTH_V2" - ActivityTypeInitOTP ActivityType = "ACTIVITY_TYPE_INIT_OTP" - ActivityTypeVerifyOTP ActivityType = "ACTIVITY_TYPE_VERIFY_OTP" - ActivityTypeOTPLogin ActivityType = "ACTIVITY_TYPE_OTP_LOGIN" - ActivityTypeStampLogin ActivityType = "ACTIVITY_TYPE_STAMP_LOGIN" - ActivityTypeOAuthLogin ActivityType = "ACTIVITY_TYPE_OAUTH_LOGIN" - ActivityTypeUpdateUserName ActivityType = "ACTIVITY_TYPE_UPDATE_USER_NAME" - ActivityTypeUpdateUserEmail ActivityType = "ACTIVITY_TYPE_UPDATE_USER_EMAIL" - ActivityTypeUpdateUserPhoneNumber ActivityType = "ACTIVITY_TYPE_UPDATE_USER_PHONE_NUMBER" - ActivityTypeInitFiatOnRamp ActivityType = "ACTIVITY_TYPE_INIT_FIAT_ON_RAMP" - ActivityTypeCreateSmartContractInterface ActivityType = "ACTIVITY_TYPE_CREATE_SMART_CONTRACT_INTERFACE" - ActivityTypeDeleteSmartContractInterface ActivityType = "ACTIVITY_TYPE_DELETE_SMART_CONTRACT_INTERFACE" - ActivityTypeEnableAuthProxy ActivityType = "ACTIVITY_TYPE_ENABLE_AUTH_PROXY" - ActivityTypeDisableAuthProxy ActivityType = "ACTIVITY_TYPE_DISABLE_AUTH_PROXY" - ActivityTypeUpdateAuthProxyConfig ActivityType = "ACTIVITY_TYPE_UPDATE_AUTH_PROXY_CONFIG" - ActivityTypeCreateOAuth2Credential ActivityType = "ACTIVITY_TYPE_CREATE_OAUTH2_CREDENTIAL" - ActivityTypeUpdateOAuth2Credential ActivityType = "ACTIVITY_TYPE_UPDATE_OAUTH2_CREDENTIAL" - ActivityTypeDeleteOAuth2Credential ActivityType = "ACTIVITY_TYPE_DELETE_OAUTH2_CREDENTIAL" - ActivityTypeOAuth2Authenticate ActivityType = "ACTIVITY_TYPE_OAUTH2_AUTHENTICATE" - ActivityTypeDeleteWalletAccounts ActivityType = "ACTIVITY_TYPE_DELETE_WALLET_ACCOUNTS" - ActivityTypeDeletePolicies ActivityType = "ACTIVITY_TYPE_DELETE_POLICIES" - ActivityTypeETHSendRawTransaction ActivityType = "ACTIVITY_TYPE_ETH_SEND_RAW_TRANSACTION" - ActivityTypeETHSendTransaction ActivityType = "ACTIVITY_TYPE_ETH_SEND_TRANSACTION" - ActivityTypeCreateFiatOnRampCredential ActivityType = "ACTIVITY_TYPE_CREATE_FIAT_ON_RAMP_CREDENTIAL" - ActivityTypeUpdateFiatOnRampCredential ActivityType = "ACTIVITY_TYPE_UPDATE_FIAT_ON_RAMP_CREDENTIAL" - ActivityTypeDeleteFiatOnRampCredential ActivityType = "ACTIVITY_TYPE_DELETE_FIAT_ON_RAMP_CREDENTIAL" - ActivityTypeEmailAuthV3 ActivityType = "ACTIVITY_TYPE_EMAIL_AUTH_V3" - ActivityTypeInitUserEmailRecoveryV2 ActivityType = "ACTIVITY_TYPE_INIT_USER_EMAIL_RECOVERY_V2" - ActivityTypeInitOTPAuthV3 ActivityType = "ACTIVITY_TYPE_INIT_OTP_AUTH_V3" - ActivityTypeInitOtpv2 ActivityType = "ACTIVITY_TYPE_INIT_OTP_V2" - ActivityTypeUpsertGasUsageConfig ActivityType = "ACTIVITY_TYPE_UPSERT_GAS_USAGE_CONFIG" - ActivityTypeCreateTVCApp ActivityType = "ACTIVITY_TYPE_CREATE_TVC_APP" - ActivityTypeCreateTVCDeployment ActivityType = "ACTIVITY_TYPE_CREATE_TVC_DEPLOYMENT" - ActivityTypeCreateTVCManifestApprovals ActivityType = "ACTIVITY_TYPE_CREATE_TVC_MANIFEST_APPROVALS" - ActivityTypeSolSendTransaction ActivityType = "ACTIVITY_TYPE_SOL_SEND_TRANSACTION" - ActivityTypeInitOtpv3 ActivityType = "ACTIVITY_TYPE_INIT_OTP_V3" - ActivityTypeVerifyOtpv2 ActivityType = "ACTIVITY_TYPE_VERIFY_OTP_V2" - ActivityTypeOTPLoginV2 ActivityType = "ACTIVITY_TYPE_OTP_LOGIN_V2" - ActivityTypeUpdateOrganizationName ActivityType = "ACTIVITY_TYPE_UPDATE_ORGANIZATION_NAME" - ActivityTypeCreateSubOrganizationV8 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V8" - ActivityTypeCreateOAuthProvidersV2 ActivityType = "ACTIVITY_TYPE_CREATE_OAUTH_PROVIDERS_V2" - ActivityTypeCreateUsersV4 ActivityType = "ACTIVITY_TYPE_CREATE_USERS_V4" - ActivityTypeCreateWebhookEndpoint ActivityType = "ACTIVITY_TYPE_CREATE_WEBHOOK_ENDPOINT" - ActivityTypeUpdateWebhookEndpoint ActivityType = "ACTIVITY_TYPE_UPDATE_WEBHOOK_ENDPOINT" - ActivityTypeDeleteWebhookEndpoint ActivityType = "ACTIVITY_TYPE_DELETE_WEBHOOK_ENDPOINT" - ActivityTypeSetIPAllowlist ActivityType = "ACTIVITY_TYPE_SET_IP_ALLOWLIST" - ActivityTypeRemoveIPAllowlist ActivityType = "ACTIVITY_TYPE_REMOVE_IP_ALLOWLIST" - ActivityTypeUpdateTVCAppLiveDeployment ActivityType = "ACTIVITY_TYPE_UPDATE_TVC_APP_LIVE_DEPLOYMENT" - ActivityTypeDeleteTVCDeployment ActivityType = "ACTIVITY_TYPE_DELETE_TVC_DEPLOYMENT" - ActivityTypeDeleteTVCAppAndDeployments ActivityType = "ACTIVITY_TYPE_DELETE_TVC_APP_AND_DEPLOYMENTS" - ActivityTypeRestoreTVCDeployment ActivityType = "ACTIVITY_TYPE_RESTORE_TVC_DEPLOYMENT" - ActivityTypeSparkSignFrost ActivityType = "ACTIVITY_TYPE_SPARK_SIGN_FROST" - ActivityTypeSparkPrepareTransfer ActivityType = "ACTIVITY_TYPE_SPARK_PREPARE_TRANSFER" - ActivityTypeSparkClaimTransfer ActivityType = "ACTIVITY_TYPE_SPARK_CLAIM_TRANSFER" - ActivityTypeSparkPrepareLightningReceive ActivityType = "ACTIVITY_TYPE_SPARK_PREPARE_LIGHTNING_RECEIVE" - ActivityTypePostTVCQuorumKeyShare ActivityType = "ACTIVITY_TYPE_POST_TVC_QUORUM_KEY_SHARE" - ActivityTypeETHSendTransactionV2 ActivityType = "ACTIVITY_TYPE_ETH_SEND_TRANSACTION_V2" - ActivityTypeCreateMfaPolicy ActivityType = "ACTIVITY_TYPE_CREATE_MFA_POLICY" - ActivityTypeUpdateMfaPolicy ActivityType = "ACTIVITY_TYPE_UPDATE_MFA_POLICY" - ActivityTypeDeleteMfaPolicy ActivityType = "ACTIVITY_TYPE_DELETE_MFA_POLICY" - ActivityTypeCreateSessionProfile ActivityType = "ACTIVITY_TYPE_CREATE_SESSION_PROFILE" - ActivityTypeEarnDeployWrapper ActivityType = "ACTIVITY_TYPE_EARN_DEPLOY_WRAPPER" - ActivityTypeEarnDeposit ActivityType = "ACTIVITY_TYPE_EARN_DEPOSIT" - ActivityTypeEarnWithdraw ActivityType = "ACTIVITY_TYPE_EARN_WITHDRAW" - ActivityTypeExecuteSwap ActivityType = "ACTIVITY_TYPE_EXECUTE_SWAP" - ActivityTypeUpsertSwapConfig ActivityType = "ACTIVITY_TYPE_UPSERT_SWAP_CONFIG" - ActivityTypeCreateTVCOperator ActivityType = "ACTIVITY_TYPE_CREATE_TVC_OPERATOR" - ActivityTypeCreateTVCQuorumKey ActivityType = "ACTIVITY_TYPE_CREATE_TVC_QUORUM_KEY" - ActivityTypeReEncryptTVCQuorumKeyShare ActivityType = "ACTIVITY_TYPE_RE_ENCRYPT_TVC_QUORUM_KEY_SHARE" - ActivityTypeInitImportSecrets ActivityType = "ACTIVITY_TYPE_INIT_IMPORT_SECRETS" - ActivityTypeSolSendTransactionV2 ActivityType = "ACTIVITY_TYPE_SOL_SEND_TRANSACTION_V2" - ActivityTypeClaimSwapFees ActivityType = "ACTIVITY_TYPE_CLAIM_SWAP_FEES" - ActivityTypeEarnSetWrapperState ActivityType = "ACTIVITY_TYPE_EARN_SET_WRAPPER_STATE" - ActivityTypeClaimEarnFees ActivityType = "ACTIVITY_TYPE_CLAIM_EARN_FEES" - ActivityTypeUpdateWalletAccountName ActivityType = "ACTIVITY_TYPE_UPDATE_WALLET_ACCOUNT_NAME" - ActivityTypeETHUndelegate7702 ActivityType = "ACTIVITY_TYPE_ETH_UNDELEGATE_7702" - ActivityTypeExecuteSwapV2 ActivityType = "ACTIVITY_TYPE_EXECUTE_SWAP_V2" - ActivityTypeCreateSwapQuote ActivityType = "ACTIVITY_TYPE_CREATE_SWAP_QUOTE" - ActivityTypeImportSecrets ActivityType = "ACTIVITY_TYPE_IMPORT_SECRETS" - ActivityTypeExportSecrets ActivityType = "ACTIVITY_TYPE_EXPORT_SECRETS" - ActivityTypeCreateVelocityControl ActivityType = "ACTIVITY_TYPE_CREATE_VELOCITY_CONTROL" - ActivityTypeDeleteVelocityControl ActivityType = "ACTIVITY_TYPE_DELETE_VELOCITY_CONTROL" + ActivityTypeCreateAPIKeys ActivityType = "ACTIVITY_TYPE_CREATE_API_KEYS" + ActivityTypeCreateUsers ActivityType = "ACTIVITY_TYPE_CREATE_USERS" + ActivityTypeCreatePrivateKeys ActivityType = "ACTIVITY_TYPE_CREATE_PRIVATE_KEYS" + ActivityTypeSignRawPayload ActivityType = "ACTIVITY_TYPE_SIGN_RAW_PAYLOAD" + ActivityTypeCreateInvitations ActivityType = "ACTIVITY_TYPE_CREATE_INVITATIONS" + ActivityTypeAcceptInvitation ActivityType = "ACTIVITY_TYPE_ACCEPT_INVITATION" + ActivityTypeCreatePolicy ActivityType = "ACTIVITY_TYPE_CREATE_POLICY" + ActivityTypeDisablePrivateKey ActivityType = "ACTIVITY_TYPE_DISABLE_PRIVATE_KEY" + ActivityTypeDeleteUsers ActivityType = "ACTIVITY_TYPE_DELETE_USERS" + ActivityTypeDeleteAPIKeys ActivityType = "ACTIVITY_TYPE_DELETE_API_KEYS" + ActivityTypeDeleteInvitation ActivityType = "ACTIVITY_TYPE_DELETE_INVITATION" + ActivityTypeDeleteOrganization ActivityType = "ACTIVITY_TYPE_DELETE_ORGANIZATION" + ActivityTypeDeletePolicy ActivityType = "ACTIVITY_TYPE_DELETE_POLICY" + ActivityTypeCreateUserTag ActivityType = "ACTIVITY_TYPE_CREATE_USER_TAG" + ActivityTypeDeleteUserTags ActivityType = "ACTIVITY_TYPE_DELETE_USER_TAGS" + ActivityTypeCreateOrganization ActivityType = "ACTIVITY_TYPE_CREATE_ORGANIZATION" + ActivityTypeSignTransaction ActivityType = "ACTIVITY_TYPE_SIGN_TRANSACTION" + ActivityTypeApproveActivity ActivityType = "ACTIVITY_TYPE_APPROVE_ACTIVITY" + ActivityTypeRejectActivity ActivityType = "ACTIVITY_TYPE_REJECT_ACTIVITY" + ActivityTypeDeleteAuthenticators ActivityType = "ACTIVITY_TYPE_DELETE_AUTHENTICATORS" + ActivityTypeCreateAuthenticators ActivityType = "ACTIVITY_TYPE_CREATE_AUTHENTICATORS" + ActivityTypeCreatePrivateKeyTag ActivityType = "ACTIVITY_TYPE_CREATE_PRIVATE_KEY_TAG" + ActivityTypeDeletePrivateKeyTags ActivityType = "ACTIVITY_TYPE_DELETE_PRIVATE_KEY_TAGS" + ActivityTypeSetPaymentMethod ActivityType = "ACTIVITY_TYPE_SET_PAYMENT_METHOD" + ActivityTypeActivateBillingTier ActivityType = "ACTIVITY_TYPE_ACTIVATE_BILLING_TIER" + ActivityTypeDeletePaymentMethod ActivityType = "ACTIVITY_TYPE_DELETE_PAYMENT_METHOD" + ActivityTypeCreatePolicyV2 ActivityType = "ACTIVITY_TYPE_CREATE_POLICY_V2" + ActivityTypeCreatePolicyV3 ActivityType = "ACTIVITY_TYPE_CREATE_POLICY_V3" + ActivityTypeCreateAPIOnlyUsers ActivityType = "ACTIVITY_TYPE_CREATE_API_ONLY_USERS" + ActivityTypeUpdateRootQuorum ActivityType = "ACTIVITY_TYPE_UPDATE_ROOT_QUORUM" + ActivityTypeUpdateUserTag ActivityType = "ACTIVITY_TYPE_UPDATE_USER_TAG" + ActivityTypeUpdatePrivateKeyTag ActivityType = "ACTIVITY_TYPE_UPDATE_PRIVATE_KEY_TAG" + ActivityTypeCreateAuthenticatorsV2 ActivityType = "ACTIVITY_TYPE_CREATE_AUTHENTICATORS_V2" + ActivityTypeCreateOrganizationV2 ActivityType = "ACTIVITY_TYPE_CREATE_ORGANIZATION_V2" + ActivityTypeCreateUsersV2 ActivityType = "ACTIVITY_TYPE_CREATE_USERS_V2" + ActivityTypeAcceptInvitationV2 ActivityType = "ACTIVITY_TYPE_ACCEPT_INVITATION_V2" + ActivityTypeCreateSubOrganization ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION" + ActivityTypeCreateSubOrganizationV2 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V2" + ActivityTypeUpdateAllowedOrigins ActivityType = "ACTIVITY_TYPE_UPDATE_ALLOWED_ORIGINS" + ActivityTypeCreatePrivateKeysV2 ActivityType = "ACTIVITY_TYPE_CREATE_PRIVATE_KEYS_V2" + ActivityTypeUpdateUser ActivityType = "ACTIVITY_TYPE_UPDATE_USER" + ActivityTypeUpdatePolicy ActivityType = "ACTIVITY_TYPE_UPDATE_POLICY" + ActivityTypeSetPaymentMethodV2 ActivityType = "ACTIVITY_TYPE_SET_PAYMENT_METHOD_V2" + ActivityTypeCreateSubOrganizationV3 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V3" + ActivityTypeCreateWallet ActivityType = "ACTIVITY_TYPE_CREATE_WALLET" + ActivityTypeCreateWalletAccounts ActivityType = "ACTIVITY_TYPE_CREATE_WALLET_ACCOUNTS" + ActivityTypeInitUserEmailRecovery ActivityType = "ACTIVITY_TYPE_INIT_USER_EMAIL_RECOVERY" + ActivityTypeRecoverUser ActivityType = "ACTIVITY_TYPE_RECOVER_USER" + ActivityTypeSetOrganizationFeature ActivityType = "ACTIVITY_TYPE_SET_ORGANIZATION_FEATURE" + ActivityTypeRemoveOrganizationFeature ActivityType = "ACTIVITY_TYPE_REMOVE_ORGANIZATION_FEATURE" + ActivityTypeSignRawPayloadV2 ActivityType = "ACTIVITY_TYPE_SIGN_RAW_PAYLOAD_V2" + ActivityTypeSignTransactionV2 ActivityType = "ACTIVITY_TYPE_SIGN_TRANSACTION_V2" + ActivityTypeExportPrivateKey ActivityType = "ACTIVITY_TYPE_EXPORT_PRIVATE_KEY" + ActivityTypeExportWallet ActivityType = "ACTIVITY_TYPE_EXPORT_WALLET" + ActivityTypeCreateSubOrganizationV4 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V4" + ActivityTypeEmailAuth ActivityType = "ACTIVITY_TYPE_EMAIL_AUTH" + ActivityTypeExportWalletAccount ActivityType = "ACTIVITY_TYPE_EXPORT_WALLET_ACCOUNT" + ActivityTypeInitImportWallet ActivityType = "ACTIVITY_TYPE_INIT_IMPORT_WALLET" + ActivityTypeImportWallet ActivityType = "ACTIVITY_TYPE_IMPORT_WALLET" + ActivityTypeInitImportPrivateKey ActivityType = "ACTIVITY_TYPE_INIT_IMPORT_PRIVATE_KEY" + ActivityTypeImportPrivateKey ActivityType = "ACTIVITY_TYPE_IMPORT_PRIVATE_KEY" + ActivityTypeCreatePolicies ActivityType = "ACTIVITY_TYPE_CREATE_POLICIES" + ActivityTypeSignRawPayloads ActivityType = "ACTIVITY_TYPE_SIGN_RAW_PAYLOADS" + ActivityTypeCreateReadOnlySession ActivityType = "ACTIVITY_TYPE_CREATE_READ_ONLY_SESSION" + ActivityTypeCreateOAuthProviders ActivityType = "ACTIVITY_TYPE_CREATE_OAUTH_PROVIDERS" + ActivityTypeDeleteOAuthProviders ActivityType = "ACTIVITY_TYPE_DELETE_OAUTH_PROVIDERS" + ActivityTypeCreateSubOrganizationV5 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V5" + ActivityTypeOAuth ActivityType = "ACTIVITY_TYPE_OAUTH" + ActivityTypeCreateAPIKeysV2 ActivityType = "ACTIVITY_TYPE_CREATE_API_KEYS_V2" + ActivityTypeCreateReadWriteSession ActivityType = "ACTIVITY_TYPE_CREATE_READ_WRITE_SESSION" + ActivityTypeEmailAuthV2 ActivityType = "ACTIVITY_TYPE_EMAIL_AUTH_V2" + ActivityTypeCreateSubOrganizationV6 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V6" + ActivityTypeDeletePrivateKeys ActivityType = "ACTIVITY_TYPE_DELETE_PRIVATE_KEYS" + ActivityTypeDeleteWallets ActivityType = "ACTIVITY_TYPE_DELETE_WALLETS" + ActivityTypeCreateReadWriteSessionV2 ActivityType = "ACTIVITY_TYPE_CREATE_READ_WRITE_SESSION_V2" + ActivityTypeDeleteSubOrganization ActivityType = "ACTIVITY_TYPE_DELETE_SUB_ORGANIZATION" + ActivityTypeInitOTPAuth ActivityType = "ACTIVITY_TYPE_INIT_OTP_AUTH" + ActivityTypeOTPAuth ActivityType = "ACTIVITY_TYPE_OTP_AUTH" + ActivityTypeCreateSubOrganizationV7 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V7" + ActivityTypeUpdateWallet ActivityType = "ACTIVITY_TYPE_UPDATE_WALLET" + ActivityTypeUpdatePolicyV2 ActivityType = "ACTIVITY_TYPE_UPDATE_POLICY_V2" + ActivityTypeCreateUsersV3 ActivityType = "ACTIVITY_TYPE_CREATE_USERS_V3" + ActivityTypeInitOTPAuthV2 ActivityType = "ACTIVITY_TYPE_INIT_OTP_AUTH_V2" + ActivityTypeInitOTP ActivityType = "ACTIVITY_TYPE_INIT_OTP" + ActivityTypeVerifyOTP ActivityType = "ACTIVITY_TYPE_VERIFY_OTP" + ActivityTypeOTPLogin ActivityType = "ACTIVITY_TYPE_OTP_LOGIN" + ActivityTypeStampLogin ActivityType = "ACTIVITY_TYPE_STAMP_LOGIN" + ActivityTypeOAuthLogin ActivityType = "ACTIVITY_TYPE_OAUTH_LOGIN" + ActivityTypeUpdateUserName ActivityType = "ACTIVITY_TYPE_UPDATE_USER_NAME" + ActivityTypeUpdateUserEmail ActivityType = "ACTIVITY_TYPE_UPDATE_USER_EMAIL" + ActivityTypeUpdateUserPhoneNumber ActivityType = "ACTIVITY_TYPE_UPDATE_USER_PHONE_NUMBER" + ActivityTypeInitFiatOnRamp ActivityType = "ACTIVITY_TYPE_INIT_FIAT_ON_RAMP" + ActivityTypeCreateSmartContractInterface ActivityType = "ACTIVITY_TYPE_CREATE_SMART_CONTRACT_INTERFACE" + ActivityTypeDeleteSmartContractInterface ActivityType = "ACTIVITY_TYPE_DELETE_SMART_CONTRACT_INTERFACE" + ActivityTypeEnableAuthProxy ActivityType = "ACTIVITY_TYPE_ENABLE_AUTH_PROXY" + ActivityTypeDisableAuthProxy ActivityType = "ACTIVITY_TYPE_DISABLE_AUTH_PROXY" + ActivityTypeUpdateAuthProxyConfig ActivityType = "ACTIVITY_TYPE_UPDATE_AUTH_PROXY_CONFIG" + ActivityTypeCreateOAuth2Credential ActivityType = "ACTIVITY_TYPE_CREATE_OAUTH2_CREDENTIAL" + ActivityTypeUpdateOAuth2Credential ActivityType = "ACTIVITY_TYPE_UPDATE_OAUTH2_CREDENTIAL" + ActivityTypeDeleteOAuth2Credential ActivityType = "ACTIVITY_TYPE_DELETE_OAUTH2_CREDENTIAL" + ActivityTypeOAuth2Authenticate ActivityType = "ACTIVITY_TYPE_OAUTH2_AUTHENTICATE" + ActivityTypeDeleteWalletAccounts ActivityType = "ACTIVITY_TYPE_DELETE_WALLET_ACCOUNTS" + ActivityTypeDeletePolicies ActivityType = "ACTIVITY_TYPE_DELETE_POLICIES" + ActivityTypeETHSendRawTransaction ActivityType = "ACTIVITY_TYPE_ETH_SEND_RAW_TRANSACTION" + ActivityTypeETHSendTransaction ActivityType = "ACTIVITY_TYPE_ETH_SEND_TRANSACTION" + ActivityTypeCreateFiatOnRampCredential ActivityType = "ACTIVITY_TYPE_CREATE_FIAT_ON_RAMP_CREDENTIAL" + ActivityTypeUpdateFiatOnRampCredential ActivityType = "ACTIVITY_TYPE_UPDATE_FIAT_ON_RAMP_CREDENTIAL" + ActivityTypeDeleteFiatOnRampCredential ActivityType = "ACTIVITY_TYPE_DELETE_FIAT_ON_RAMP_CREDENTIAL" + ActivityTypeEmailAuthV3 ActivityType = "ACTIVITY_TYPE_EMAIL_AUTH_V3" + ActivityTypeInitUserEmailRecoveryV2 ActivityType = "ACTIVITY_TYPE_INIT_USER_EMAIL_RECOVERY_V2" + ActivityTypeInitOTPAuthV3 ActivityType = "ACTIVITY_TYPE_INIT_OTP_AUTH_V3" + ActivityTypeInitOtpv2 ActivityType = "ACTIVITY_TYPE_INIT_OTP_V2" + ActivityTypeUpsertGasUsageConfig ActivityType = "ACTIVITY_TYPE_UPSERT_GAS_USAGE_CONFIG" + ActivityTypeCreateTVCApp ActivityType = "ACTIVITY_TYPE_CREATE_TVC_APP" + ActivityTypeCreateTVCDeployment ActivityType = "ACTIVITY_TYPE_CREATE_TVC_DEPLOYMENT" + ActivityTypeCreateTVCManifestApprovals ActivityType = "ACTIVITY_TYPE_CREATE_TVC_MANIFEST_APPROVALS" + ActivityTypeSolSendTransaction ActivityType = "ACTIVITY_TYPE_SOL_SEND_TRANSACTION" + ActivityTypeInitOtpv3 ActivityType = "ACTIVITY_TYPE_INIT_OTP_V3" + ActivityTypeVerifyOtpv2 ActivityType = "ACTIVITY_TYPE_VERIFY_OTP_V2" + ActivityTypeOTPLoginV2 ActivityType = "ACTIVITY_TYPE_OTP_LOGIN_V2" + ActivityTypeUpdateOrganizationName ActivityType = "ACTIVITY_TYPE_UPDATE_ORGANIZATION_NAME" + ActivityTypeCreateSubOrganizationV8 ActivityType = "ACTIVITY_TYPE_CREATE_SUB_ORGANIZATION_V8" + ActivityTypeCreateOAuthProvidersV2 ActivityType = "ACTIVITY_TYPE_CREATE_OAUTH_PROVIDERS_V2" + ActivityTypeCreateUsersV4 ActivityType = "ACTIVITY_TYPE_CREATE_USERS_V4" + ActivityTypeCreateWebhookEndpoint ActivityType = "ACTIVITY_TYPE_CREATE_WEBHOOK_ENDPOINT" + ActivityTypeUpdateWebhookEndpoint ActivityType = "ACTIVITY_TYPE_UPDATE_WEBHOOK_ENDPOINT" + ActivityTypeDeleteWebhookEndpoint ActivityType = "ACTIVITY_TYPE_DELETE_WEBHOOK_ENDPOINT" + ActivityTypeSetIPAllowlist ActivityType = "ACTIVITY_TYPE_SET_IP_ALLOWLIST" + ActivityTypeRemoveIPAllowlist ActivityType = "ACTIVITY_TYPE_REMOVE_IP_ALLOWLIST" + ActivityTypeUpdateTVCAppLiveDeployment ActivityType = "ACTIVITY_TYPE_UPDATE_TVC_APP_LIVE_DEPLOYMENT" + ActivityTypeDeleteTVCDeployment ActivityType = "ACTIVITY_TYPE_DELETE_TVC_DEPLOYMENT" + ActivityTypeDeleteTVCAppAndDeployments ActivityType = "ACTIVITY_TYPE_DELETE_TVC_APP_AND_DEPLOYMENTS" + ActivityTypeRestoreTVCDeployment ActivityType = "ACTIVITY_TYPE_RESTORE_TVC_DEPLOYMENT" + ActivityTypeSparkSignFrost ActivityType = "ACTIVITY_TYPE_SPARK_SIGN_FROST" + ActivityTypeSparkPrepareTransfer ActivityType = "ACTIVITY_TYPE_SPARK_PREPARE_TRANSFER" + ActivityTypeSparkClaimTransfer ActivityType = "ACTIVITY_TYPE_SPARK_CLAIM_TRANSFER" + ActivityTypeSparkPrepareLightningReceive ActivityType = "ACTIVITY_TYPE_SPARK_PREPARE_LIGHTNING_RECEIVE" + ActivityTypePostTVCQuorumKeyShare ActivityType = "ACTIVITY_TYPE_POST_TVC_QUORUM_KEY_SHARE" + ActivityTypeETHSendTransactionV2 ActivityType = "ACTIVITY_TYPE_ETH_SEND_TRANSACTION_V2" + ActivityTypeCreateMfaPolicy ActivityType = "ACTIVITY_TYPE_CREATE_MFA_POLICY" + ActivityTypeUpdateMfaPolicy ActivityType = "ACTIVITY_TYPE_UPDATE_MFA_POLICY" + ActivityTypeDeleteMfaPolicy ActivityType = "ACTIVITY_TYPE_DELETE_MFA_POLICY" + ActivityTypeCreateSessionProfile ActivityType = "ACTIVITY_TYPE_CREATE_SESSION_PROFILE" + ActivityTypeEarnDeployWrapper ActivityType = "ACTIVITY_TYPE_EARN_DEPLOY_WRAPPER" + ActivityTypeEarnDeposit ActivityType = "ACTIVITY_TYPE_EARN_DEPOSIT" + ActivityTypeEarnWithdraw ActivityType = "ACTIVITY_TYPE_EARN_WITHDRAW" + ActivityTypeExecuteSwap ActivityType = "ACTIVITY_TYPE_EXECUTE_SWAP" + ActivityTypeUpsertSwapConfig ActivityType = "ACTIVITY_TYPE_UPSERT_SWAP_CONFIG" + ActivityTypeCreateTVCOperator ActivityType = "ACTIVITY_TYPE_CREATE_TVC_OPERATOR" + ActivityTypeCreateTVCQuorumKey ActivityType = "ACTIVITY_TYPE_CREATE_TVC_QUORUM_KEY" + ActivityTypeReEncryptTVCQuorumKeyShare ActivityType = "ACTIVITY_TYPE_RE_ENCRYPT_TVC_QUORUM_KEY_SHARE" + ActivityTypeInitImportSecrets ActivityType = "ACTIVITY_TYPE_INIT_IMPORT_SECRETS" + ActivityTypeSolSendTransactionV2 ActivityType = "ACTIVITY_TYPE_SOL_SEND_TRANSACTION_V2" + ActivityTypeClaimSwapFees ActivityType = "ACTIVITY_TYPE_CLAIM_SWAP_FEES" + ActivityTypeEarnSetWrapperState ActivityType = "ACTIVITY_TYPE_EARN_SET_WRAPPER_STATE" + ActivityTypeClaimEarnFees ActivityType = "ACTIVITY_TYPE_CLAIM_EARN_FEES" + ActivityTypeUpdateWalletAccountName ActivityType = "ACTIVITY_TYPE_UPDATE_WALLET_ACCOUNT_NAME" + ActivityTypeETHUndelegate7702 ActivityType = "ACTIVITY_TYPE_ETH_UNDELEGATE_7702" + ActivityTypeExecuteSwapV2 ActivityType = "ACTIVITY_TYPE_EXECUTE_SWAP_V2" + ActivityTypeCreateSwapQuote ActivityType = "ACTIVITY_TYPE_CREATE_SWAP_QUOTE" + ActivityTypeImportSecrets ActivityType = "ACTIVITY_TYPE_IMPORT_SECRETS" + ActivityTypeExportSecrets ActivityType = "ACTIVITY_TYPE_EXPORT_SECRETS" + ActivityTypeCreateVelocityControl ActivityType = "ACTIVITY_TYPE_CREATE_VELOCITY_CONTROL" + ActivityTypeDeleteVelocityControls ActivityType = "ACTIVITY_TYPE_DELETE_VELOCITY_CONTROLS" + ActivityTypeUpdatePaymentMethod ActivityType = "ACTIVITY_TYPE_UPDATE_PAYMENT_METHOD" + ActivityTypeCreateSwapQuoteV2 ActivityType = "ACTIVITY_TYPE_CREATE_SWAP_QUOTE_V2" + ActivityTypeExecuteSwapV3 ActivityType = "ACTIVITY_TYPE_EXECUTE_SWAP_V3" + ActivityTypeDeleteSecrets ActivityType = "ACTIVITY_TYPE_DELETE_SECRETS" + ActivityTypeEarnClaimRewards ActivityType = "ACTIVITY_TYPE_EARN_CLAIM_REWARDS" + ActivityTypeCreateSwapQuoteV3 ActivityType = "ACTIVITY_TYPE_CREATE_SWAP_QUOTE_V3" + ActivityTypeUpsertSwapFeeSponsorshipLimitConfig ActivityType = "ACTIVITY_TYPE_UPSERT_SWAP_FEE_SPONSORSHIP_LIMIT_CONFIG" + ActivityTypeUpsertSwapFixedRateLimitConfig ActivityType = "ACTIVITY_TYPE_UPSERT_SWAP_FIXED_RATE_LIMIT_CONFIG" ) type AddressFormat string @@ -305,6 +321,7 @@ type EarnProvider string const ( EarnProviderMorpho EarnProvider = "EARN_PROVIDER_MORPHO" EarnProviderAave EarnProvider = "EARN_PROVIDER_AAVE" + EarnProviderKamino EarnProvider = "EARN_PROVIDER_KAMINO" ) type Effect string @@ -328,6 +345,8 @@ const ( FeatureNameSolanaRentPrefundEnabled FeatureName = "FEATURE_NAME_SOLANA_RENT_PREFUND_ENABLED" FeatureNameSwapConfig FeatureName = "FEATURE_NAME_SWAP_CONFIG" FeatureNameEarnConfig FeatureName = "FEATURE_NAME_EARN_CONFIG" + FeatureNameSwapFeeSponsorship FeatureName = "FEATURE_NAME_SWAP_FEE_SPONSORSHIP" + FeatureNameSwapFixedRate FeatureName = "FEATURE_NAME_SWAP_FIXED_RATE" ) type FiatOnRampBlockchainNetwork string @@ -649,6 +668,16 @@ type BillingSetPaymentMethodResult struct { LastFour string `json:"lastFour"` } +type BillingUpdatePaymentMethodIntent struct { + // The email that will receive invoices for the payment method. + PaymentEmail string `json:"paymentEmail"` +} + +type BillingUpdatePaymentMethodResult struct { + // The email address associated with the payment method. + PaymentEmail string `json:"paymentEmail"` +} + type DataV1Tag struct { CreatedAt ExternalDataV1Timestamp `json:"createdAt"` // Unique identifier for a given Tag. @@ -673,6 +702,13 @@ type ExternalActivityV1PolicyEvaluation struct { VoteID string `json:"voteId"` } +type ExternalCryptoV1Signature struct { + Message *string `json:"message,omitempty"` + PublicKey *string `json:"publicKey,omitempty"` + Scheme *ExternalCryptoV1SignatureScheme `json:"scheme,omitempty"` + Signature *string `json:"signature,omitempty"` +} + type ExternalDataV1Address struct { Address *string `json:"address,omitempty"` Format *AddressFormat `json:"format,omitempty"` @@ -800,6 +836,19 @@ type AcceptInvitationResult struct { UserID string `json:"userId"` } +type ActivePolicyStatus struct { + // Whether the policy is currently active. A policy without a time window is always active. + Active bool `json:"active"` + // Set when the policy's time expression could not be evaluated; the policy is reported inactive. + Error *string `json:"error,omitempty"` + // Unique identifier for the organization the policy belongs to. + OrganizationID string `json:"organizationId"` + // Unique identifier for a given policy. + PolicyID string `json:"policyId"` + // The policy's time expression, absent when the policy has no time window. + TimeExpr *string `json:"timeExpr,omitempty"` +} + type Activity struct { // A list of App Proofs generated by enclaves during activity execution, providing verifiable attestations of performed operations. AppProofs []AppProof `json:"appProofs,omitempty"` @@ -905,6 +954,8 @@ type AssetBalance struct { Name *string `json:"name,omitempty"` // The asset symbol Symbol *string `json:"symbol,omitempty"` + // Solana token program address that owns this mint, inferred from getTokenAccountsByOwner. TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA for classic SPL Token, TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb for Token-2022. Empty for native SOL and non-Solana assets. + TokenProgram *string `json:"tokenProgram,omitempty"` } type AssetBalanceDisplay struct { @@ -1583,11 +1634,47 @@ type CreateSwapQuoteIntent struct { SlippageBps *string `json:"slippageBps,omitempty"` } +type CreateSwapQuoteIntentV2 struct { + // Raw public address that receives the output asset. Required for cross-protocol swaps. The address must match the output token protocol. Wallet account IDs, private key IDs, and CAIP account or asset identifiers are not supported. + DestinationAddress *string `json:"destinationAddress,omitempty"` + // Base-unit amount of the input asset. + InputAmount string `json:"inputAmount"` + // CAIP-19 asset ID for the input asset. The chain is derived from this value. + InputToken string `json:"inputToken"` + // CAIP-19 asset ID for the output asset. + OutputToken string `json:"outputToken"` + // Wallet account address used to price the executable provider quote. Private Key identifiers are not supported. + SignWith string `json:"signWith"` + // Provider-neutral maximum allowed slippage in basis points. Turnkey converts this value to each provider's request format. When omitted, each provider applies its default slippage behavior. + SlippageBps *string `json:"slippageBps,omitempty"` +} + +type CreateSwapQuoteIntentV3 struct { + // Raw public address that receives the output asset. Required for cross-protocol swaps. The address must match the output token protocol. Wallet account IDs, private key IDs, and CAIP account or asset identifiers are not supported. + DestinationAddress *string `json:"destinationAddress,omitempty"` + FeeSponsorship *bool `json:"feeSponsorship,omitempty"` + FixedRate *bool `json:"fixedRate,omitempty"` + // Base-unit amount of the input asset. + InputAmount string `json:"inputAmount"` + // CAIP-19 asset ID for the input asset. The chain is derived from this value. + InputToken string `json:"inputToken"` + // CAIP-19 asset ID for the output asset. + OutputToken string `json:"outputToken"` + // Wallet account address used to price the executable provider quote. Private Key identifiers are not supported. + SignWith string `json:"signWith"` + // Provider-neutral maximum allowed slippage in basis points. Turnkey converts this value to each provider's request format. When omitted, each provider applies its default slippage behavior. + SlippageBps *string `json:"slippageBps,omitempty"` +} + type CreateSwapQuoteResult struct { // One or more provider quotes for this request. Today this contains a single Relay quote; pass quotes[i].quoteId to execute_swap_v2 to bind execution. Quotes []SwapQuote `json:"quotes"` } +type CreateSwapQuoteResultV2 struct { + Quotes []SwapQuoteV2 `json:"quotes,omitempty"` +} + type CreateTVCAppIntent struct { // When true, this app may create deployments in debug-mode. Debug-mode deployments expose logs and emit zero'd attestation PCRs, so remote attestation cannot succeed. Cannot be changed after app creation. Setting this true means the app's quorum key is considered permanently insecure, and a new app with a fresh quorum key must be created. Default if not provided: false. EnableDebugModeDeployments *bool `json:"enableDebugModeDeployments,omitempty"` @@ -1635,6 +1722,10 @@ type CreateTVCDeploymentIntent struct { HealthCheckPort int64 `json:"healthCheckPort"` // Health check type (TVC_HEALTH_CHECK_TYPE_HTTP or TVC_HEALTH_CHECK_TYPE_GRPC). HTTP health checks are made with a GET request on /health, and gRPC health checks follow the standard gRPC health checking protocol. HealthCheckType TVCHealthCheckType `json:"healthCheckType"` + // Optional desired instance cpu count. + InstanceSizeCpus *int64 `json:"instanceSizeCpus,omitempty"` + // Optional desired instance memory size in GiB. + InstanceSizeRam *int64 `json:"instanceSizeRam,omitempty"` // Optional nonce to ensure uniqueness of the deployment manifest. If not provided, it defaults to the current Unix timestamp in seconds. Nonce *int64 `json:"nonce,omitempty"` // Arguments to pass to the pivot binary at startup. Encoded as a list of strings, for example ["--foo", "bar"] @@ -1953,6 +2044,16 @@ type DeletePrivateKeysResult struct { PrivateKeyIds []string `json:"privateKeyIds"` } +type DeleteSecretsIntent struct { + // Unique identifiers of the secrets to delete. Must contain between 1 and 32 distinct UUIDs. All secrets must belong to the organization. + SecretIds []string `json:"secretIds"` +} + +type DeleteSecretsResult struct { + // Unique identifiers of the deleted secrets, in the order requested. + SecretIds []string `json:"secretIds"` +} + type DeleteSmartContractInterfaceIntent struct { // The ID of a Smart Contract Interface intended for deletion. SmartContractInterfaceID string `json:"smartContractInterfaceId"` @@ -2015,12 +2116,14 @@ type DeleteUsersResult struct { UserIds []string `json:"userIds"` } -type DeleteVelocityControlIntent struct { - VelocityControlID string `json:"velocityControlId"` +type DeleteVelocityControlsIntent struct { + // List of unique identifiers for Velocity Controls within an Organization. + VelocityControlIds []string `json:"velocityControlIds"` } -type DeleteVelocityControlResult struct { - VelocityControlID string `json:"velocityControlId"` +type DeleteVelocityControlsResult struct { + // A list of unique identifiers for the deleted Velocity Controls. + VelocityControlIds []string `json:"velocityControlIds"` } type DeleteWalletAccountsIntent struct { @@ -2065,7 +2168,7 @@ type DeploymentStatus struct { // Last time this deployment was updated LastUpdatedTime ExternalDataV1Timestamp `json:"lastUpdatedTime"` // Current quorum-key provisioning state for this deployment - ProvisioningState *ProvisioningState `json:"provisioningState,omitempty"` + ProvisioningState ProvisioningState `json:"provisioningState"` // Number of ready replicas ReadyReplicas int `json:"readyReplicas"` } @@ -2084,9 +2187,23 @@ type DisablePrivateKeyResult struct { PrivateKeyID string `json:"privateKeyId"` } +type EarnClaimRewardsIntent struct { + // CAIP-2 chain to claim rewards on (e.g. 'eip155:8453'). Rewards accrue per chain; see ListEarnRewards. + Caip2 string `json:"caip2"` + // A Turnkey-managed wallet address the rewards are attributed to. The claim transaction is signed by this wallet and the Merkl Distributor transfers every reward token to it. + SignWith string `json:"signWith"` + // Whether to sponsor this transaction via Gas Station. + Sponsor *bool `json:"sponsor,omitempty"` +} + +type EarnClaimRewardsResult struct { + // Identifier to poll claim status and tx hash via GetEarnClaimRewardsStatus. + ClaimRequestID string `json:"claimRequestId"` +} + type EarnDeployWrapperIntent struct { // CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base). - ChainCaip2 string `json:"chainCaip2"` + Caip2 string `json:"caip2"` // Your fee on gross yield, in basis points (e.g., '2000' for 20%). Maximum is 4000 (40%). ClientFeeBps string `json:"clientFeeBps"` // The wallet address that receives the client's fee payouts on-chain. Must be a Turnkey-managed wallet address. @@ -2108,7 +2225,7 @@ type EarnDepositIntent struct { // Amount of the underlying asset to deposit, in raw on-chain units (e.g., '1000000' for 1 USDC at 6 decimals). Assets string `json:"assets"` // CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base). - ChainCaip2 string `json:"chainCaip2"` + Caip2 string `json:"caip2"` // A Wallet account address or Private Key address to deposit from and sign with. Must be an on-chain address; Private Key identifiers are not supported. SignWith string `json:"signWith"` // Whether to sponsor this transaction via Gas Station. @@ -2137,12 +2254,22 @@ type EarnEnabledVault struct { ClientFeeWallet *string `json:"clientFeeWallet,omitempty"` // Vault curator name(s), comma-separated when a vault has multiple. Empty for providers without curators (e.g. Aave). Curator *string `json:"curator,omitempty"` + // Failure detail when deploy_status is FAILED. + DeployError *string `json:"deployError,omitempty"` + // Request id of the wrapper's most recent deploy, for polling GetEarnDeployStatus. Empty when no deploy is recorded. + DeployRequestID *string `json:"deployRequestId,omitempty"` + // On-chain status of the wrapper deployment: PENDING, COMPLETED, or FAILED. Only a COMPLETED wrapper is usable. Empty when no deploy is recorded for the wrapper. + DeployStatus *string `json:"deployStatus,omitempty"` // When true, deposits to this wrapper are rejected; withdrawals are unaffected. Toggled via EarnSetWrapperState. DepositsDisabled *bool `json:"depositsDisabled,omitempty"` // Normalized total-deposited values for display only (usd + crypto). Do not do arithmetic with these; use total_deposited instead. Display *EarnValueDisplay `json:"display,omitempty"` // The underlying markets the vault allocates into, ranked by supplied amount descending. Only populated when the request sets include_exposure, and only for providers that expose an allocation breakdown (Morpho). Exposures []EarnVaultExposure `json:"exposures,omitempty"` + // Additional assets withdrawable from the underlying vault by force-deallocating its non-liquidity adapters at zero penalty, in raw on-chain units of the underlying asset. Additive to liquidity. Empty when the provider does not report it. + ForceDeallocatableLiquidity *string `json:"forceDeallocatableLiquidity,omitempty"` + // Normalized force-deallocatable liquidity values for display purposes only (usd + crypto). Do not do arithmetic with these; use force_deallocatable_liquidity instead. + ForceDeallocatableLiquidityDisplay *EarnValueDisplay `json:"forceDeallocatableLiquidityDisplay,omitempty"` // Assets currently withdrawable from the underlying vault without a reallocation, in raw on-chain units of the underlying asset. This is the vault's liquidity, not the wrapper's balance. Empty when the provider does not report it. Liquidity *string `json:"liquidity,omitempty"` // Normalized liquidity values for display purposes only (usd + crypto). Do not do arithmetic with these; use liquidity instead. @@ -2197,6 +2324,40 @@ type EarnPositionDisplay struct { TotalWithdrawnUsd *string `json:"totalWithdrawnUsd,omitempty"` } +type EarnReward struct { + // CAIP-19 asset ID of the reward token (e.g. 'eip155:8453/erc20:0xBAa5...'). Reward tokens are campaign-specific and unrelated to the position's underlying asset. + Caip19 *string `json:"caip19,omitempty"` + // CAIP-2 chain the reward is claimable on (e.g. 'eip155:8453'). + Caip2 *string `json:"caip2,omitempty"` + // Amount claimable now, in raw on-chain units of the reward token. + Claimable *string `json:"claimable,omitempty"` + // Lifetime amount already claimed, in raw on-chain units of the reward token. + Claimed *string `json:"claimed,omitempty"` + // Decimals of the reward token. + Decimals *int `json:"decimals,omitempty"` + // USD + crypto renderings for display only. Do not do arithmetic with these. + Display *EarnRewardDisplay `json:"display,omitempty"` + // Amount accrued but not yet claimable (not yet in a live on-chain merkle root; roots update roughly every 8 hours), in raw on-chain units of the reward token. + Pending *string `json:"pending,omitempty"` + // Symbol of the reward token (e.g. 'MORPHO'), as reported by Merkl. + Symbol *string `json:"symbol,omitempty"` +} + +type EarnRewardDisplay struct { + // Claimable amount in the reward token's own units, for display only. + ClaimableCrypto *string `json:"claimableCrypto,omitempty"` + // Claimable amount in USD, for display only. Empty when the token is unpriced. + ClaimableUsd *string `json:"claimableUsd,omitempty"` + // Lifetime claimed amount in the reward token's own units, for display only. + ClaimedCrypto *string `json:"claimedCrypto,omitempty"` + // Lifetime claimed amount in USD, for display only. Empty when the token is unpriced. + ClaimedUsd *string `json:"claimedUsd,omitempty"` + // Pending amount in the reward token's own units, for display only. + PendingCrypto *string `json:"pendingCrypto,omitempty"` + // Pending amount in USD, for display only. Empty when the token is unpriced. + PendingUsd *string `json:"pendingUsd,omitempty"` +} + type EarnSetWrapperStateIntent struct { // When true, deposits to this wrapper are rejected; withdrawals are unaffected. Set to false to re-enable deposits. DepositsDisabled bool `json:"depositsDisabled"` @@ -2229,6 +2390,10 @@ type EarnVault struct { Display *EarnValueDisplay `json:"display,omitempty"` // Whether the organization has enabled this vault. Enabled *bool `json:"enabled,omitempty"` + // Additional assets withdrawable from the vault by force-deallocating its non-liquidity adapters at zero penalty, in raw on-chain units of the underlying asset. Additive to liquidity. Empty when the provider does not report it. + ForceDeallocatableLiquidity *string `json:"forceDeallocatableLiquidity,omitempty"` + // Normalized force-deallocatable liquidity values for display purposes only (usd + crypto). Do not do arithmetic with these; use force_deallocatable_liquidity instead. + ForceDeallocatableLiquidityDisplay *EarnValueDisplay `json:"forceDeallocatableLiquidityDisplay,omitempty"` // Assets currently withdrawable from the vault without a reallocation, in raw on-chain units of the underlying asset. Empty when the provider does not report it. Liquidity *string `json:"liquidity,omitempty"` // Normalized liquidity values for display purposes only (usd + crypto). Do not do arithmetic with these; use liquidity instead. @@ -2264,7 +2429,7 @@ type EarnWithdrawIntent struct { // The amount of the underlying asset to withdraw, in raw on-chain units. Pass 'MAX' to withdraw the entire position. AmountValue string `json:"amountValue"` // CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base). - ChainCaip2 string `json:"chainCaip2"` + Caip2 string `json:"caip2"` // A Wallet account address or Private Key address to withdraw to and sign with. Must be an on-chain address; Private Key identifiers are not supported. SignWith string `json:"signWith"` // Whether to sponsor this transaction via Gas Station. @@ -2526,6 +2691,8 @@ type ETHSendTransactionStatus struct { type ETHTransactionHistoryItem struct { // Block metadata for the transaction. Block TransactionHistoryBlock `json:"block"` + // Whether the transaction failed during on-chain execution. Omitted when execution outcome is unavailable. + ExecutionFailed *bool `json:"executionFailed,omitempty"` // Transaction fee information. Fee TransactionHistoryFee `json:"fee"` // EVM sender address for the transaction. @@ -2606,6 +2773,31 @@ type ExecuteSwapIntentV2 struct { Sponsor bool `json:"sponsor"` } +type ExecuteSwapIntentV3 struct { + // Raw public address that receives the output asset. Required for cross-protocol swaps. The address must match the output token protocol. Wallet account IDs, private key IDs, and CAIP account or asset identifiers are not supported. + DestinationAddress *string `json:"destinationAddress,omitempty"` + // Exact EVM sender (EOA account) nonce. Valid only for a non-sponsored EVM swap. Honored for already-delegated (Type-2) batch swaps and single-call swaps; ignored for not-yet-delegated EIP-7702 (Type-4) batches where the outer nonce is derived from the authorization. Prefer gas_station_nonce for batch replay protection and use the nonces endpoint to fetch it. Omit to auto-fetch. + EvmNonce *string `json:"evmNonce,omitempty"` + // Exact gas station delegate contract nonce used in the BatchExecution EIP-712 message. Valid for sponsored EVM swaps and non-sponsored EVM swaps that execute as a multi-call batch (for example ERC-20 approve + swap). This is the replay-protection nonce for gas-station batches; use the nonces endpoint to fetch it. Omit to auto-fetch. + GasStationNonce *string `json:"gasStationNonce,omitempty"` + // Exact base-unit amount of the input asset committed by the quote. + InputAmount string `json:"inputAmount"` + // CAIP-19 asset ID for the input asset. + InputToken string `json:"inputToken"` + // Exact minimum base-unit output committed by the quote. + MinOutputAmount string `json:"minOutputAmount"` + // CAIP-19 asset ID for the output asset. + OutputToken string `json:"outputToken"` + // Quote identifier returned by create_swap_quote. Execution is bound to this quote; the signer is derived from the quote and must not be resupplied. + QuoteID string `json:"quoteId"` + // Exact quoted base-unit output amount committed by the quote. + QuotedOutputAmount string `json:"quotedOutputAmount"` + // Exact Solana recent blockhash. Valid only for a Solana swap, including sponsored swaps. Omit to auto-fetch. + RecentBlockhash *string `json:"recentBlockhash,omitempty"` + // Whether the quoted transaction is sponsored. + Sponsor bool `json:"sponsor"` +} + type ExecuteSwapResult struct { // Swap provider used to build the transaction. Provider *string `json:"provider,omitempty"` @@ -2632,6 +2824,8 @@ type ExportPrivateKeyResult struct { type ExportSecretParams struct { // Transport encryption suite used for the exported secret. EncryptionSuite TransportEncryptionSuite `json:"encryptionSuite"` + // Bind metadata to the request. + RequestContext []KeyValue `json:"requestContext,omitempty"` // Unique identifier for the secret to export. SecretID string `json:"secretId"` // Client-side public key generated by the user, to which the exported secret will be encrypted. @@ -2678,6 +2872,19 @@ type ExportWalletResult struct { WalletID string `json:"walletId"` } +type ExternalSignerTask struct { + // The activity associated with the external signer task. + Activity Activity `json:"activity"` + // Unique identifier for the organization associated with the external signer task. + OrganizationID string `json:"organizationId"` + // Ump signature associated with the external signer task. + Signature ExternalCryptoV1Signature `json:"signature"` + // Unique identifier for a given external signer task. + TaskID string `json:"taskId"` + // Unique identifier for the user associated with the external signer task. + UserID string `json:"userId"` +} + type Feature struct { Name *FeatureName `json:"name,omitempty"` Value *string `json:"value,omitempty"` @@ -2709,6 +2916,8 @@ type AuthProxyGetAccountRequest struct { FilterType string `json:"filterType"` // The value of the filter to apply for the specified type. For example, a specific email or name string. FilterValue string `json:"filterValue"` + // Whether to include requires_social_linking in the response. Only applies when filter_type is 'OIDC_TOKEN'. + IncludeRequiresSocialLinking *bool `json:"includeRequiresSocialLinking,omitempty"` // OIDC token to verify access to PII (email/phone number) when filter_type is 'EMAIL' or 'PHONE_NUMBER'. Needed for social linking when verification_token is not available. OidcToken *string `json:"oidcToken,omitempty"` // Signed JWT containing a unique id, expiry, verification type, contact. Used to verify access to PII (email/phone number) when filter_type is 'EMAIL' or 'PHONE_NUMBER'. @@ -2717,6 +2926,20 @@ type AuthProxyGetAccountRequest struct { type AuthProxyGetAccountResponse struct { OrganizationID *string `json:"organizationId,omitempty"` + // True when the organization was matched by verified email and the OIDC token is not yet a registered identity on it. + RequiresSocialLinking *bool `json:"requiresSocialLinking,omitempty"` +} + +type GetActivePoliciesRequest struct { + // Unique identifier for a given organization. + OrganizationID string `json:"organizationId"` +} + +type GetActivePoliciesResponse struct { + // The enclave's trusted timestamp (Unix epoch milliseconds) used to evaluate every policy. + EvaluatedAtMs string `json:"evaluatedAtMs"` + // The active/inactive status of every policy in the organization. + Statuses []ActivePolicyStatus `json:"statuses"` } type GetActivitiesRequest struct { @@ -2836,6 +3059,22 @@ type GetClaimEarnFeesStatusResponse struct { Status string `json:"status"` } +type GetEarnClaimRewardsStatusRequest struct { + // The claim_request_id returned by EarnClaimRewards. + ClaimRequestID string `json:"claimRequestId"` + // Unique identifier for a given Organization. + OrganizationID string `json:"organizationId"` +} + +type GetEarnClaimRewardsStatusResponse struct { + // Transaction hash of the rewards claim, once available. + ClaimTxHash *string `json:"claimTxHash,omitempty"` + // Reason the rewards claim transaction failed, when status is FAILED. + Error *string `json:"error,omitempty"` + // Status of the rewards claim. + Status string `json:"status"` +} + type GetEarnDeployStatusRequest struct { // The deploy_request_id returned by EarnDeployWrapper. DeployRequestID string `json:"deployRequestId"` @@ -2884,6 +3123,20 @@ type GetEarnWithdrawStatusResponse struct { WithdrawTxHash *string `json:"withdrawTxHash,omitempty"` } +type GetExternalSignerTasksRequest struct { + // Public key of the external signer. + ExternalSignerPublicKey string `json:"externalSignerPublicKey"` + // Maximum number of tasks to retrieve. + MaxTasks int64 `json:"maxTasks"` + // Unique identifier for a given organization. + OrganizationID string `json:"organizationId"` +} + +type GetExternalSignerTasksResponse struct { + // List of external signer tasks. + Tasks []ExternalSignerTask `json:"tasks"` +} + type GetGasUsageRequest struct { // Unique identifier for a given Organization. OrganizationID string `json:"organizationId"` @@ -3158,6 +3411,15 @@ type GetSubOrgIdsResponse struct { OrganizationIds []string `json:"organizationIds"` } +type GetSwapSponsorshipUsageRequest struct { + OrganizationID string `json:"organizationId"` +} + +type GetSwapSponsorshipUsageResponse struct { + FeeSponsorship SwapSponsorshipFeature `json:"feeSponsorship"` + FixedRate SwapSponsorshipFeature `json:"fixedRate"` +} + type GetSwapStatusRequest struct { // Unique identifier for a given Organization. OrganizationID string `json:"organizationId"` @@ -3166,6 +3428,8 @@ type GetSwapStatusRequest struct { } type GetSwapStatusResponse struct { + // Address that receives the output asset. + DestinationAddress *string `json:"destinationAddress,omitempty"` // Provider-reported destination-chain transaction hashes; cross-chain COMPLETED only. DestinationTxHashes []string `json:"destinationTxHashes,omitempty"` // Normalized failure details, present whenever status is FAILED. @@ -3217,6 +3481,8 @@ type GetTVCAppResponse struct { } type GetTVCAppsRequest struct { + // Filter TVC Apps by whether they have a live deployment. If omitted, all TVC Apps are returned. + IsLive *bool `json:"isLive,omitempty"` // Unique identifier for a given organization. OrganizationID string `json:"organizationId"` } @@ -3242,6 +3508,22 @@ type GetTVCDeploymentDebugLogsResponse struct { Entries []TVCDeploymentDebugLogEntry `json:"entries"` } +type GetTVCDeploymentProvisioningDetailsRequest struct { + // Unique identifier for a given TVC Deployment. + DeploymentID string `json:"deploymentId"` + // Unique identifier for a given Organization. + OrganizationID string `json:"organizationId"` +} + +type GetTVCDeploymentProvisioningDetailsResponse struct { + // The attestation document of the provisioning enclave. Present only when a deployment is awaiting provisioning. + AttestationDocument *string `json:"attestationDocument,omitempty"` + // The manifest envelope containing the TVC deployment's manifest and signatures. Present only when a deployment is awaiting provisioning. + ManifestEnvelope *string `json:"manifestEnvelope,omitempty"` + // Current provisioning state. + ProvisioningState ProvisioningState `json:"provisioningState"` +} + type GetTVCDeploymentRequest struct { // Unique identifier for a given TVC Deployment. DeploymentID string `json:"deploymentId"` @@ -3254,6 +3536,15 @@ type GetTVCDeploymentResponse struct { TVCDeployment TVCDeployment `json:"tvcDeployment"` } +type GetTVCOperatorsRequest struct { + // Unique identifier for a given organization. + OrganizationID string `json:"organizationId"` +} + +type GetTVCOperatorsResponse struct { + TVCOperators []TVCOperator `json:"tvcOperators"` +} + type GetTVCQosVersionsRequest struct { // Unique identifier for a given Organization. OrganizationID string `json:"organizationId"` @@ -3266,6 +3557,15 @@ type GetTVCQosVersionsResponse struct { LatestVersion string `json:"latestVersion"` } +type GetTVCQuorumKeysRequest struct { + // Unique identifier for a given organization. + OrganizationID string `json:"organizationId"` +} + +type GetTVCQuorumKeysResponse struct { + TVCQuorumKeys []TVCQuorumKey `json:"tvcQuorumKeys"` +} + type GetUserRequest struct { // Unique identifier for a given organization. OrganizationID string `json:"organizationId"` @@ -3288,17 +3588,8 @@ type GetUsersResponse struct { Users []User `json:"users"` } -type GetVelocityControlRequest struct { - OrganizationID string `json:"organizationId"` - VelocityControlID string `json:"velocityControlId"` -} - -type GetVelocityControlResponse struct { - VelocityControl VelocityControl `json:"velocityControl"` -} - type GetVerifiedSubOrgIdsRequest struct { - // Specifies the type of filter to apply, i.e 'EMAIL', 'PHONE_NUMBER'. + // Specifies the type of filter to apply, i.e 'EMAIL', 'PHONE_NUMBER', 'OIDC_TOKEN', 'OAUTH_CLAIM', or 'PUBLIC_KEY' FilterType *string `json:"filterType,omitempty"` // The value of the filter to apply for the specified type. For example, a specific email or phone number string. FilterValue *string `json:"filterValue,omitempty"` @@ -3779,170 +4070,178 @@ type InitUserEmailRecoveryResult struct { } type Intent struct { - AcceptInvitationIntent *AcceptInvitationIntent `json:"acceptInvitationIntent,omitempty"` - AcceptInvitationIntentV2 *AcceptInvitationIntentV2 `json:"acceptInvitationIntentV2,omitempty"` - ActivateBillingTierIntent *BillingActivateBillingTierIntent `json:"activateBillingTierIntent,omitempty"` - ApproveActivityIntent *ApproveActivityIntent `json:"approveActivityIntent,omitempty"` - ClaimEarnFeesIntent *ClaimEarnFeesIntent `json:"claimEarnFeesIntent,omitempty"` - ClaimSwapFeesIntent *ClaimSwapFeesIntent `json:"claimSwapFeesIntent,omitempty"` - CreateAPIKeysIntent *CreateAPIKeysIntent `json:"createApiKeysIntent,omitempty"` - CreateAPIKeysIntentV2 *CreateAPIKeysIntentV2 `json:"createApiKeysIntentV2,omitempty"` - CreateAPIOnlyUsersIntent *CreateAPIOnlyUsersIntent `json:"createApiOnlyUsersIntent,omitempty"` - CreateAuthenticatorsIntent *CreateAuthenticatorsIntent `json:"createAuthenticatorsIntent,omitempty"` - CreateAuthenticatorsIntentV2 *CreateAuthenticatorsIntentV2 `json:"createAuthenticatorsIntentV2,omitempty"` - CreateFiatOnRampCredentialIntent *CreateFiatOnRampCredentialIntent `json:"createFiatOnRampCredentialIntent,omitempty"` - CreateInvitationsIntent *CreateInvitationsIntent `json:"createInvitationsIntent,omitempty"` - CreateMfaPolicyIntent *CreateMfaPolicyIntent `json:"createMfaPolicyIntent,omitempty"` - CreateOAuth2CredentialIntent *CreateOAuth2CredentialIntent `json:"createOauth2CredentialIntent,omitempty"` - CreateOAuthProvidersIntent *CreateOAuthProvidersIntent `json:"createOauthProvidersIntent,omitempty"` - CreateOAuthProvidersIntentV2 *CreateOAuthProvidersIntentV2 `json:"createOauthProvidersIntentV2,omitempty"` - CreateOrganizationIntent *CreateOrganizationIntent `json:"createOrganizationIntent,omitempty"` - CreateOrganizationIntentV2 *CreateOrganizationIntentV2 `json:"createOrganizationIntentV2,omitempty"` - CreatePoliciesIntent *CreatePoliciesIntent `json:"createPoliciesIntent,omitempty"` - CreatePolicyIntent *CreatePolicyIntent `json:"createPolicyIntent,omitempty"` - CreatePolicyIntentV2 *CreatePolicyIntentV2 `json:"createPolicyIntentV2,omitempty"` - CreatePolicyIntentV3 *CreatePolicyIntentV3 `json:"createPolicyIntentV3,omitempty"` - CreatePrivateKeyTagIntent *CreatePrivateKeyTagIntent `json:"createPrivateKeyTagIntent,omitempty"` - CreatePrivateKeysIntent *CreatePrivateKeysIntent `json:"createPrivateKeysIntent,omitempty"` - CreatePrivateKeysIntentV2 *CreatePrivateKeysIntentV2 `json:"createPrivateKeysIntentV2,omitempty"` - CreateReadOnlySessionIntent *CreateReadOnlySessionIntent `json:"createReadOnlySessionIntent,omitempty"` - CreateReadWriteSessionIntent *CreateReadWriteSessionIntent `json:"createReadWriteSessionIntent,omitempty"` - CreateReadWriteSessionIntentV2 *CreateReadWriteSessionIntentV2 `json:"createReadWriteSessionIntentV2,omitempty"` - CreateSessionProfileIntent *CreateSessionProfileIntent `json:"createSessionProfileIntent,omitempty"` - CreateSmartContractInterfaceIntent *CreateSmartContractInterfaceIntent `json:"createSmartContractInterfaceIntent,omitempty"` - CreateSubOrganizationIntent *CreateSubOrganizationIntent `json:"createSubOrganizationIntent,omitempty"` - CreateSubOrganizationIntentV2 *CreateSubOrganizationIntentV2 `json:"createSubOrganizationIntentV2,omitempty"` - CreateSubOrganizationIntentV3 *CreateSubOrganizationIntentV3 `json:"createSubOrganizationIntentV3,omitempty"` - CreateSubOrganizationIntentV4 *CreateSubOrganizationIntentV4 `json:"createSubOrganizationIntentV4,omitempty"` - CreateSubOrganizationIntentV5 *CreateSubOrganizationIntentV5 `json:"createSubOrganizationIntentV5,omitempty"` - CreateSubOrganizationIntentV6 *CreateSubOrganizationIntentV6 `json:"createSubOrganizationIntentV6,omitempty"` - CreateSubOrganizationIntentV7 *CreateSubOrganizationIntentV7 `json:"createSubOrganizationIntentV7,omitempty"` - CreateSubOrganizationIntentV8 *CreateSubOrganizationIntentV8 `json:"createSubOrganizationIntentV8,omitempty"` - CreateSwapQuoteIntent *CreateSwapQuoteIntent `json:"createSwapQuoteIntent,omitempty"` - CreateTVCAppIntent *CreateTVCAppIntent `json:"createTvcAppIntent,omitempty"` - CreateTVCDeploymentIntent *CreateTVCDeploymentIntent `json:"createTvcDeploymentIntent,omitempty"` - CreateTVCManifestApprovalsIntent *CreateTVCManifestApprovalsIntent `json:"createTvcManifestApprovalsIntent,omitempty"` - CreateTVCOperatorIntent *CreateTVCOperatorIntent `json:"createTvcOperatorIntent,omitempty"` - CreateTVCQuorumKeyIntent *CreateTVCQuorumKeyIntent `json:"createTvcQuorumKeyIntent,omitempty"` - CreateUserTagIntent *CreateUserTagIntent `json:"createUserTagIntent,omitempty"` - CreateUsersIntent *CreateUsersIntent `json:"createUsersIntent,omitempty"` - CreateUsersIntentV2 *CreateUsersIntentV2 `json:"createUsersIntentV2,omitempty"` - CreateUsersIntentV3 *CreateUsersIntentV3 `json:"createUsersIntentV3,omitempty"` - CreateUsersIntentV4 *CreateUsersIntentV4 `json:"createUsersIntentV4,omitempty"` - CreateVelocityControlIntent *CreateVelocityControlIntent `json:"createVelocityControlIntent,omitempty"` - CreateWalletAccountsIntent *CreateWalletAccountsIntent `json:"createWalletAccountsIntent,omitempty"` - CreateWalletIntent *CreateWalletIntent `json:"createWalletIntent,omitempty"` - CreateWebhookEndpointIntent *CreateWebhookEndpointIntent `json:"createWebhookEndpointIntent,omitempty"` - DeleteAPIKeysIntent *DeleteAPIKeysIntent `json:"deleteApiKeysIntent,omitempty"` - DeleteAuthenticatorsIntent *DeleteAuthenticatorsIntent `json:"deleteAuthenticatorsIntent,omitempty"` - DeleteFiatOnRampCredentialIntent *DeleteFiatOnRampCredentialIntent `json:"deleteFiatOnRampCredentialIntent,omitempty"` - DeleteInvitationIntent *DeleteInvitationIntent `json:"deleteInvitationIntent,omitempty"` - DeleteMfaPolicyIntent *DeleteMfaPolicyIntent `json:"deleteMfaPolicyIntent,omitempty"` - DeleteOAuth2CredentialIntent *DeleteOAuth2CredentialIntent `json:"deleteOauth2CredentialIntent,omitempty"` - DeleteOAuthProvidersIntent *DeleteOAuthProvidersIntent `json:"deleteOauthProvidersIntent,omitempty"` - DeleteOrganizationIntent *DeleteOrganizationIntent `json:"deleteOrganizationIntent,omitempty"` - DeletePaymentMethodIntent *BillingDeletePaymentMethodIntent `json:"deletePaymentMethodIntent,omitempty"` - DeletePoliciesIntent *DeletePoliciesIntent `json:"deletePoliciesIntent,omitempty"` - DeletePolicyIntent *DeletePolicyIntent `json:"deletePolicyIntent,omitempty"` - DeletePrivateKeyTagsIntent *DeletePrivateKeyTagsIntent `json:"deletePrivateKeyTagsIntent,omitempty"` - DeletePrivateKeysIntent *DeletePrivateKeysIntent `json:"deletePrivateKeysIntent,omitempty"` - DeleteSmartContractInterfaceIntent *DeleteSmartContractInterfaceIntent `json:"deleteSmartContractInterfaceIntent,omitempty"` - DeleteSubOrganizationIntent *DeleteSubOrganizationIntent `json:"deleteSubOrganizationIntent,omitempty"` - DeleteTVCAppAndDeploymentsIntent *DeleteTVCAppAndDeploymentsIntent `json:"deleteTvcAppAndDeploymentsIntent,omitempty"` - DeleteTVCDeploymentIntent *DeleteTVCDeploymentIntent `json:"deleteTvcDeploymentIntent,omitempty"` - DeleteUserTagsIntent *DeleteUserTagsIntent `json:"deleteUserTagsIntent,omitempty"` - DeleteUsersIntent *DeleteUsersIntent `json:"deleteUsersIntent,omitempty"` - DeleteVelocityControlIntent *DeleteVelocityControlIntent `json:"deleteVelocityControlIntent,omitempty"` - DeleteWalletAccountsIntent *DeleteWalletAccountsIntent `json:"deleteWalletAccountsIntent,omitempty"` - DeleteWalletsIntent *DeleteWalletsIntent `json:"deleteWalletsIntent,omitempty"` - DeleteWebhookEndpointIntent *DeleteWebhookEndpointIntent `json:"deleteWebhookEndpointIntent,omitempty"` - DisableAuthProxyIntent *DisableAuthProxyIntent `json:"disableAuthProxyIntent,omitempty"` - DisablePrivateKeyIntent *DisablePrivateKeyIntent `json:"disablePrivateKeyIntent,omitempty"` - EarnDeployWrapperIntent *EarnDeployWrapperIntent `json:"earnDeployWrapperIntent,omitempty"` - EarnDepositIntent *EarnDepositIntent `json:"earnDepositIntent,omitempty"` - EarnSetWrapperStateIntent *EarnSetWrapperStateIntent `json:"earnSetWrapperStateIntent,omitempty"` - EarnWithdrawIntent *EarnWithdrawIntent `json:"earnWithdrawIntent,omitempty"` - EmailAuthIntent *EmailAuthIntent `json:"emailAuthIntent,omitempty"` - EmailAuthIntentV2 *EmailAuthIntentV2 `json:"emailAuthIntentV2,omitempty"` - EmailAuthIntentV3 *EmailAuthIntentV3 `json:"emailAuthIntentV3,omitempty"` - EnableAuthProxyIntent *EnableAuthProxyIntent `json:"enableAuthProxyIntent,omitempty"` - ETHSendRawTransactionIntent *ETHSendRawTransactionIntent `json:"ethSendRawTransactionIntent,omitempty"` - ETHSendTransactionIntent *ETHSendTransactionIntent `json:"ethSendTransactionIntent,omitempty"` - ETHSendTransactionIntentV2 *ETHSendTransactionIntentV2 `json:"ethSendTransactionIntentV2,omitempty"` - ETHUndelegate7702Intent *ETHUndelegate7702Intent `json:"ethUndelegate7702Intent,omitempty"` - ExecuteSwapIntent *ExecuteSwapIntent `json:"executeSwapIntent,omitempty"` - ExecuteSwapIntentV2 *ExecuteSwapIntentV2 `json:"executeSwapIntentV2,omitempty"` - ExportPrivateKeyIntent *ExportPrivateKeyIntent `json:"exportPrivateKeyIntent,omitempty"` - ExportSecretsIntent *ExportSecretsIntent `json:"exportSecretsIntent,omitempty"` - ExportWalletAccountIntent *ExportWalletAccountIntent `json:"exportWalletAccountIntent,omitempty"` - ExportWalletIntent *ExportWalletIntent `json:"exportWalletIntent,omitempty"` - ImportPrivateKeyIntent *ImportPrivateKeyIntent `json:"importPrivateKeyIntent,omitempty"` - ImportSecretsIntent *ImportSecretsIntent `json:"importSecretsIntent,omitempty"` - ImportWalletIntent *ImportWalletIntent `json:"importWalletIntent,omitempty"` - InitFiatOnRampIntent *InitFiatOnRampIntent `json:"initFiatOnRampIntent,omitempty"` - InitImportPrivateKeyIntent *InitImportPrivateKeyIntent `json:"initImportPrivateKeyIntent,omitempty"` - InitImportSecretsIntent *InitImportSecretsIntent `json:"initImportSecretsIntent,omitempty"` - InitImportWalletIntent *InitImportWalletIntent `json:"initImportWalletIntent,omitempty"` - InitOTPAuthIntent *InitOTPAuthIntent `json:"initOtpAuthIntent,omitempty"` - InitOTPAuthIntentV2 *InitOTPAuthIntentV2 `json:"initOtpAuthIntentV2,omitempty"` - InitOTPAuthIntentV3 *InitOTPAuthIntentV3 `json:"initOtpAuthIntentV3,omitempty"` - InitOTPIntent *InitOTPIntent `json:"initOtpIntent,omitempty"` - InitOTPIntentV2 *InitOTPIntentV2 `json:"initOtpIntentV2,omitempty"` - InitOTPIntentV3 *InitOTPIntentV3 `json:"initOtpIntentV3,omitempty"` - InitUserEmailRecoveryIntent *InitUserEmailRecoveryIntent `json:"initUserEmailRecoveryIntent,omitempty"` - InitUserEmailRecoveryIntentV2 *InitUserEmailRecoveryIntentV2 `json:"initUserEmailRecoveryIntentV2,omitempty"` - OAuth2AuthenticateIntent *OAuth2AuthenticateIntent `json:"oauth2AuthenticateIntent,omitempty"` - OAuthIntent *OAuthIntent `json:"oauthIntent,omitempty"` - OAuthLoginIntent *OAuthLoginIntent `json:"oauthLoginIntent,omitempty"` - OTPAuthIntent *OTPAuthIntent `json:"otpAuthIntent,omitempty"` - OTPLoginIntent *OTPLoginIntent `json:"otpLoginIntent,omitempty"` - OTPLoginIntentV2 *OTPLoginIntentV2 `json:"otpLoginIntentV2,omitempty"` - PostTVCQuorumKeyShareIntent *PostTVCQuorumKeyShareIntent `json:"postTvcQuorumKeyShareIntent,omitempty"` - ReEncryptTVCQuorumKeyShareIntent *ReEncryptTVCQuorumKeyShareIntent `json:"reEncryptTvcQuorumKeyShareIntent,omitempty"` - RecoverUserIntent *RecoverUserIntent `json:"recoverUserIntent,omitempty"` - RejectActivityIntent *RejectActivityIntent `json:"rejectActivityIntent,omitempty"` - RemoveIPAllowlistIntent *RemoveIPAllowlistIntent `json:"removeIpAllowlistIntent,omitempty"` - RemoveOrganizationFeatureIntent *RemoveOrganizationFeatureIntent `json:"removeOrganizationFeatureIntent,omitempty"` - RestoreTVCDeploymentIntent *RestoreTVCDeploymentIntent `json:"restoreTvcDeploymentIntent,omitempty"` - SetIPAllowlistIntent *SetIPAllowlistIntent `json:"setIpAllowlistIntent,omitempty"` - SetOrganizationFeatureIntent *SetOrganizationFeatureIntent `json:"setOrganizationFeatureIntent,omitempty"` - SetPaymentMethodIntent *BillingSetPaymentMethodIntent `json:"setPaymentMethodIntent,omitempty"` - SetPaymentMethodIntentV2 *BillingSetPaymentMethodIntentV2 `json:"setPaymentMethodIntentV2,omitempty"` - SignRawPayloadIntent *SignRawPayloadIntent `json:"signRawPayloadIntent,omitempty"` - SignRawPayloadIntentV2 *SignRawPayloadIntentV2 `json:"signRawPayloadIntentV2,omitempty"` - SignRawPayloadsIntent *SignRawPayloadsIntent `json:"signRawPayloadsIntent,omitempty"` - SignTransactionIntent *SignTransactionIntent `json:"signTransactionIntent,omitempty"` - SignTransactionIntentV2 *SignTransactionIntentV2 `json:"signTransactionIntentV2,omitempty"` - SolSendTransactionIntent *SolSendTransactionIntent `json:"solSendTransactionIntent,omitempty"` - SolSendTransactionIntentV2 *SolSendTransactionIntentV2 `json:"solSendTransactionIntentV2,omitempty"` - SparkClaimTransferIntent *SparkClaimTransferIntent `json:"sparkClaimTransferIntent,omitempty"` - SparkPrepareLightningReceiveIntent *SparkPrepareLightningReceiveIntent `json:"sparkPrepareLightningReceiveIntent,omitempty"` - SparkPrepareTransferIntent *SparkPrepareTransferIntent `json:"sparkPrepareTransferIntent,omitempty"` - SparkSignFrostIntent *SparkSignFrostIntent `json:"sparkSignFrostIntent,omitempty"` - StampLoginIntent *StampLoginIntent `json:"stampLoginIntent,omitempty"` - UpdateAllowedOriginsIntent *UpdateAllowedOriginsIntent `json:"updateAllowedOriginsIntent,omitempty"` - UpdateAuthProxyConfigIntent *UpdateAuthProxyConfigIntent `json:"updateAuthProxyConfigIntent,omitempty"` - UpdateFiatOnRampCredentialIntent *UpdateFiatOnRampCredentialIntent `json:"updateFiatOnRampCredentialIntent,omitempty"` - UpdateMfaPolicyIntent *UpdateMfaPolicyIntent `json:"updateMfaPolicyIntent,omitempty"` - UpdateOAuth2CredentialIntent *UpdateOAuth2CredentialIntent `json:"updateOauth2CredentialIntent,omitempty"` - UpdateOrganizationNameIntent *UpdateOrganizationNameIntent `json:"updateOrganizationNameIntent,omitempty"` - UpdatePolicyIntent *UpdatePolicyIntent `json:"updatePolicyIntent,omitempty"` - UpdatePolicyIntentV2 *UpdatePolicyIntentV2 `json:"updatePolicyIntentV2,omitempty"` - UpdatePrivateKeyTagIntent *UpdatePrivateKeyTagIntent `json:"updatePrivateKeyTagIntent,omitempty"` - UpdateRootQuorumIntent *UpdateRootQuorumIntent `json:"updateRootQuorumIntent,omitempty"` - UpdateTVCAppLiveDeploymentIntent *UpdateTVCAppLiveDeploymentIntent `json:"updateTvcAppLiveDeploymentIntent,omitempty"` - UpdateUserEmailIntent *UpdateUserEmailIntent `json:"updateUserEmailIntent,omitempty"` - UpdateUserIntent *UpdateUserIntent `json:"updateUserIntent,omitempty"` - UpdateUserNameIntent *UpdateUserNameIntent `json:"updateUserNameIntent,omitempty"` - UpdateUserPhoneNumberIntent *UpdateUserPhoneNumberIntent `json:"updateUserPhoneNumberIntent,omitempty"` - UpdateUserTagIntent *UpdateUserTagIntent `json:"updateUserTagIntent,omitempty"` - UpdateWalletAccountNameIntent *UpdateWalletAccountNameIntent `json:"updateWalletAccountNameIntent,omitempty"` - UpdateWalletIntent *UpdateWalletIntent `json:"updateWalletIntent,omitempty"` - UpdateWebhookEndpointIntent *UpdateWebhookEndpointIntent `json:"updateWebhookEndpointIntent,omitempty"` - UpsertGasUsageConfigIntent *UpsertGasUsageConfigIntent `json:"upsertGasUsageConfigIntent,omitempty"` - UpsertSwapConfigIntent *UpsertSwapConfigIntent `json:"upsertSwapConfigIntent,omitempty"` - VerifyOTPIntent *VerifyOTPIntent `json:"verifyOtpIntent,omitempty"` - VerifyOTPIntentV2 *VerifyOTPIntentV2 `json:"verifyOtpIntentV2,omitempty"` + AcceptInvitationIntent *AcceptInvitationIntent `json:"acceptInvitationIntent,omitempty"` + AcceptInvitationIntentV2 *AcceptInvitationIntentV2 `json:"acceptInvitationIntentV2,omitempty"` + ActivateBillingTierIntent *BillingActivateBillingTierIntent `json:"activateBillingTierIntent,omitempty"` + ApproveActivityIntent *ApproveActivityIntent `json:"approveActivityIntent,omitempty"` + ClaimEarnFeesIntent *ClaimEarnFeesIntent `json:"claimEarnFeesIntent,omitempty"` + ClaimSwapFeesIntent *ClaimSwapFeesIntent `json:"claimSwapFeesIntent,omitempty"` + CreateAPIKeysIntent *CreateAPIKeysIntent `json:"createApiKeysIntent,omitempty"` + CreateAPIKeysIntentV2 *CreateAPIKeysIntentV2 `json:"createApiKeysIntentV2,omitempty"` + CreateAPIOnlyUsersIntent *CreateAPIOnlyUsersIntent `json:"createApiOnlyUsersIntent,omitempty"` + CreateAuthenticatorsIntent *CreateAuthenticatorsIntent `json:"createAuthenticatorsIntent,omitempty"` + CreateAuthenticatorsIntentV2 *CreateAuthenticatorsIntentV2 `json:"createAuthenticatorsIntentV2,omitempty"` + CreateFiatOnRampCredentialIntent *CreateFiatOnRampCredentialIntent `json:"createFiatOnRampCredentialIntent,omitempty"` + CreateInvitationsIntent *CreateInvitationsIntent `json:"createInvitationsIntent,omitempty"` + CreateMfaPolicyIntent *CreateMfaPolicyIntent `json:"createMfaPolicyIntent,omitempty"` + CreateOAuth2CredentialIntent *CreateOAuth2CredentialIntent `json:"createOauth2CredentialIntent,omitempty"` + CreateOAuthProvidersIntent *CreateOAuthProvidersIntent `json:"createOauthProvidersIntent,omitempty"` + CreateOAuthProvidersIntentV2 *CreateOAuthProvidersIntentV2 `json:"createOauthProvidersIntentV2,omitempty"` + CreateOrganizationIntent *CreateOrganizationIntent `json:"createOrganizationIntent,omitempty"` + CreateOrganizationIntentV2 *CreateOrganizationIntentV2 `json:"createOrganizationIntentV2,omitempty"` + CreatePoliciesIntent *CreatePoliciesIntent `json:"createPoliciesIntent,omitempty"` + CreatePolicyIntent *CreatePolicyIntent `json:"createPolicyIntent,omitempty"` + CreatePolicyIntentV2 *CreatePolicyIntentV2 `json:"createPolicyIntentV2,omitempty"` + CreatePolicyIntentV3 *CreatePolicyIntentV3 `json:"createPolicyIntentV3,omitempty"` + CreatePrivateKeyTagIntent *CreatePrivateKeyTagIntent `json:"createPrivateKeyTagIntent,omitempty"` + CreatePrivateKeysIntent *CreatePrivateKeysIntent `json:"createPrivateKeysIntent,omitempty"` + CreatePrivateKeysIntentV2 *CreatePrivateKeysIntentV2 `json:"createPrivateKeysIntentV2,omitempty"` + CreateReadOnlySessionIntent *CreateReadOnlySessionIntent `json:"createReadOnlySessionIntent,omitempty"` + CreateReadWriteSessionIntent *CreateReadWriteSessionIntent `json:"createReadWriteSessionIntent,omitempty"` + CreateReadWriteSessionIntentV2 *CreateReadWriteSessionIntentV2 `json:"createReadWriteSessionIntentV2,omitempty"` + CreateSessionProfileIntent *CreateSessionProfileIntent `json:"createSessionProfileIntent,omitempty"` + CreateSmartContractInterfaceIntent *CreateSmartContractInterfaceIntent `json:"createSmartContractInterfaceIntent,omitempty"` + CreateSubOrganizationIntent *CreateSubOrganizationIntent `json:"createSubOrganizationIntent,omitempty"` + CreateSubOrganizationIntentV2 *CreateSubOrganizationIntentV2 `json:"createSubOrganizationIntentV2,omitempty"` + CreateSubOrganizationIntentV3 *CreateSubOrganizationIntentV3 `json:"createSubOrganizationIntentV3,omitempty"` + CreateSubOrganizationIntentV4 *CreateSubOrganizationIntentV4 `json:"createSubOrganizationIntentV4,omitempty"` + CreateSubOrganizationIntentV5 *CreateSubOrganizationIntentV5 `json:"createSubOrganizationIntentV5,omitempty"` + CreateSubOrganizationIntentV6 *CreateSubOrganizationIntentV6 `json:"createSubOrganizationIntentV6,omitempty"` + CreateSubOrganizationIntentV7 *CreateSubOrganizationIntentV7 `json:"createSubOrganizationIntentV7,omitempty"` + CreateSubOrganizationIntentV8 *CreateSubOrganizationIntentV8 `json:"createSubOrganizationIntentV8,omitempty"` + CreateSwapQuoteIntent *CreateSwapQuoteIntent `json:"createSwapQuoteIntent,omitempty"` + CreateSwapQuoteIntentV2 *CreateSwapQuoteIntentV2 `json:"createSwapQuoteIntentV2,omitempty"` + CreateSwapQuoteIntentV3 *CreateSwapQuoteIntentV3 `json:"createSwapQuoteIntentV3,omitempty"` + CreateTVCAppIntent *CreateTVCAppIntent `json:"createTvcAppIntent,omitempty"` + CreateTVCDeploymentIntent *CreateTVCDeploymentIntent `json:"createTvcDeploymentIntent,omitempty"` + CreateTVCManifestApprovalsIntent *CreateTVCManifestApprovalsIntent `json:"createTvcManifestApprovalsIntent,omitempty"` + CreateTVCOperatorIntent *CreateTVCOperatorIntent `json:"createTvcOperatorIntent,omitempty"` + CreateTVCQuorumKeyIntent *CreateTVCQuorumKeyIntent `json:"createTvcQuorumKeyIntent,omitempty"` + CreateUserTagIntent *CreateUserTagIntent `json:"createUserTagIntent,omitempty"` + CreateUsersIntent *CreateUsersIntent `json:"createUsersIntent,omitempty"` + CreateUsersIntentV2 *CreateUsersIntentV2 `json:"createUsersIntentV2,omitempty"` + CreateUsersIntentV3 *CreateUsersIntentV3 `json:"createUsersIntentV3,omitempty"` + CreateUsersIntentV4 *CreateUsersIntentV4 `json:"createUsersIntentV4,omitempty"` + CreateVelocityControlIntent *CreateVelocityControlIntent `json:"createVelocityControlIntent,omitempty"` + CreateWalletAccountsIntent *CreateWalletAccountsIntent `json:"createWalletAccountsIntent,omitempty"` + CreateWalletIntent *CreateWalletIntent `json:"createWalletIntent,omitempty"` + CreateWebhookEndpointIntent *CreateWebhookEndpointIntent `json:"createWebhookEndpointIntent,omitempty"` + DeleteAPIKeysIntent *DeleteAPIKeysIntent `json:"deleteApiKeysIntent,omitempty"` + DeleteAuthenticatorsIntent *DeleteAuthenticatorsIntent `json:"deleteAuthenticatorsIntent,omitempty"` + DeleteFiatOnRampCredentialIntent *DeleteFiatOnRampCredentialIntent `json:"deleteFiatOnRampCredentialIntent,omitempty"` + DeleteInvitationIntent *DeleteInvitationIntent `json:"deleteInvitationIntent,omitempty"` + DeleteMfaPolicyIntent *DeleteMfaPolicyIntent `json:"deleteMfaPolicyIntent,omitempty"` + DeleteOAuth2CredentialIntent *DeleteOAuth2CredentialIntent `json:"deleteOauth2CredentialIntent,omitempty"` + DeleteOAuthProvidersIntent *DeleteOAuthProvidersIntent `json:"deleteOauthProvidersIntent,omitempty"` + DeleteOrganizationIntent *DeleteOrganizationIntent `json:"deleteOrganizationIntent,omitempty"` + DeletePaymentMethodIntent *BillingDeletePaymentMethodIntent `json:"deletePaymentMethodIntent,omitempty"` + DeletePoliciesIntent *DeletePoliciesIntent `json:"deletePoliciesIntent,omitempty"` + DeletePolicyIntent *DeletePolicyIntent `json:"deletePolicyIntent,omitempty"` + DeletePrivateKeyTagsIntent *DeletePrivateKeyTagsIntent `json:"deletePrivateKeyTagsIntent,omitempty"` + DeletePrivateKeysIntent *DeletePrivateKeysIntent `json:"deletePrivateKeysIntent,omitempty"` + DeleteSecretsIntent *DeleteSecretsIntent `json:"deleteSecretsIntent,omitempty"` + DeleteSmartContractInterfaceIntent *DeleteSmartContractInterfaceIntent `json:"deleteSmartContractInterfaceIntent,omitempty"` + DeleteSubOrganizationIntent *DeleteSubOrganizationIntent `json:"deleteSubOrganizationIntent,omitempty"` + DeleteTVCAppAndDeploymentsIntent *DeleteTVCAppAndDeploymentsIntent `json:"deleteTvcAppAndDeploymentsIntent,omitempty"` + DeleteTVCDeploymentIntent *DeleteTVCDeploymentIntent `json:"deleteTvcDeploymentIntent,omitempty"` + DeleteUserTagsIntent *DeleteUserTagsIntent `json:"deleteUserTagsIntent,omitempty"` + DeleteUsersIntent *DeleteUsersIntent `json:"deleteUsersIntent,omitempty"` + DeleteVelocityControlsIntent *DeleteVelocityControlsIntent `json:"deleteVelocityControlsIntent,omitempty"` + DeleteWalletAccountsIntent *DeleteWalletAccountsIntent `json:"deleteWalletAccountsIntent,omitempty"` + DeleteWalletsIntent *DeleteWalletsIntent `json:"deleteWalletsIntent,omitempty"` + DeleteWebhookEndpointIntent *DeleteWebhookEndpointIntent `json:"deleteWebhookEndpointIntent,omitempty"` + DisableAuthProxyIntent *DisableAuthProxyIntent `json:"disableAuthProxyIntent,omitempty"` + DisablePrivateKeyIntent *DisablePrivateKeyIntent `json:"disablePrivateKeyIntent,omitempty"` + EarnClaimRewardsIntent *EarnClaimRewardsIntent `json:"earnClaimRewardsIntent,omitempty"` + EarnDeployWrapperIntent *EarnDeployWrapperIntent `json:"earnDeployWrapperIntent,omitempty"` + EarnDepositIntent *EarnDepositIntent `json:"earnDepositIntent,omitempty"` + EarnSetWrapperStateIntent *EarnSetWrapperStateIntent `json:"earnSetWrapperStateIntent,omitempty"` + EarnWithdrawIntent *EarnWithdrawIntent `json:"earnWithdrawIntent,omitempty"` + EmailAuthIntent *EmailAuthIntent `json:"emailAuthIntent,omitempty"` + EmailAuthIntentV2 *EmailAuthIntentV2 `json:"emailAuthIntentV2,omitempty"` + EmailAuthIntentV3 *EmailAuthIntentV3 `json:"emailAuthIntentV3,omitempty"` + EnableAuthProxyIntent *EnableAuthProxyIntent `json:"enableAuthProxyIntent,omitempty"` + ETHSendRawTransactionIntent *ETHSendRawTransactionIntent `json:"ethSendRawTransactionIntent,omitempty"` + ETHSendTransactionIntent *ETHSendTransactionIntent `json:"ethSendTransactionIntent,omitempty"` + ETHSendTransactionIntentV2 *ETHSendTransactionIntentV2 `json:"ethSendTransactionIntentV2,omitempty"` + ETHUndelegate7702Intent *ETHUndelegate7702Intent `json:"ethUndelegate7702Intent,omitempty"` + ExecuteSwapIntent *ExecuteSwapIntent `json:"executeSwapIntent,omitempty"` + ExecuteSwapIntentV2 *ExecuteSwapIntentV2 `json:"executeSwapIntentV2,omitempty"` + ExecuteSwapIntentV3 *ExecuteSwapIntentV3 `json:"executeSwapIntentV3,omitempty"` + ExportPrivateKeyIntent *ExportPrivateKeyIntent `json:"exportPrivateKeyIntent,omitempty"` + ExportSecretsIntent *ExportSecretsIntent `json:"exportSecretsIntent,omitempty"` + ExportWalletAccountIntent *ExportWalletAccountIntent `json:"exportWalletAccountIntent,omitempty"` + ExportWalletIntent *ExportWalletIntent `json:"exportWalletIntent,omitempty"` + ImportPrivateKeyIntent *ImportPrivateKeyIntent `json:"importPrivateKeyIntent,omitempty"` + ImportSecretsIntent *ImportSecretsIntent `json:"importSecretsIntent,omitempty"` + ImportWalletIntent *ImportWalletIntent `json:"importWalletIntent,omitempty"` + InitFiatOnRampIntent *InitFiatOnRampIntent `json:"initFiatOnRampIntent,omitempty"` + InitImportPrivateKeyIntent *InitImportPrivateKeyIntent `json:"initImportPrivateKeyIntent,omitempty"` + InitImportSecretsIntent *InitImportSecretsIntent `json:"initImportSecretsIntent,omitempty"` + InitImportWalletIntent *InitImportWalletIntent `json:"initImportWalletIntent,omitempty"` + InitOTPAuthIntent *InitOTPAuthIntent `json:"initOtpAuthIntent,omitempty"` + InitOTPAuthIntentV2 *InitOTPAuthIntentV2 `json:"initOtpAuthIntentV2,omitempty"` + InitOTPAuthIntentV3 *InitOTPAuthIntentV3 `json:"initOtpAuthIntentV3,omitempty"` + InitOTPIntent *InitOTPIntent `json:"initOtpIntent,omitempty"` + InitOTPIntentV2 *InitOTPIntentV2 `json:"initOtpIntentV2,omitempty"` + InitOTPIntentV3 *InitOTPIntentV3 `json:"initOtpIntentV3,omitempty"` + InitUserEmailRecoveryIntent *InitUserEmailRecoveryIntent `json:"initUserEmailRecoveryIntent,omitempty"` + InitUserEmailRecoveryIntentV2 *InitUserEmailRecoveryIntentV2 `json:"initUserEmailRecoveryIntentV2,omitempty"` + OAuth2AuthenticateIntent *OAuth2AuthenticateIntent `json:"oauth2AuthenticateIntent,omitempty"` + OAuthIntent *OAuthIntent `json:"oauthIntent,omitempty"` + OAuthLoginIntent *OAuthLoginIntent `json:"oauthLoginIntent,omitempty"` + OTPAuthIntent *OTPAuthIntent `json:"otpAuthIntent,omitempty"` + OTPLoginIntent *OTPLoginIntent `json:"otpLoginIntent,omitempty"` + OTPLoginIntentV2 *OTPLoginIntentV2 `json:"otpLoginIntentV2,omitempty"` + PostTVCQuorumKeyShareIntent *PostTVCQuorumKeyShareIntent `json:"postTvcQuorumKeyShareIntent,omitempty"` + ReEncryptTVCQuorumKeyShareIntent *ReEncryptTVCQuorumKeyShareIntent `json:"reEncryptTvcQuorumKeyShareIntent,omitempty"` + RecoverUserIntent *RecoverUserIntent `json:"recoverUserIntent,omitempty"` + RejectActivityIntent *RejectActivityIntent `json:"rejectActivityIntent,omitempty"` + RemoveIPAllowlistIntent *RemoveIPAllowlistIntent `json:"removeIpAllowlistIntent,omitempty"` + RemoveOrganizationFeatureIntent *RemoveOrganizationFeatureIntent `json:"removeOrganizationFeatureIntent,omitempty"` + RestoreTVCDeploymentIntent *RestoreTVCDeploymentIntent `json:"restoreTvcDeploymentIntent,omitempty"` + SetIPAllowlistIntent *SetIPAllowlistIntent `json:"setIpAllowlistIntent,omitempty"` + SetOrganizationFeatureIntent *SetOrganizationFeatureIntent `json:"setOrganizationFeatureIntent,omitempty"` + SetPaymentMethodIntent *BillingSetPaymentMethodIntent `json:"setPaymentMethodIntent,omitempty"` + SetPaymentMethodIntentV2 *BillingSetPaymentMethodIntentV2 `json:"setPaymentMethodIntentV2,omitempty"` + SignRawPayloadIntent *SignRawPayloadIntent `json:"signRawPayloadIntent,omitempty"` + SignRawPayloadIntentV2 *SignRawPayloadIntentV2 `json:"signRawPayloadIntentV2,omitempty"` + SignRawPayloadsIntent *SignRawPayloadsIntent `json:"signRawPayloadsIntent,omitempty"` + SignTransactionIntent *SignTransactionIntent `json:"signTransactionIntent,omitempty"` + SignTransactionIntentV2 *SignTransactionIntentV2 `json:"signTransactionIntentV2,omitempty"` + SolSendTransactionIntent *SolSendTransactionIntent `json:"solSendTransactionIntent,omitempty"` + SolSendTransactionIntentV2 *SolSendTransactionIntentV2 `json:"solSendTransactionIntentV2,omitempty"` + SparkClaimTransferIntent *SparkClaimTransferIntent `json:"sparkClaimTransferIntent,omitempty"` + SparkPrepareLightningReceiveIntent *SparkPrepareLightningReceiveIntent `json:"sparkPrepareLightningReceiveIntent,omitempty"` + SparkPrepareTransferIntent *SparkPrepareTransferIntent `json:"sparkPrepareTransferIntent,omitempty"` + SparkSignFrostIntent *SparkSignFrostIntent `json:"sparkSignFrostIntent,omitempty"` + StampLoginIntent *StampLoginIntent `json:"stampLoginIntent,omitempty"` + UpdateAllowedOriginsIntent *UpdateAllowedOriginsIntent `json:"updateAllowedOriginsIntent,omitempty"` + UpdateAuthProxyConfigIntent *UpdateAuthProxyConfigIntent `json:"updateAuthProxyConfigIntent,omitempty"` + UpdateFiatOnRampCredentialIntent *UpdateFiatOnRampCredentialIntent `json:"updateFiatOnRampCredentialIntent,omitempty"` + UpdateMfaPolicyIntent *UpdateMfaPolicyIntent `json:"updateMfaPolicyIntent,omitempty"` + UpdateOAuth2CredentialIntent *UpdateOAuth2CredentialIntent `json:"updateOauth2CredentialIntent,omitempty"` + UpdateOrganizationNameIntent *UpdateOrganizationNameIntent `json:"updateOrganizationNameIntent,omitempty"` + UpdatePaymentMethodIntent *BillingUpdatePaymentMethodIntent `json:"updatePaymentMethodIntent,omitempty"` + UpdatePolicyIntent *UpdatePolicyIntent `json:"updatePolicyIntent,omitempty"` + UpdatePolicyIntentV2 *UpdatePolicyIntentV2 `json:"updatePolicyIntentV2,omitempty"` + UpdatePrivateKeyTagIntent *UpdatePrivateKeyTagIntent `json:"updatePrivateKeyTagIntent,omitempty"` + UpdateRootQuorumIntent *UpdateRootQuorumIntent `json:"updateRootQuorumIntent,omitempty"` + UpdateTVCAppLiveDeploymentIntent *UpdateTVCAppLiveDeploymentIntent `json:"updateTvcAppLiveDeploymentIntent,omitempty"` + UpdateUserEmailIntent *UpdateUserEmailIntent `json:"updateUserEmailIntent,omitempty"` + UpdateUserIntent *UpdateUserIntent `json:"updateUserIntent,omitempty"` + UpdateUserNameIntent *UpdateUserNameIntent `json:"updateUserNameIntent,omitempty"` + UpdateUserPhoneNumberIntent *UpdateUserPhoneNumberIntent `json:"updateUserPhoneNumberIntent,omitempty"` + UpdateUserTagIntent *UpdateUserTagIntent `json:"updateUserTagIntent,omitempty"` + UpdateWalletAccountNameIntent *UpdateWalletAccountNameIntent `json:"updateWalletAccountNameIntent,omitempty"` + UpdateWalletIntent *UpdateWalletIntent `json:"updateWalletIntent,omitempty"` + UpdateWebhookEndpointIntent *UpdateWebhookEndpointIntent `json:"updateWebhookEndpointIntent,omitempty"` + UpsertGasUsageConfigIntent *UpsertGasUsageConfigIntent `json:"upsertGasUsageConfigIntent,omitempty"` + UpsertSwapConfigIntent *UpsertSwapConfigIntent `json:"upsertSwapConfigIntent,omitempty"` + UpsertSwapFeeSponsorshipLimitConfigIntent *UpsertSwapFeeSponsorshipLimitConfigIntent `json:"upsertSwapFeeSponsorshipLimitConfigIntent,omitempty"` + UpsertSwapFixedRateLimitConfigIntent *UpsertSwapFixedRateLimitConfigIntent `json:"upsertSwapFixedRateLimitConfigIntent,omitempty"` + VerifyOTPIntent *VerifyOTPIntent `json:"verifyOtpIntent,omitempty"` + VerifyOTPIntentV2 *VerifyOTPIntentV2 `json:"verifyOtpIntentV2,omitempty"` } type InvitationParams struct { @@ -4020,6 +4319,20 @@ type ListEarnPositionsResponse struct { Positions []EarnPosition `json:"positions,omitempty"` } +type ListEarnRewardsRequest struct { + // Optional filter: only return rewards on this chain (e.g. 'eip155:8453'). When unset, every chain the organization has deployed Earn wrappers on is queried. + Caip2 *string `json:"caip2,omitempty"` + // Unique identifier for a given Organization. + OrganizationID string `json:"organizationId"` + // The wallet address to return rewards for. + WalletAddress string `json:"walletAddress"` +} + +type ListEarnRewardsResponse struct { + // The wallet's rewards, one entry per (chain, reward token), sorted by chain then token. Entries where every amount is zero are omitted. + Rewards []EarnReward `json:"rewards,omitempty"` +} + type ListEarnVaultsRequest struct { // CAIP-19 asset ID (e.g. 'eip155:8453/erc20:0x833589...') to return vaults for. Only vaults whose underlying asset matches are returned; the chain is taken from the CAIP-19 identifier. Caip19 string `json:"caip19"` @@ -4150,16 +4463,6 @@ type ListUserTagsResponse struct { UserTags []DataV1Tag `json:"userTags"` } -type ListVelocityControlsRequest struct { - OrganizationID string `json:"organizationId"` - PaginationOptions *Pagination `json:"paginationOptions,omitempty"` -} - -type ListVelocityControlsResponse struct { - PageInfo PageInfo `json:"pageInfo"` - VelocityControls []VelocityControl `json:"velocityControls"` -} - type ListWebhookEndpointsRequest struct { // Unique identifier for a given Organization. OrganizationID string `json:"organizationId"` @@ -4642,147 +4945,153 @@ type RestoreTVCDeploymentResult struct { } type Result struct { - AcceptInvitationResult *AcceptInvitationResult `json:"acceptInvitationResult,omitempty"` - ActivateBillingTierResult *BillingActivateBillingTierResult `json:"activateBillingTierResult,omitempty"` - ClaimEarnFeesResult *ClaimEarnFeesResult `json:"claimEarnFeesResult,omitempty"` - ClaimSwapFeesResult *ClaimSwapFeesResult `json:"claimSwapFeesResult,omitempty"` - CreateAPIKeysResult *CreateAPIKeysResult `json:"createApiKeysResult,omitempty"` - CreateAPIOnlyUsersResult *CreateAPIOnlyUsersResult `json:"createApiOnlyUsersResult,omitempty"` - CreateAuthenticatorsResult *CreateAuthenticatorsResult `json:"createAuthenticatorsResult,omitempty"` - CreateFiatOnRampCredentialResult *CreateFiatOnRampCredentialResult `json:"createFiatOnRampCredentialResult,omitempty"` - CreateInvitationsResult *CreateInvitationsResult `json:"createInvitationsResult,omitempty"` - CreateMfaPolicyResult *CreateMfaPolicyResult `json:"createMfaPolicyResult,omitempty"` - CreateOAuth2CredentialResult *CreateOAuth2CredentialResult `json:"createOauth2CredentialResult,omitempty"` - CreateOAuthProvidersResult *CreateOAuthProvidersResult `json:"createOauthProvidersResult,omitempty"` - CreateOAuthProvidersResultV2 *CreateOAuthProvidersResultV2 `json:"createOauthProvidersResultV2,omitempty"` - CreateOrganizationResult *CreateOrganizationResult `json:"createOrganizationResult,omitempty"` - CreatePoliciesResult *CreatePoliciesResult `json:"createPoliciesResult,omitempty"` - CreatePolicyResult *CreatePolicyResult `json:"createPolicyResult,omitempty"` - CreatePrivateKeyTagResult *CreatePrivateKeyTagResult `json:"createPrivateKeyTagResult,omitempty"` - CreatePrivateKeysResult *CreatePrivateKeysResult `json:"createPrivateKeysResult,omitempty"` - CreatePrivateKeysResultV2 *CreatePrivateKeysResultV2 `json:"createPrivateKeysResultV2,omitempty"` - CreateReadOnlySessionResult *CreateReadOnlySessionResult `json:"createReadOnlySessionResult,omitempty"` - CreateReadWriteSessionResult *CreateReadWriteSessionResult `json:"createReadWriteSessionResult,omitempty"` - CreateReadWriteSessionResultV2 *CreateReadWriteSessionResultV2 `json:"createReadWriteSessionResultV2,omitempty"` - CreateSessionProfileResult *CreateSessionProfileResult `json:"createSessionProfileResult,omitempty"` - CreateSmartContractInterfaceResult *CreateSmartContractInterfaceResult `json:"createSmartContractInterfaceResult,omitempty"` - CreateSubOrganizationResult *CreateSubOrganizationResult `json:"createSubOrganizationResult,omitempty"` - CreateSubOrganizationResultV3 *CreateSubOrganizationResultV3 `json:"createSubOrganizationResultV3,omitempty"` - CreateSubOrganizationResultV4 *CreateSubOrganizationResultV4 `json:"createSubOrganizationResultV4,omitempty"` - CreateSubOrganizationResultV5 *CreateSubOrganizationResultV5 `json:"createSubOrganizationResultV5,omitempty"` - CreateSubOrganizationResultV6 *CreateSubOrganizationResultV6 `json:"createSubOrganizationResultV6,omitempty"` - CreateSubOrganizationResultV7 *CreateSubOrganizationResultV7 `json:"createSubOrganizationResultV7,omitempty"` - CreateSubOrganizationResultV8 *CreateSubOrganizationResultV8 `json:"createSubOrganizationResultV8,omitempty"` - CreateSwapQuoteResult *CreateSwapQuoteResult `json:"createSwapQuoteResult,omitempty"` - CreateTVCAppResult *CreateTVCAppResult `json:"createTvcAppResult,omitempty"` - CreateTVCDeploymentResult *CreateTVCDeploymentResult `json:"createTvcDeploymentResult,omitempty"` - CreateTVCManifestApprovalsResult *CreateTVCManifestApprovalsResult `json:"createTvcManifestApprovalsResult,omitempty"` - CreateTVCOperatorResult *CreateTVCOperatorResult `json:"createTvcOperatorResult,omitempty"` - CreateTVCQuorumKeyResult *CreateTVCQuorumKeyResult `json:"createTvcQuorumKeyResult,omitempty"` - CreateUserTagResult *CreateUserTagResult `json:"createUserTagResult,omitempty"` - CreateUsersResult *CreateUsersResult `json:"createUsersResult,omitempty"` - CreateVelocityControlResult *CreateVelocityControlResult `json:"createVelocityControlResult,omitempty"` - CreateWalletAccountsResult *CreateWalletAccountsResult `json:"createWalletAccountsResult,omitempty"` - CreateWalletResult *CreateWalletResult `json:"createWalletResult,omitempty"` - CreateWebhookEndpointResult *CreateWebhookEndpointResult `json:"createWebhookEndpointResult,omitempty"` - DeleteAPIKeysResult *DeleteAPIKeysResult `json:"deleteApiKeysResult,omitempty"` - DeleteAuthenticatorsResult *DeleteAuthenticatorsResult `json:"deleteAuthenticatorsResult,omitempty"` - DeleteFiatOnRampCredentialResult *DeleteFiatOnRampCredentialResult `json:"deleteFiatOnRampCredentialResult,omitempty"` - DeleteInvitationResult *DeleteInvitationResult `json:"deleteInvitationResult,omitempty"` - DeleteMfaPolicyResult *DeleteMfaPolicyResult `json:"deleteMfaPolicyResult,omitempty"` - DeleteOAuth2CredentialResult *DeleteOAuth2CredentialResult `json:"deleteOauth2CredentialResult,omitempty"` - DeleteOAuthProvidersResult *DeleteOAuthProvidersResult `json:"deleteOauthProvidersResult,omitempty"` - DeleteOrganizationResult *DeleteOrganizationResult `json:"deleteOrganizationResult,omitempty"` - DeletePaymentMethodResult *BillingDeletePaymentMethodResult `json:"deletePaymentMethodResult,omitempty"` - DeletePoliciesResult *DeletePoliciesResult `json:"deletePoliciesResult,omitempty"` - DeletePolicyResult *DeletePolicyResult `json:"deletePolicyResult,omitempty"` - DeletePrivateKeyTagsResult *DeletePrivateKeyTagsResult `json:"deletePrivateKeyTagsResult,omitempty"` - DeletePrivateKeysResult *DeletePrivateKeysResult `json:"deletePrivateKeysResult,omitempty"` - DeleteSmartContractInterfaceResult *DeleteSmartContractInterfaceResult `json:"deleteSmartContractInterfaceResult,omitempty"` - DeleteSubOrganizationResult *DeleteSubOrganizationResult `json:"deleteSubOrganizationResult,omitempty"` - DeleteTVCAppAndDeploymentsResult *DeleteTVCAppAndDeploymentsResult `json:"deleteTvcAppAndDeploymentsResult,omitempty"` - DeleteTVCDeploymentResult *DeleteTVCDeploymentResult `json:"deleteTvcDeploymentResult,omitempty"` - DeleteUserTagsResult *DeleteUserTagsResult `json:"deleteUserTagsResult,omitempty"` - DeleteUsersResult *DeleteUsersResult `json:"deleteUsersResult,omitempty"` - DeleteVelocityControlResult *DeleteVelocityControlResult `json:"deleteVelocityControlResult,omitempty"` - DeleteWalletAccountsResult *DeleteWalletAccountsResult `json:"deleteWalletAccountsResult,omitempty"` - DeleteWalletsResult *DeleteWalletsResult `json:"deleteWalletsResult,omitempty"` - DeleteWebhookEndpointResult *DeleteWebhookEndpointResult `json:"deleteWebhookEndpointResult,omitempty"` - DisableAuthProxyResult *DisableAuthProxyResult `json:"disableAuthProxyResult,omitempty"` - DisablePrivateKeyResult *DisablePrivateKeyResult `json:"disablePrivateKeyResult,omitempty"` - EarnDeployWrapperResult *EarnDeployWrapperResult `json:"earnDeployWrapperResult,omitempty"` - EarnDepositResult *EarnDepositResult `json:"earnDepositResult,omitempty"` - EarnSetWrapperStateResult *EarnSetWrapperStateResult `json:"earnSetWrapperStateResult,omitempty"` - EarnWithdrawResult *EarnWithdrawResult `json:"earnWithdrawResult,omitempty"` - EmailAuthResult *EmailAuthResult `json:"emailAuthResult,omitempty"` - EnableAuthProxyResult *EnableAuthProxyResult `json:"enableAuthProxyResult,omitempty"` - ETHSendRawTransactionResult *ETHSendRawTransactionResult `json:"ethSendRawTransactionResult,omitempty"` - ETHSendTransactionResult *ETHSendTransactionResult `json:"ethSendTransactionResult,omitempty"` - ETHSendTransactionResultV2 *ETHSendTransactionResultV2 `json:"ethSendTransactionResultV2,omitempty"` - ETHUndelegate7702Result *ETHUndelegate7702Result `json:"ethUndelegate7702Result,omitempty"` - ExecuteSwapResult *ExecuteSwapResult `json:"executeSwapResult,omitempty"` - ExportPrivateKeyResult *ExportPrivateKeyResult `json:"exportPrivateKeyResult,omitempty"` - ExportSecretsResult *ExportSecretsResult `json:"exportSecretsResult,omitempty"` - ExportWalletAccountResult *ExportWalletAccountResult `json:"exportWalletAccountResult,omitempty"` - ExportWalletResult *ExportWalletResult `json:"exportWalletResult,omitempty"` - ImportPrivateKeyResult *ImportPrivateKeyResult `json:"importPrivateKeyResult,omitempty"` - ImportSecretsResult *ImportSecretsResult `json:"importSecretsResult,omitempty"` - ImportWalletResult *ImportWalletResult `json:"importWalletResult,omitempty"` - InitFiatOnRampResult *InitFiatOnRampResult `json:"initFiatOnRampResult,omitempty"` - InitImportPrivateKeyResult *InitImportPrivateKeyResult `json:"initImportPrivateKeyResult,omitempty"` - InitImportSecretsResult *InitImportSecretsResult `json:"initImportSecretsResult,omitempty"` - InitImportWalletResult *InitImportWalletResult `json:"initImportWalletResult,omitempty"` - InitOTPAuthResult *InitOTPAuthResult `json:"initOtpAuthResult,omitempty"` - InitOTPAuthResultV2 *InitOTPAuthResultV2 `json:"initOtpAuthResultV2,omitempty"` - InitOTPResult *InitOTPResult `json:"initOtpResult,omitempty"` - InitOTPResultV2 *InitOTPResultV2 `json:"initOtpResultV2,omitempty"` - InitUserEmailRecoveryResult *InitUserEmailRecoveryResult `json:"initUserEmailRecoveryResult,omitempty"` - OAuth2AuthenticateResult *OAuth2AuthenticateResult `json:"oauth2AuthenticateResult,omitempty"` - OAuthLoginResult *OAuthLoginResult `json:"oauthLoginResult,omitempty"` - OAuthResult *OAuthResult `json:"oauthResult,omitempty"` - OTPAuthResult *OTPAuthResult `json:"otpAuthResult,omitempty"` - OTPLoginResult *OTPLoginResult `json:"otpLoginResult,omitempty"` - PostTVCQuorumKeyShareResult *PostTVCQuorumKeyShareResult `json:"postTvcQuorumKeyShareResult,omitempty"` - ReEncryptTVCQuorumKeyShareResult *ReEncryptTVCQuorumKeyShareResult `json:"reEncryptTvcQuorumKeyShareResult,omitempty"` - RecoverUserResult *RecoverUserResult `json:"recoverUserResult,omitempty"` - RemoveIPAllowlistResult *RemoveIPAllowlistResult `json:"removeIpAllowlistResult,omitempty"` - RemoveOrganizationFeatureResult *RemoveOrganizationFeatureResult `json:"removeOrganizationFeatureResult,omitempty"` - RestoreTVCDeploymentResult *RestoreTVCDeploymentResult `json:"restoreTvcDeploymentResult,omitempty"` - SetIPAllowlistResult *SetIPAllowlistResult `json:"setIpAllowlistResult,omitempty"` - SetOrganizationFeatureResult *SetOrganizationFeatureResult `json:"setOrganizationFeatureResult,omitempty"` - SetPaymentMethodResult *BillingSetPaymentMethodResult `json:"setPaymentMethodResult,omitempty"` - SignRawPayloadResult *SignRawPayloadResult `json:"signRawPayloadResult,omitempty"` - SignRawPayloadsResult *SignRawPayloadsResult `json:"signRawPayloadsResult,omitempty"` - SignTransactionResult *SignTransactionResult `json:"signTransactionResult,omitempty"` - SolSendTransactionResult *SolSendTransactionResult `json:"solSendTransactionResult,omitempty"` - SolSendTransactionResultV2 *SolSendTransactionResultV2 `json:"solSendTransactionResultV2,omitempty"` - SparkClaimTransferResult *SparkClaimTransferResult `json:"sparkClaimTransferResult,omitempty"` - SparkPrepareLightningReceiveResult *SparkPrepareLightningReceiveResult `json:"sparkPrepareLightningReceiveResult,omitempty"` - SparkPrepareTransferResult *SparkPrepareTransferResult `json:"sparkPrepareTransferResult,omitempty"` - SparkSignFrostResult *SparkSignFrostResult `json:"sparkSignFrostResult,omitempty"` - StampLoginResult *StampLoginResult `json:"stampLoginResult,omitempty"` - UpdateAllowedOriginsResult *UpdateAllowedOriginsResult `json:"updateAllowedOriginsResult,omitempty"` - UpdateAuthProxyConfigResult *UpdateAuthProxyConfigResult `json:"updateAuthProxyConfigResult,omitempty"` - UpdateFiatOnRampCredentialResult *UpdateFiatOnRampCredentialResult `json:"updateFiatOnRampCredentialResult,omitempty"` - UpdateMfaPolicyResult *UpdateMfaPolicyResult `json:"updateMfaPolicyResult,omitempty"` - UpdateOAuth2CredentialResult *UpdateOAuth2CredentialResult `json:"updateOauth2CredentialResult,omitempty"` - UpdateOrganizationNameResult *UpdateOrganizationNameResult `json:"updateOrganizationNameResult,omitempty"` - UpdatePolicyResult *UpdatePolicyResult `json:"updatePolicyResult,omitempty"` - UpdatePolicyResultV2 *UpdatePolicyResultV2 `json:"updatePolicyResultV2,omitempty"` - UpdatePrivateKeyTagResult *UpdatePrivateKeyTagResult `json:"updatePrivateKeyTagResult,omitempty"` - UpdateRootQuorumResult *UpdateRootQuorumResult `json:"updateRootQuorumResult,omitempty"` - UpdateTVCAppLiveDeploymentResult *UpdateTVCAppLiveDeploymentResult `json:"updateTvcAppLiveDeploymentResult,omitempty"` - UpdateUserEmailResult *UpdateUserEmailResult `json:"updateUserEmailResult,omitempty"` - UpdateUserNameResult *UpdateUserNameResult `json:"updateUserNameResult,omitempty"` - UpdateUserPhoneNumberResult *UpdateUserPhoneNumberResult `json:"updateUserPhoneNumberResult,omitempty"` - UpdateUserResult *UpdateUserResult `json:"updateUserResult,omitempty"` - UpdateUserTagResult *UpdateUserTagResult `json:"updateUserTagResult,omitempty"` - UpdateWalletAccountNameResult *UpdateWalletAccountNameResult `json:"updateWalletAccountNameResult,omitempty"` - UpdateWalletResult *UpdateWalletResult `json:"updateWalletResult,omitempty"` - UpdateWebhookEndpointResult *UpdateWebhookEndpointResult `json:"updateWebhookEndpointResult,omitempty"` - UpsertGasUsageConfigResult *UpsertGasUsageConfigResult `json:"upsertGasUsageConfigResult,omitempty"` - UpsertSwapConfigResult *UpsertSwapConfigResult `json:"upsertSwapConfigResult,omitempty"` - VerifyOTPResult *VerifyOTPResult `json:"verifyOtpResult,omitempty"` + AcceptInvitationResult *AcceptInvitationResult `json:"acceptInvitationResult,omitempty"` + ActivateBillingTierResult *BillingActivateBillingTierResult `json:"activateBillingTierResult,omitempty"` + ClaimEarnFeesResult *ClaimEarnFeesResult `json:"claimEarnFeesResult,omitempty"` + ClaimSwapFeesResult *ClaimSwapFeesResult `json:"claimSwapFeesResult,omitempty"` + CreateAPIKeysResult *CreateAPIKeysResult `json:"createApiKeysResult,omitempty"` + CreateAPIOnlyUsersResult *CreateAPIOnlyUsersResult `json:"createApiOnlyUsersResult,omitempty"` + CreateAuthenticatorsResult *CreateAuthenticatorsResult `json:"createAuthenticatorsResult,omitempty"` + CreateFiatOnRampCredentialResult *CreateFiatOnRampCredentialResult `json:"createFiatOnRampCredentialResult,omitempty"` + CreateInvitationsResult *CreateInvitationsResult `json:"createInvitationsResult,omitempty"` + CreateMfaPolicyResult *CreateMfaPolicyResult `json:"createMfaPolicyResult,omitempty"` + CreateOAuth2CredentialResult *CreateOAuth2CredentialResult `json:"createOauth2CredentialResult,omitempty"` + CreateOAuthProvidersResult *CreateOAuthProvidersResult `json:"createOauthProvidersResult,omitempty"` + CreateOAuthProvidersResultV2 *CreateOAuthProvidersResultV2 `json:"createOauthProvidersResultV2,omitempty"` + CreateOrganizationResult *CreateOrganizationResult `json:"createOrganizationResult,omitempty"` + CreatePoliciesResult *CreatePoliciesResult `json:"createPoliciesResult,omitempty"` + CreatePolicyResult *CreatePolicyResult `json:"createPolicyResult,omitempty"` + CreatePrivateKeyTagResult *CreatePrivateKeyTagResult `json:"createPrivateKeyTagResult,omitempty"` + CreatePrivateKeysResult *CreatePrivateKeysResult `json:"createPrivateKeysResult,omitempty"` + CreatePrivateKeysResultV2 *CreatePrivateKeysResultV2 `json:"createPrivateKeysResultV2,omitempty"` + CreateReadOnlySessionResult *CreateReadOnlySessionResult `json:"createReadOnlySessionResult,omitempty"` + CreateReadWriteSessionResult *CreateReadWriteSessionResult `json:"createReadWriteSessionResult,omitempty"` + CreateReadWriteSessionResultV2 *CreateReadWriteSessionResultV2 `json:"createReadWriteSessionResultV2,omitempty"` + CreateSessionProfileResult *CreateSessionProfileResult `json:"createSessionProfileResult,omitempty"` + CreateSmartContractInterfaceResult *CreateSmartContractInterfaceResult `json:"createSmartContractInterfaceResult,omitempty"` + CreateSubOrganizationResult *CreateSubOrganizationResult `json:"createSubOrganizationResult,omitempty"` + CreateSubOrganizationResultV3 *CreateSubOrganizationResultV3 `json:"createSubOrganizationResultV3,omitempty"` + CreateSubOrganizationResultV4 *CreateSubOrganizationResultV4 `json:"createSubOrganizationResultV4,omitempty"` + CreateSubOrganizationResultV5 *CreateSubOrganizationResultV5 `json:"createSubOrganizationResultV5,omitempty"` + CreateSubOrganizationResultV6 *CreateSubOrganizationResultV6 `json:"createSubOrganizationResultV6,omitempty"` + CreateSubOrganizationResultV7 *CreateSubOrganizationResultV7 `json:"createSubOrganizationResultV7,omitempty"` + CreateSubOrganizationResultV8 *CreateSubOrganizationResultV8 `json:"createSubOrganizationResultV8,omitempty"` + CreateSwapQuoteResult *CreateSwapQuoteResult `json:"createSwapQuoteResult,omitempty"` + CreateSwapQuoteResultV2 *CreateSwapQuoteResultV2 `json:"createSwapQuoteResultV2,omitempty"` + CreateTVCAppResult *CreateTVCAppResult `json:"createTvcAppResult,omitempty"` + CreateTVCDeploymentResult *CreateTVCDeploymentResult `json:"createTvcDeploymentResult,omitempty"` + CreateTVCManifestApprovalsResult *CreateTVCManifestApprovalsResult `json:"createTvcManifestApprovalsResult,omitempty"` + CreateTVCOperatorResult *CreateTVCOperatorResult `json:"createTvcOperatorResult,omitempty"` + CreateTVCQuorumKeyResult *CreateTVCQuorumKeyResult `json:"createTvcQuorumKeyResult,omitempty"` + CreateUserTagResult *CreateUserTagResult `json:"createUserTagResult,omitempty"` + CreateUsersResult *CreateUsersResult `json:"createUsersResult,omitempty"` + CreateVelocityControlResult *CreateVelocityControlResult `json:"createVelocityControlResult,omitempty"` + CreateWalletAccountsResult *CreateWalletAccountsResult `json:"createWalletAccountsResult,omitempty"` + CreateWalletResult *CreateWalletResult `json:"createWalletResult,omitempty"` + CreateWebhookEndpointResult *CreateWebhookEndpointResult `json:"createWebhookEndpointResult,omitempty"` + DeleteAPIKeysResult *DeleteAPIKeysResult `json:"deleteApiKeysResult,omitempty"` + DeleteAuthenticatorsResult *DeleteAuthenticatorsResult `json:"deleteAuthenticatorsResult,omitempty"` + DeleteFiatOnRampCredentialResult *DeleteFiatOnRampCredentialResult `json:"deleteFiatOnRampCredentialResult,omitempty"` + DeleteInvitationResult *DeleteInvitationResult `json:"deleteInvitationResult,omitempty"` + DeleteMfaPolicyResult *DeleteMfaPolicyResult `json:"deleteMfaPolicyResult,omitempty"` + DeleteOAuth2CredentialResult *DeleteOAuth2CredentialResult `json:"deleteOauth2CredentialResult,omitempty"` + DeleteOAuthProvidersResult *DeleteOAuthProvidersResult `json:"deleteOauthProvidersResult,omitempty"` + DeleteOrganizationResult *DeleteOrganizationResult `json:"deleteOrganizationResult,omitempty"` + DeletePaymentMethodResult *BillingDeletePaymentMethodResult `json:"deletePaymentMethodResult,omitempty"` + DeletePoliciesResult *DeletePoliciesResult `json:"deletePoliciesResult,omitempty"` + DeletePolicyResult *DeletePolicyResult `json:"deletePolicyResult,omitempty"` + DeletePrivateKeyTagsResult *DeletePrivateKeyTagsResult `json:"deletePrivateKeyTagsResult,omitempty"` + DeletePrivateKeysResult *DeletePrivateKeysResult `json:"deletePrivateKeysResult,omitempty"` + DeleteSecretsResult *DeleteSecretsResult `json:"deleteSecretsResult,omitempty"` + DeleteSmartContractInterfaceResult *DeleteSmartContractInterfaceResult `json:"deleteSmartContractInterfaceResult,omitempty"` + DeleteSubOrganizationResult *DeleteSubOrganizationResult `json:"deleteSubOrganizationResult,omitempty"` + DeleteTVCAppAndDeploymentsResult *DeleteTVCAppAndDeploymentsResult `json:"deleteTvcAppAndDeploymentsResult,omitempty"` + DeleteTVCDeploymentResult *DeleteTVCDeploymentResult `json:"deleteTvcDeploymentResult,omitempty"` + DeleteUserTagsResult *DeleteUserTagsResult `json:"deleteUserTagsResult,omitempty"` + DeleteUsersResult *DeleteUsersResult `json:"deleteUsersResult,omitempty"` + DeleteVelocityControlsResult *DeleteVelocityControlsResult `json:"deleteVelocityControlsResult,omitempty"` + DeleteWalletAccountsResult *DeleteWalletAccountsResult `json:"deleteWalletAccountsResult,omitempty"` + DeleteWalletsResult *DeleteWalletsResult `json:"deleteWalletsResult,omitempty"` + DeleteWebhookEndpointResult *DeleteWebhookEndpointResult `json:"deleteWebhookEndpointResult,omitempty"` + DisableAuthProxyResult *DisableAuthProxyResult `json:"disableAuthProxyResult,omitempty"` + DisablePrivateKeyResult *DisablePrivateKeyResult `json:"disablePrivateKeyResult,omitempty"` + EarnClaimRewardsResult *EarnClaimRewardsResult `json:"earnClaimRewardsResult,omitempty"` + EarnDeployWrapperResult *EarnDeployWrapperResult `json:"earnDeployWrapperResult,omitempty"` + EarnDepositResult *EarnDepositResult `json:"earnDepositResult,omitempty"` + EarnSetWrapperStateResult *EarnSetWrapperStateResult `json:"earnSetWrapperStateResult,omitempty"` + EarnWithdrawResult *EarnWithdrawResult `json:"earnWithdrawResult,omitempty"` + EmailAuthResult *EmailAuthResult `json:"emailAuthResult,omitempty"` + EnableAuthProxyResult *EnableAuthProxyResult `json:"enableAuthProxyResult,omitempty"` + ETHSendRawTransactionResult *ETHSendRawTransactionResult `json:"ethSendRawTransactionResult,omitempty"` + ETHSendTransactionResult *ETHSendTransactionResult `json:"ethSendTransactionResult,omitempty"` + ETHSendTransactionResultV2 *ETHSendTransactionResultV2 `json:"ethSendTransactionResultV2,omitempty"` + ETHUndelegate7702Result *ETHUndelegate7702Result `json:"ethUndelegate7702Result,omitempty"` + ExecuteSwapResult *ExecuteSwapResult `json:"executeSwapResult,omitempty"` + ExportPrivateKeyResult *ExportPrivateKeyResult `json:"exportPrivateKeyResult,omitempty"` + ExportSecretsResult *ExportSecretsResult `json:"exportSecretsResult,omitempty"` + ExportWalletAccountResult *ExportWalletAccountResult `json:"exportWalletAccountResult,omitempty"` + ExportWalletResult *ExportWalletResult `json:"exportWalletResult,omitempty"` + ImportPrivateKeyResult *ImportPrivateKeyResult `json:"importPrivateKeyResult,omitempty"` + ImportSecretsResult *ImportSecretsResult `json:"importSecretsResult,omitempty"` + ImportWalletResult *ImportWalletResult `json:"importWalletResult,omitempty"` + InitFiatOnRampResult *InitFiatOnRampResult `json:"initFiatOnRampResult,omitempty"` + InitImportPrivateKeyResult *InitImportPrivateKeyResult `json:"initImportPrivateKeyResult,omitempty"` + InitImportSecretsResult *InitImportSecretsResult `json:"initImportSecretsResult,omitempty"` + InitImportWalletResult *InitImportWalletResult `json:"initImportWalletResult,omitempty"` + InitOTPAuthResult *InitOTPAuthResult `json:"initOtpAuthResult,omitempty"` + InitOTPAuthResultV2 *InitOTPAuthResultV2 `json:"initOtpAuthResultV2,omitempty"` + InitOTPResult *InitOTPResult `json:"initOtpResult,omitempty"` + InitOTPResultV2 *InitOTPResultV2 `json:"initOtpResultV2,omitempty"` + InitUserEmailRecoveryResult *InitUserEmailRecoveryResult `json:"initUserEmailRecoveryResult,omitempty"` + OAuth2AuthenticateResult *OAuth2AuthenticateResult `json:"oauth2AuthenticateResult,omitempty"` + OAuthLoginResult *OAuthLoginResult `json:"oauthLoginResult,omitempty"` + OAuthResult *OAuthResult `json:"oauthResult,omitempty"` + OTPAuthResult *OTPAuthResult `json:"otpAuthResult,omitempty"` + OTPLoginResult *OTPLoginResult `json:"otpLoginResult,omitempty"` + PostTVCQuorumKeyShareResult *PostTVCQuorumKeyShareResult `json:"postTvcQuorumKeyShareResult,omitempty"` + ReEncryptTVCQuorumKeyShareResult *ReEncryptTVCQuorumKeyShareResult `json:"reEncryptTvcQuorumKeyShareResult,omitempty"` + RecoverUserResult *RecoverUserResult `json:"recoverUserResult,omitempty"` + RemoveIPAllowlistResult *RemoveIPAllowlistResult `json:"removeIpAllowlistResult,omitempty"` + RemoveOrganizationFeatureResult *RemoveOrganizationFeatureResult `json:"removeOrganizationFeatureResult,omitempty"` + RestoreTVCDeploymentResult *RestoreTVCDeploymentResult `json:"restoreTvcDeploymentResult,omitempty"` + SetIPAllowlistResult *SetIPAllowlistResult `json:"setIpAllowlistResult,omitempty"` + SetOrganizationFeatureResult *SetOrganizationFeatureResult `json:"setOrganizationFeatureResult,omitempty"` + SetPaymentMethodResult *BillingSetPaymentMethodResult `json:"setPaymentMethodResult,omitempty"` + SignRawPayloadResult *SignRawPayloadResult `json:"signRawPayloadResult,omitempty"` + SignRawPayloadsResult *SignRawPayloadsResult `json:"signRawPayloadsResult,omitempty"` + SignTransactionResult *SignTransactionResult `json:"signTransactionResult,omitempty"` + SolSendTransactionResult *SolSendTransactionResult `json:"solSendTransactionResult,omitempty"` + SolSendTransactionResultV2 *SolSendTransactionResultV2 `json:"solSendTransactionResultV2,omitempty"` + SparkClaimTransferResult *SparkClaimTransferResult `json:"sparkClaimTransferResult,omitempty"` + SparkPrepareLightningReceiveResult *SparkPrepareLightningReceiveResult `json:"sparkPrepareLightningReceiveResult,omitempty"` + SparkPrepareTransferResult *SparkPrepareTransferResult `json:"sparkPrepareTransferResult,omitempty"` + SparkSignFrostResult *SparkSignFrostResult `json:"sparkSignFrostResult,omitempty"` + StampLoginResult *StampLoginResult `json:"stampLoginResult,omitempty"` + UpdateAllowedOriginsResult *UpdateAllowedOriginsResult `json:"updateAllowedOriginsResult,omitempty"` + UpdateAuthProxyConfigResult *UpdateAuthProxyConfigResult `json:"updateAuthProxyConfigResult,omitempty"` + UpdateFiatOnRampCredentialResult *UpdateFiatOnRampCredentialResult `json:"updateFiatOnRampCredentialResult,omitempty"` + UpdateMfaPolicyResult *UpdateMfaPolicyResult `json:"updateMfaPolicyResult,omitempty"` + UpdateOAuth2CredentialResult *UpdateOAuth2CredentialResult `json:"updateOauth2CredentialResult,omitempty"` + UpdateOrganizationNameResult *UpdateOrganizationNameResult `json:"updateOrganizationNameResult,omitempty"` + UpdatePaymentMethodResult *BillingUpdatePaymentMethodResult `json:"updatePaymentMethodResult,omitempty"` + UpdatePolicyResult *UpdatePolicyResult `json:"updatePolicyResult,omitempty"` + UpdatePolicyResultV2 *UpdatePolicyResultV2 `json:"updatePolicyResultV2,omitempty"` + UpdatePrivateKeyTagResult *UpdatePrivateKeyTagResult `json:"updatePrivateKeyTagResult,omitempty"` + UpdateRootQuorumResult *UpdateRootQuorumResult `json:"updateRootQuorumResult,omitempty"` + UpdateTVCAppLiveDeploymentResult *UpdateTVCAppLiveDeploymentResult `json:"updateTvcAppLiveDeploymentResult,omitempty"` + UpdateUserEmailResult *UpdateUserEmailResult `json:"updateUserEmailResult,omitempty"` + UpdateUserNameResult *UpdateUserNameResult `json:"updateUserNameResult,omitempty"` + UpdateUserPhoneNumberResult *UpdateUserPhoneNumberResult `json:"updateUserPhoneNumberResult,omitempty"` + UpdateUserResult *UpdateUserResult `json:"updateUserResult,omitempty"` + UpdateUserTagResult *UpdateUserTagResult `json:"updateUserTagResult,omitempty"` + UpdateWalletAccountNameResult *UpdateWalletAccountNameResult `json:"updateWalletAccountNameResult,omitempty"` + UpdateWalletResult *UpdateWalletResult `json:"updateWalletResult,omitempty"` + UpdateWebhookEndpointResult *UpdateWebhookEndpointResult `json:"updateWebhookEndpointResult,omitempty"` + UpsertGasUsageConfigResult *UpsertGasUsageConfigResult `json:"upsertGasUsageConfigResult,omitempty"` + UpsertSwapConfigResult *UpsertSwapConfigResult `json:"upsertSwapConfigResult,omitempty"` + UpsertSwapFeeSponsorshipLimitConfigResult *UpsertSwapFeeSponsorshipLimitConfigResult `json:"upsertSwapFeeSponsorshipLimitConfigResult,omitempty"` + UpsertSwapFixedRateLimitConfigResult *UpsertSwapFixedRateLimitConfigResult `json:"upsertSwapFixedRateLimitConfigResult,omitempty"` + VerifyOTPResult *VerifyOTPResult `json:"verifyOtpResult,omitempty"` } type RevertChainEntry struct { @@ -4953,11 +5262,11 @@ type SignRawPayloadIntentV2 struct { } type SignRawPayloadResult struct { - // Component of an ECSDA signature. + // Component of a cryptographic signature, meaning varies based on signing scheme. R string `json:"r"` - // Component of an ECSDA signature. + // Component of a cryptographic signature, meaning varies based on signing scheme. S string `json:"s"` - // Component of an ECSDA signature. + // Recovery ID for ECDSA signatures, "00" otherwise. V string `json:"v"` } @@ -5090,7 +5399,7 @@ type SolSendTransactionIntent struct { SignWith string `json:"signWith"` // Whether to sponsor this transaction via Gas Station. Sponsor *bool `json:"sponsor,omitempty"` - // Base64-encoded serialized unsigned Solana transaction + // Hex-encoded serialized unsigned Solana transaction in full wire format. Legacy/V0 transactions allow 1232 bytes. V1 allows 4096 bytes with up to 12 trailing 64-byte signature slots, including the paymaster for sponsored transactions. Fill unsigned slots with zeroes. UnsignedTransaction string `json:"unsignedTransaction"` } @@ -5099,11 +5408,11 @@ type SolSendTransactionIntentV2 struct { Caip2 string `json:"caip2"` // User-provided blockhash for replay protection / deadline control. If provided, it is used as-is, including for sponsored transactions (the transaction is only broadcastable while the blockhash is current). If omitted and sponsor=true, a fresh blockhash is fetched during execution. RecentBlockhash *string `json:"recentBlockhash,omitempty"` - // Ordered Solana signer addresses Turnkey signs with. Between 1 and 16 signers. For sponsored transactions this must list every required signer of the transaction in transaction order. + // Ordered Solana signer addresses Turnkey signs with. Between 1 and 16 signers for legacy/V0, or up to 12 for V1 (11 when sponsored). For sponsored transactions this must list every required signer of the transaction in transaction order. SignWiths []string `json:"signWiths"` // Whether to sponsor this transaction via Gas Station. Sponsor *bool `json:"sponsor,omitempty"` - // Hex-encoded serialized unsigned Solana transaction (full wire format with zeroed signature placeholders) + // Hex-encoded serialized unsigned Solana transaction in full wire format. Legacy/V0 transactions allow 1232 bytes. V1 allows 4096 bytes with up to 12 trailing 64-byte signature slots, including the paymaster for sponsored transactions. Fill unsigned slots with zeroes. UnsignedTransaction string `json:"unsignedTransaction"` } @@ -5120,6 +5429,8 @@ type SolSendTransactionResultV2 struct { type SolTransactionHistoryItem struct { // Block metadata for the transaction. Block TransactionHistoryBlock `json:"block"` + // Whether the transaction failed during on-chain execution. Omitted when execution outcome is unavailable. + ExecutionFailed *bool `json:"executionFailed,omitempty"` // Transaction fee information. Fee TransactionHistoryFee `json:"fee"` // Address that paid the Solana transaction fee. This is the first signer in the transaction message. @@ -5412,6 +5723,30 @@ type SwapQuote struct { SlippageBps *string `json:"slippageBps,omitempty"` } +type SwapQuoteV2 struct { + // Client fee in basis points applied for this pair. Informational only; already reflected in output_amount and min_output_amount. + ClientFeeBps string `json:"clientFeeBps"` + // Provider-estimated completion time in seconds, when available. + EstimatedTimeSeconds *string `json:"estimatedTimeSeconds,omitempty"` + // Quote expiration as a millisecond epoch string. + ExpiresAt string `json:"expiresAt"` + FeeSponsorship *bool `json:"feeSponsorship,omitempty"` + FixedRate *bool `json:"fixedRate,omitempty"` + // Minimum acceptable base-unit amount of the output asset after slippage. + MinOutputAmount string `json:"minOutputAmount"` + // Estimated base-unit amount of the output asset. + OutputAmount string `json:"outputAmount"` + // Swap provider that produced this quote. + Provider string `json:"provider"` + // Identifier for this provider quote. Pass this value to execute_swap_v2 to bind execution to this exact quote. The signer is derived from the quote; clients do not resupply sign_with on execute. + QuoteID string `json:"quoteId"` + RemainingFeeComponents []string `json:"remainingFeeComponents,omitempty"` + // Effective total slippage tolerance in basis points for this quote, taken from the provider response when present. When the request omits input slippage_bps, the provider may calculate this value. + SlippageBps *string `json:"slippageBps,omitempty"` + SponsoredFeeComponents []string `json:"sponsoredFeeComponents,omitempty"` + TurnkeyFeeCollection *string `json:"turnkeyFeeCollection,omitempty"` +} + type SwapRefund struct { // Base-unit amount returned by the swap provider. Amount string `json:"amount"` @@ -5421,6 +5756,26 @@ type SwapRefund struct { TxHash *string `json:"txHash,omitempty"` } +type SwapSpendingWindow struct { + Enabled bool `json:"enabled"` + // Remaining spending capacity, clamped to zero. For children, also capped by remaining parent capacity. Zero when the window is disabled. This is not a reservation or a guarantee of feature eligibility. + RemainingUsd string `json:"remainingUsd"` + // Configured per-child limit. Returned only when querying the billing parent. + SubOrgWindowLimitUsd *string `json:"subOrgWindowLimitUsd,omitempty"` + // Settled spending in the current window. Fixed-rate usage stays zero until final fixed-rate costs are recorded. + UsageUsd string `json:"usageUsd"` + WindowDurationMinutes int `json:"windowDurationMinutes"` + // The parent's window limit, or the per-child limit when queried by a sub-organization. + WindowLimitUsd string `json:"windowLimitUsd"` +} + +type SwapSponsorshipFeature struct { + // Whether the billing parent holds this feature's signed permission. Quotes can use the feature only when it is permitted and its window is enabled. + Permitted bool `json:"permitted"` + // Absent until the billing parent saves a spending window. + Window *SwapSpendingWindow `json:"window,omitempty"` +} + type TokenUsage struct { Login *LoginUsage `json:"login,omitempty"` Signup *SignupUsage `json:"signup,omitempty"` @@ -5539,6 +5894,10 @@ type TVCDeployment struct { Delete bool `json:"delete"` // Unique Identifier for this TVC Deployment. ID string `json:"id"` + // The instance cpu count for this enclave. + InstanceSizeCpus *int64 `json:"instanceSizeCpus,omitempty"` + // The instance memory size in GiB for this enclave. + InstanceSizeRam *int64 `json:"instanceSizeRam,omitempty"` // The manifest used for this deployment Manifest TVCManifest `json:"manifest"` // List of operator approvals for this manifest @@ -5581,13 +5940,19 @@ type TVCManifestApproval struct { type TVCOperator struct { CreatedAt ExternalDataV1Timestamp `json:"createdAt"` + // Encryption public key for this TVC Operator. + EncryptPublicKey string `json:"encryptPublicKey"` // Unique Identifier for this TVC Operator. ID string `json:"id"` + // Source of the operator keys: EXTERNAL_KEY or ORG_WALLET_ACCOUNT. Absent for legacy operators whose source was not recorded. + KeySource *string `json:"keySource,omitempty"` // Name of this TVC Operator. Name string `json:"name"` // Public key for this TVC Operator. - PublicKey string `json:"publicKey"` - UpdatedAt ExternalDataV1Timestamp `json:"updatedAt"` + PublicKey string `json:"publicKey"` + // Signing public key for this TVC Operator. + SignPublicKey string `json:"signPublicKey"` + UpdatedAt ExternalDataV1Timestamp `json:"updatedAt"` } type TVCOperatorApproval struct { @@ -5636,6 +6001,15 @@ type TVCOperatorSetParams struct { Threshold int64 `json:"threshold"` } +type TVCQuorumKey struct { + CreatedAt ExternalDataV1Timestamp `json:"createdAt"` + ID string `json:"id"` + OperatorIds []string `json:"operatorIds"` + PublicKey string `json:"publicKey"` + Threshold int64 `json:"threshold"` + UpdatedAt ExternalDataV1Timestamp `json:"updatedAt"` +} + type TxError struct { // Ethereum-specific failure details, if available. ETH *ETHFailureDetails `json:"eth,omitempty"` @@ -5997,6 +6371,36 @@ type UpsertSwapConfigResult struct { StableFeeBps *string `json:"stableFeeBps,omitempty"` } +type UpsertSwapFeeSponsorshipLimitConfigIntent struct { + // Whether this spending window permits new swaps. Setting false only turns the saved window off and keeps its limits; it doesn't require the signed permission. This does not grant or remove the signed organization permission. + Enabled bool `json:"enabled"` + // Positive USD limit shared by the billing parent and its sub-organizations. At most 18 integer and 12 fractional digits. + OrgWindowLimitUsd string `json:"orgWindowLimitUsd"` + // Positive USD limit for each sub-organization, no greater than the parent limit. + SubOrgWindowLimitUsd string `json:"subOrgWindowLimitUsd"` + // Positive rolling window duration in minutes, at most 153722867. + WindowDurationMinutes string `json:"windowDurationMinutes"` +} + +type UpsertSwapFeeSponsorshipLimitConfigResult struct { + OrganizationID string `json:"organizationId"` +} + +type UpsertSwapFixedRateLimitConfigIntent struct { + // Whether this spending window permits new swaps. Setting false only turns the saved window off and keeps its limits; it doesn't require the signed permission. This does not grant or remove the signed organization permission. + Enabled bool `json:"enabled"` + // Positive USD limit shared by the billing parent and its sub-organizations. At most 18 integer and 12 fractional digits. + OrgWindowLimitUsd string `json:"orgWindowLimitUsd"` + // Positive USD limit for each sub-organization, no greater than the parent limit. + SubOrgWindowLimitUsd string `json:"subOrgWindowLimitUsd"` + // Positive rolling window duration in minutes, at most 153722867. + WindowDurationMinutes string `json:"windowDurationMinutes"` +} + +type UpsertSwapFixedRateLimitConfigResult struct { + OrganizationID string `json:"organizationId"` +} + type User struct { // A list of API Key parameters. This field, if not needed, should be an empty array in your request body. APIKeys []APIKey `json:"apiKeys"` @@ -6095,25 +6499,6 @@ type ValidateTVCImageResponse struct { ResolvedImageDigest *string `json:"resolvedImageDigest,omitempty"` } -type VelocityControl struct { - // Aggregation expression that the Velocity Control evaluates. - Aggregation VelocityControlAggregation `json:"aggregation"` - // Time when the Velocity Control was created. - CreatedAt ExternalDataV1Timestamp `json:"createdAt"` - // Data source for the Velocity Control. - DataSource VelocityControlDataSource `json:"dataSource"` - // Identifier for the Velocity Control. Policies reference it as `controls.`. It must be unique within the Organization. - Identifier string `json:"identifier"` - // Human-readable name for the Velocity Control. - Name string `json:"name"` - // Identifier of the Organization that owns the Velocity Control. - OrganizationID string `json:"organizationId"` - // Time when the Velocity Control was last updated. - UpdatedAt ExternalDataV1Timestamp `json:"updatedAt"` - // Unique identifier for the Velocity Control. - VelocityControlID string `json:"velocityControlId"` -} - type VelocityControlAggregation struct { // Scope that partitions matching data before aggregation. GroupBy VelocityControlAggregationGroupBy `json:"groupBy"` @@ -6152,8 +6537,8 @@ type VelocityControlAggregationWindow struct { type VelocityControlAggregationWindowInfinite map[string]any type VelocityControlAggregationWindowRolling struct { - // Duration of the rolling window, in seconds, as a base-10 integer string. - Duration string `json:"duration"` + // Duration of the rolling window, in seconds. + Duration int64 `json:"duration"` } type VelocityControlDataSource struct { @@ -6185,8 +6570,8 @@ type VelocityControlDataSourceChainAssetTransfer struct { type VelocityControlDataSourceChainAssetTransferDefinition struct { // CAIP-19 identifier for the asset. Caip19 string `json:"caip19"` - // Base-10 integer string from 0 through 255 that specifies the number of decimal places for the asset. - Decimals string `json:"decimals"` + // Integer between 0 and 255 (inclusive) that specifies the number of decimal places for the asset. + Decimals int64 `json:"decimals"` } type VelocityControlDataSourceChainAssetTransferFilter struct { @@ -6856,6 +7241,10 @@ type CreateTVCDeploymentRequest struct { HealthCheckPort int64 `json:"healthCheckPort"` // Health check type (TVC_HEALTH_CHECK_TYPE_HTTP or TVC_HEALTH_CHECK_TYPE_GRPC). HTTP health checks are made with a GET request on /health, and gRPC health checks follow the standard gRPC health checking protocol. HealthCheckType TVCHealthCheckType `json:"healthCheckType"` + // Optional desired instance cpu count. + InstanceSizeCpus *int64 `json:"instanceSizeCpus,omitempty"` + // Optional desired instance memory size in GiB. + InstanceSizeRam *int64 `json:"instanceSizeRam,omitempty"` // Optional nonce to ensure uniqueness of the deployment manifest. If not provided, it defaults to the current Unix timestamp in seconds. Nonce *int64 `json:"nonce,omitempty"` // Arguments to pass to the pivot binary at startup. Encoded as a list of strings, for example ["--foo", "bar"] @@ -6901,6 +7290,46 @@ type CreateTVCManifestApprovalsResponse struct { CreateTVCManifestApprovalsResult } +type CreateTVCOperatorRequest struct { + // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. + OrganizationID string `json:"organizationId,omitempty"` + // TimestampMs is set automatically to the current time. Override only if you need a specific timestamp. + TimestampMs string `json:"timestampMs,omitempty"` + // Human-readable name for this new TVC operator + OperatorName string `json:"operatorName"` + // Base derivation path for creating TVC operator wallet accounts + Path string `json:"path"` + // Unique identifier for an existing wallet to reuse for this TVC operator + WalletID *string `json:"walletId,omitempty"` + // Human-readable name for a new wallet created for this TVC operator + WalletName *string `json:"walletName,omitempty"` +} + +func (CreateTVCOperatorRequest) ActivityType() string { return "ACTIVITY_TYPE_CREATE_TVC_OPERATOR" } + +type CreateTVCOperatorResponse struct { + Activity Activity `json:"activity"` + CreateTVCOperatorResult +} + +type CreateTVCQuorumKeyRequest struct { + // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. + OrganizationID string `json:"organizationId,omitempty"` + // TimestampMs is set automatically to the current time. Override only if you need a specific timestamp. + TimestampMs string `json:"timestampMs,omitempty"` + // Operator public keys used to encrypt and later approve the generated TVC quorum key shares + OperatorEncryptKeys []string `json:"operatorEncryptKeys"` + // The threshold of operators needed to reassemble this TVC quorum key + Threshold int64 `json:"threshold"` +} + +func (CreateTVCQuorumKeyRequest) ActivityType() string { return "ACTIVITY_TYPE_CREATE_TVC_QUORUM_KEY" } + +type CreateTVCQuorumKeyResponse struct { + Activity Activity `json:"activity"` + CreateTVCQuorumKeyResult +} + type CreateUserTagRequest struct { // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. OrganizationID string `json:"organizationId,omitempty"` @@ -6935,30 +7364,6 @@ type CreateUsersResponse struct { CreateUsersResult } -type CreateVelocityControlRequest struct { - // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. - OrganizationID string `json:"organizationId,omitempty"` - // TimestampMs is set automatically to the current time. Override only if you need a specific timestamp. - TimestampMs string `json:"timestampMs,omitempty"` - // Aggregation expression that the Velocity Control evaluates. - Aggregation VelocityControlAggregation `json:"aggregation"` - // Data source for the Velocity Control. - DataSource VelocityControlDataSource `json:"dataSource"` - // Identifier for the Velocity Control. Policies reference it as `controls.`. It must be unique within the Organization. - Identifier string `json:"identifier"` - // Human-readable name for the Velocity Control. - Name string `json:"name"` -} - -func (CreateVelocityControlRequest) ActivityType() string { - return "ACTIVITY_TYPE_CREATE_VELOCITY_CONTROL" -} - -type CreateVelocityControlResponse struct { - Activity Activity `json:"activity"` - CreateVelocityControlResult -} - type CreateWalletRequest struct { // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. OrganizationID string `json:"organizationId,omitempty"` @@ -7219,6 +7624,22 @@ type DeletePrivateKeysResponse struct { DeletePrivateKeysResult } +type DeleteSecretsRequest struct { + // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. + OrganizationID string `json:"organizationId,omitempty"` + // TimestampMs is set automatically to the current time. Override only if you need a specific timestamp. + TimestampMs string `json:"timestampMs,omitempty"` + // Unique identifiers of the secrets to delete. Must contain between 1 and 32 distinct UUIDs. All secrets must belong to the organization. + SecretIds []string `json:"secretIds"` +} + +func (DeleteSecretsRequest) ActivityType() string { return "ACTIVITY_TYPE_DELETE_SECRETS" } + +type DeleteSecretsResponse struct { + Activity Activity `json:"activity"` + DeleteSecretsResult +} + type DeleteSmartContractInterfaceRequest struct { // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. OrganizationID string `json:"organizationId,omitempty"` @@ -7321,23 +7742,6 @@ type DeleteUsersResponse struct { DeleteUsersResult } -type DeleteVelocityControlRequest struct { - // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. - OrganizationID string `json:"organizationId,omitempty"` - // TimestampMs is set automatically to the current time. Override only if you need a specific timestamp. - TimestampMs string `json:"timestampMs,omitempty"` - VelocityControlID string `json:"velocityControlId"` -} - -func (DeleteVelocityControlRequest) ActivityType() string { - return "ACTIVITY_TYPE_DELETE_VELOCITY_CONTROL" -} - -type DeleteVelocityControlResponse struct { - Activity Activity `json:"activity"` - DeleteVelocityControlResult -} - type DeleteWalletAccountsRequest struct { // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. OrganizationID string `json:"organizationId,omitempty"` @@ -7456,13 +7860,33 @@ type ETHUndelegate7702Response struct { ETHUndelegate7702Result } +type EarnClaimRewardsRequest struct { + // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. + OrganizationID string `json:"organizationId,omitempty"` + // TimestampMs is set automatically to the current time. Override only if you need a specific timestamp. + TimestampMs string `json:"timestampMs,omitempty"` + // CAIP-2 chain to claim rewards on (e.g. 'eip155:8453'). Rewards accrue per chain; see ListEarnRewards. + Caip2 string `json:"caip2"` + // A Turnkey-managed wallet address the rewards are attributed to. The claim transaction is signed by this wallet and the Merkl Distributor transfers every reward token to it. + SignWith string `json:"signWith"` + // Whether to sponsor this transaction via Gas Station. + Sponsor *bool `json:"sponsor,omitempty"` +} + +func (EarnClaimRewardsRequest) ActivityType() string { return "ACTIVITY_TYPE_EARN_CLAIM_REWARDS" } + +type EarnClaimRewardsResponse struct { + Activity Activity `json:"activity"` + EarnClaimRewardsResult +} + type EarnDeployWrapperRequest struct { // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. OrganizationID string `json:"organizationId,omitempty"` // TimestampMs is set automatically to the current time. Override only if you need a specific timestamp. TimestampMs string `json:"timestampMs,omitempty"` // CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base). - ChainCaip2 string `json:"chainCaip2"` + Caip2 string `json:"caip2"` // Your fee on gross yield, in basis points (e.g., '2000' for 20%). Maximum is 4000 (40%). ClientFeeBps string `json:"clientFeeBps"` // The wallet address that receives the client's fee payouts on-chain. Must be a Turnkey-managed wallet address. @@ -7486,7 +7910,7 @@ type EarnDepositRequest struct { // Amount of the underlying asset to deposit, in raw on-chain units (e.g., '1000000' for 1 USDC at 6 decimals). Assets string `json:"assets"` // CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base). - ChainCaip2 string `json:"chainCaip2"` + Caip2 string `json:"caip2"` // A Wallet account address or Private Key address to deposit from and sign with. Must be an on-chain address; Private Key identifiers are not supported. SignWith string `json:"signWith"` // Whether to sponsor this transaction via Gas Station. @@ -7530,7 +7954,7 @@ type EarnWithdrawRequest struct { // The amount of the underlying asset to withdraw, in raw on-chain units. Pass 'MAX' to withdraw the entire position. AmountValue string `json:"amountValue"` // CAIP-2 chain ID the vault lives on (e.g., 'eip155:8453' for Base). - ChainCaip2 string `json:"chainCaip2"` + Caip2 string `json:"caip2"` // A Wallet account address or Private Key address to withdraw to and sign with. Must be an on-chain address; Private Key identifiers are not supported. SignWith string `json:"signWith"` // Whether to sponsor this transaction via Gas Station. @@ -8066,6 +8490,56 @@ type OTPLoginResponse struct { OTPLoginResult } +type PostTVCQuorumKeyShareRequest struct { + // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. + OrganizationID string `json:"organizationId,omitempty"` + // TimestampMs is set automatically to the current time. Override only if you need a specific timestamp. + TimestampMs string `json:"timestampMs,omitempty"` + // Unique identifier of the TVC deployment receiving quorum key share + DeploymentID string `json:"deploymentId"` + // Hex-encoded ephemeral public key used to encrypt the quorum key share + EphemeralPublicKeyHex string `json:"ephemeralPublicKeyHex"` + // Re-encrypted quorum key share and approval + ShareApprovalBundle QuorumKeyShareApprovalBundle `json:"shareApprovalBundle"` +} + +func (PostTVCQuorumKeyShareRequest) ActivityType() string { + return "ACTIVITY_TYPE_POST_TVC_QUORUM_KEY_SHARE" +} + +type PostTVCQuorumKeyShareResponse struct { + Activity Activity `json:"activity"` + PostTVCQuorumKeyShareResult +} + +type ReEncryptTVCQuorumKeyShareRequest struct { + // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. + OrganizationID string `json:"organizationId,omitempty"` + // TimestampMs is set automatically to the current time. Override only if you need a specific timestamp. + TimestampMs string `json:"timestampMs,omitempty"` + // Quorum key for the TVC application + AppQuorumKey string `json:"appQuorumKey"` + // Base64-encoded attestation document for the TVC deployment provisioning enclave + AttestationDocB64 string `json:"attestationDocB64"` + // Unique identifier of the TVC deployment receiving the re-encrypted quorum key share + DeploymentID string `json:"deploymentId"` + // Base64-encoded manifest for the TVC deployment + ManifestB64 string `json:"manifestB64"` + // Operator encryption public key used to encrypt the hosted TVC quorum key share + OperatorEncryptKey string `json:"operatorEncryptKey"` + // Operator signing public key used to approve the TVC manifest + OperatorSignKey string `json:"operatorSignKey"` +} + +func (ReEncryptTVCQuorumKeyShareRequest) ActivityType() string { + return "ACTIVITY_TYPE_RE_ENCRYPT_TVC_QUORUM_KEY_SHARE" +} + +type ReEncryptTVCQuorumKeyShareResponse struct { + Activity Activity `json:"activity"` + ReEncryptTVCQuorumKeyShareResult +} + type RecoverUserRequest struct { // OrganizationID defaults to the client's organization ID. Override only when targeting a sub-organization. OrganizationID string `json:"organizationId,omitempty"` @@ -8265,11 +8739,11 @@ type SolSendTransactionRequest struct { Caip2 string `json:"caip2"` // User-provided blockhash for replay protection / deadline control. If provided, it is used as-is, including for sponsored transactions (the transaction is only broadcastable while the blockhash is current). If omitted and sponsor=true, a fresh blockhash is fetched during execution. RecentBlockhash *string `json:"recentBlockhash,omitempty"` - // Ordered Solana signer addresses Turnkey signs with. Between 1 and 16 signers. For sponsored transactions this must list every required signer of the transaction in transaction order. + // Ordered Solana signer addresses Turnkey signs with. Between 1 and 16 signers for legacy/V0, or up to 12 for V1 (11 when sponsored). For sponsored transactions this must list every required signer of the transaction in transaction order. SignWiths []string `json:"signWiths"` // Whether to sponsor this transaction via Gas Station. Sponsor *bool `json:"sponsor,omitempty"` - // Hex-encoded serialized unsigned Solana transaction (full wire format with zeroed signature placeholders) + // Hex-encoded serialized unsigned Solana transaction in full wire format. Legacy/V0 transactions allow 1232 bytes. V1 allows 4096 bytes with up to 12 trailing 64-byte signature slots, including the paymaster for sponsored transactions. Fill unsigned slots with zeroes. UnsignedTransaction string `json:"unsignedTransaction"` }