HTTP
Routes
These routes live on yap-pay.xyz. They do not accept a seed, vault password, or private key.
GET /api/session
Reads the signed-in account for the header. A signed-out visit, or a database that is down, returns no user.
{ "user": null }
{ "user": { "email": "person@example.com", "role": "member" } }role is member or operator. The operator role opens the desk.
POST /api/referral/install
Credits one Yap Signer install for an 8-character referral code. The installer token is a UUID, stored only as a hash. A credited install adds 5 credits. The same token does not credit twice, and an account cannot credit its own code.
{
"code": "AB23CD45",
"installerToken": "123e4567-e89b-12d3-a456-426614174000"
}200{ "credited": true, "credits": 5 }200{ "credited": false, "reason": "already" }200{ "credited": false, "reason": "own-code" }404{ "credited": false, "reason": "unknown-code" }400{ "credited": false, "reason": "bad" }503{ "credited": false, "reason": "offline" }
POST /api/activity
A signed-in account records a confirmed swap or send. The route stores the asset, the amount, and the public signature. It does not sign the transfer. A repeated signature is kept once.
{
"kind": "swap",
"asset": "SOL",
"amount": "0.25",
"counterAsset": "USDC",
"signature": "<public signature>"
}kind is swap or send. asset is 2 to 12 letters or digits. amount is a decimal greater than 0, with at most 9 places and at most 12 digits before the decimal. counterAsset is stored for a swap. signature is optional: a Solana signature or a 0x transaction hash. A send drops counterAsset.
200{ "recorded": true }or{ "recorded": false }401{ "recorded": false, "reason": "signed-out" }400{ "recorded": false, "reason": "bad" }503{ "recorded": false, "reason": "offline" }