Request conventions
The API is served under /v1. JSON responses use typed fields. Campaign IDs and entry IDs are UUIDs; token quantities are canonical decimal strings in base units.
GET requests retrieve state. Session-authenticated mutations require the session cookie, X-CSRF-Token, an allowed Origin, and Idempotency-Key. Keep the CSRF token in memory.
GET /v1/campaigns?limit=25&sort=ending
Accept: application/jsonWallet authentication
Deployed contract wallets use EIP-1271 signature validation. Counterfactual wallets using EIP-6492 are not supported. Changing or revoking a contract-wallet signature can invalidate the session.
POST /auth/challenge with wallet and chain_id.
Sign the exact returned message using the selected wallet.
POST /auth/verify with message and signature.
Send credentials on authenticated requests and the returned CSRF token on mutations.
{
"wallet": "<wallet-address>",
"chain_id": "<configured-chain-id>"
}Core endpoints
| Endpoint | Purpose |
|---|---|
| GET /campaigns | Paginated public discovery; filters and newest/ending sort. |
| GET /campaigns/:id | Campaign configuration and ordered tasks. |
| POST /campaigns | Create a private campaign draft. |
| POST /campaigns/:id/entries | Register the authenticated payout wallet. |
| PUT /campaigns/:id/my-entry/submissions/:task_id | Save versioned task evidence. |
| POST /campaigns/:id/my-entry/submit | Submit the current entry for review. |
| GET /campaigns/:id/allocations/:wallet | Retrieve allocations and claim proofs. |
Prepared transactions
Prepare endpoints return an unsigned transaction with chain_id, to, data, value, expected_sender, intent, and expires_at. The caller checks the payload and asks the designated wallet to execute it.
Creation, funding, activation, finalization, claiming, cancellation, and sweeping each have a prepare endpoint. Funding also returns required approvals. Confirm approvals and prepare funding again before execution.
POST /campaigns/:id/transactions records a tracking hint. Authoritative confirmation comes from the indexer’s verified escrow events.
Versioning and retries
Versioned mutations carry expected_version. If state has changed, refresh and inspect it before repeating the action.
For an ambiguous network failure or timeout, reuse the same idempotency key with the exact original payload. Do not retry a rejected business rule blindly.
X-CSRF-Token: <session-csrf-token>
Idempotency-Key: <unique-request-key>
Content-Type: application/jsonError responses
400 indicates an invalid request, 401 an unauthenticated session, 403 denied access, 404 an unavailable resource, 409 a state or version conflict, 422 business validation, and 429 a rate limit. Dependency failures use 503 or 504.
{
"error": {
"code": "STALE_VERSION",
"message": "Refresh the campaign before editing.",
"request_id": "<request-reference>"
}
}