API and webhooks
Integrate without a public webhook dump of decrypted balances.
Status: design. XEROPAY is being built. These pages describe intended behaviour. Nothing here is claimed as live mainnet. Details can change. See What's live.
REST-shaped endpoints for shield, unshield, and note queries. Events fire when a payment settles, fails, or a viewing key is disclosed. There is no public sandbox key yet — this is the intended surface, not a live contract list.
| Method | Path | Note |
|---|---|---|
| POST | /v1/shield | Create a shielded note for a named payee. |
| POST | /v1/unshield | Exit to a named destination after screening. |
| GET | /v1/notes | Client-side decrypt — never a server-side balance. |
| POST | /v1/webhooks | Subscribe to settled / failed / disclosed events. |
Rules of the surface
- Auth is scoped per workspace, not a single shared wallet.
- Webhook payloads never include decrypted balances.
- Idempotency keys on money-moving calls.
- Retries on failed delivery; no public event log.
