WalletD developers

All endpoints

Every operation in the wallet contract, in one list. This is the fastest way to find an endpoint by name, or to hand the whole surface to an agent.

Users and balances

Wallet users, their balances per account purpose, and their transaction history.

Top-ups

Money in, through a payment gateway. The wallet is credited only on verified confirmation.

Transfers

Peer-to-peer movement inside the tenant loop.

Payments and refunds

Paying a merchant instantly or as an authorization hold, then capturing, voiding or refunding it.

Subscriptions

Recurring charge mandates, their lifecycle, and the dunning that follows a failed cycle.

Rewards and loyalty

Reward rules, the grants they produce, and converting points back into wallet cash.

Limits and tiers

Per-tier caps on money movement and the tier a user is assigned to.

Merchants

Merchants and their settlement accounts.

Catalog

Offerings, variants, categories and stock, owned by the ecosystem client that sells them.

Upload one image and get the URL to store on a profile or offering

Stores one image in the deployment's object store and answers with its public URL, which you then pass as logo_url or image_url on a separate profile or offering write; uploading alone changes noth...

The clients the caller may manage

A consumer gets the clients its organization memberships cover, which is how a founder finds their own client after onboarding.

Self-serve ecosystem client onboarding (org + merchant + profile)

Self-serve onboarding: creates the identity-provider organization, the merchant with its settlement account and the public profile in one call.

What this client sold, and what it kept

The client's own trading history: a summary (sales, gross, fees, marketplace commission, refunded and net, plus subscriber count) followed by a page of individual sales, newest first by created_at,...

Fetch a client (members and loop staff)

Fetches one client with its profile, status, commission override and the merchant it settles to.

Update the client's public identity

Replaces the client's public identity — display name, category, description and logo — as Explore shows it.

The client's own offerings, one page at a time

The client's own offerings in every status, with the merchant view of each variant: cost, markup, pricing mode and stock counts, none of which Explore ever shows a shopper.

Create a draft offering

Creates an offering as a draft; nothing reaches Explore until it is published.

One of the client's own offerings, any status, with its live variants

One of the client's own offerings in any status, with its live variants and the merchant-only pricing fields.

Edit an offering

A draft may change anything. A published item may be repriced, and the change is recorded in its price history.

Publish a draft offering to discovery

Moves a draft into discovery. This is the only client action that puts something in front of the loop's users, so it is the one that waits for approval: a client the platform has not made active is...

Archive an offering (draft or published)

Retires an offering, draft or published: it leaves discovery and can no longer be edited or bought.

Add a variant to an item

Adds a variant to a product, with its own option values, price or cost-plus markup, SKU and optional inventory tracking.

Edit a variant; a price change is recorded in history

Edits one variant. A price change is written to the client's price history with the actor that made it, so a shopper's disputed price can be explained later.

Retire a variant (a product keeps at least one)

Retires one variant. A product keeps at least one live variant, so archiving the last one is refused invalid_request (400) — archive the product instead.

Change a tracked variant's on-hand count, with a reason

Changes a tracked variant's on-hand count, either by delta or to an absolute set_to, with a reason, and answers with the variant and the movement row it wrote.

The shop's stock log, newest first

The shop's stock log, newest first: every reservation, sale, restock and manual adjustment with the on-hand and reserved counts it left behind and the actor who caused it.

The shop's default markup and rounding

The shop's default markup and rounding rule, which is what variants priced cost_plus derive their price from.

Set the shop's default markup and rounding, repricing cost_plus variants

Sets the shop's default markup and rounding and immediately reprices every cost_plus variant; the response says how many were repriced and each change lands in the price history.

Every price change in the shop, newest first

Every price change in the shop, newest first, with the old and new amount, what caused it (a manual edit or a repricing) and who did it.

The shop's category tree, parents first

The shop's category tree, parents before their children.

Create a category

Creates a category, optionally under a parent.

Delete an unused category

Deletes a category and answers 204. Needs authority over the client — membership of its organization, an API key bound to this client, or tenant staff holding clients:manage; anything else is refus...

Rename or move a category

Renames a category or moves it under a different parent.

The shop's imports, newest first

The shop's bulk imports, newest first, each with its status and its create, update, error and applied counts.

Upload a CSV or XLSX (and optionally a ZIP of images) for preview

Nothing lands until the import is committed.

One import and its counts

One import with its current status and counts — poll this after starting or committing an import, both of which finish in the background.

The preview, row by row

The parsed preview, row by row: what each row would create or update, the image it resolved, and the validation errors that would stop it.

Apply a ready import in the background

Applies a previewed import in the background and answers 202 with the import moved to committing; poll the import to see it finish.

Drop an import that has not been committed

Drops an import that has not been committed, leaving the catalog untouched.

The merchant's API keys, without secrets

The merchant's API keys with their environment, scopes, status and last use.

Issue an API key that acts as this merchant

Only a signed-in member of the merchant's organization may issue a key; a key cannot mint more keys.

Revoke one of the merchant's keys

Revokes one of the merchant's keys and answers 204; the key stops authenticating at once.

The merchant's own webhook endpoints

A merchant endpoint receives the events that belong to this merchant: product.*, order.*, inventory.* and import.*.

Register a webhook endpoint for this merchant; the signing secret is returned once

Registers a webhook endpoint that receives only this merchant's events.

Stop deliveries to one of the merchant's endpoints

Stops deliveries to one of the merchant's endpoints and answers 204.

Delivery attempts to the merchant's endpoints

Delivery attempts to this merchant's endpoints, newest first, with response code and error.

Settlement and marketing balances

The client's settlement balance and its marketing balance.

Move the client's settlement money into its marketing account

Moves money from the client's settlement balance into its marketing account, where cashback rules draw from.

Set a merchant's per-transaction commission rate (tenant admin)

The tenant's negotiated marketplace commission for this one merchant, applied to every catalog sale it makes.

List this merchant's own cashback and loyalty rules

The merchant's own cashback and loyalty rules — the ones it owns, not the tenant-wide rules that may also apply to its sales.

Set a cashback or loyalty rule for this merchant, common or per-product

Sets one of the merchant's own reward rules, either common to the whole shop or bound to one offering by offering_id; a per-product rule overrides the common one for that product.

Turn off one of this merchant's own rules

Retires a rule the merchant owns, freeing its slot so a new rate can be set.

Orders

Multi-line orders against the catalog, and their fulfilment state.

Discovery

The public read surface over published clients and offerings, plus purchase and subscribe.

Payouts

Moving a client's settlement money out of the loop. Books first, the transfer follows.

Webhooks

Endpoint registration, the emitted event log, and redelivery.

Ledger and reporting

Tenant-wide transaction explorer, balance totals, movement metrics and the fee plan.

Operations and audit

The audit trail and the vendor-support access grants that gate WalletD's own staff.

Platform administration

Tenant provisioning and per-tenant health. Platform staff only; not part of a partner integration.

List tenants (platform staff only)

Every tenant on this deployment, newest first, with its fee plan and commission mode.

Provision a tenant with its system accounts (platform staff only)

Provisions a partner loop: the tenant's ledger is created first, then the tenant row, so the tenant id is minted alongside its books.

Per-tenant health snapshot — balances, fee plan, ledger invariants (platform staff only)

The tenant's balance rollup by owner type, purpose and commodity, plus the one invariant a caller can check without holding the books: every commodity must net to zero across the whole ledger.

Whole-platform ledger view — every tenant's position and health (global admin only)

One row per tenant with its user count, 30-day movement, treasury float, outstanding liabilities and whether its books net to zero, plus totals per currency.

Ecosystem clients across all tenants, the review queue (global admin only)

Ecosystem clients across every tenant — the moderation queue.

Let a pending client publish to Explore (platform staff only)

Lets a pending client publish its offerings to Explore.

Hide a client's whole catalog from Explore (platform staff only)

Suspension is moderation, not confiscation: the catalog disappears from Explore while settled money stays settled and a payout still works.

Cross-tenant transaction explorer (global admin only)

Every tenant's transactions with their resolved legs, optionally narrowed by tenant and by type.

Wallet users across all tenants (global admin only)

Wallet users across every tenant, optionally narrowed by tenant and by a free-text query.

Subscriptions across all tenants (global admin only)

Subscriptions across every tenant, optionally narrowed by tenant and by status.

System

Liveness. Unauthenticated, and the only path outside the bearer scheme.

On this page