Developers · API
The Governance API
A resource-oriented REST API for identity, mandates, the authorize gate, evidence and human review — served under /api/v1.
01
Onboarding
- POST /onboarding/agent — provision in one call
- POST /onboarding/sandbox — a ready sandbox agent (no auth)
- POST /onboarding/requests — delegated issuance
- POST /agent-identity/:id/verify-key — prove a BYOK key
02
The gate
- POST /policy/mandate/authorize — allow / observe / block / escalate; every verdict also carries principalVerified
- POST /policy/mandate/authorize/:id/capture — settle a hold
- GET /policy/mandate/:ref/status — cap, spend, principalVerified & principalTierReason
- GET /policy/bundle/:did — the signed policy bundle
- GET /policy/escalations — the human-review queue
03
Conventions
Every request is Ed25519-signed over a canonical message with a single-use nonce, so the gate is server-authoritative and can't be bypassed or replayed. Responses share one envelope ({ success, message, data }) and every verdict carries a stable reasonCode (e.g. SOP_SPEND_CAP, RISK_REVIEW, AGENT_KEY_UNVERIFIED). Fetch the machine-readable schema at GET /magp/schema.
Example
See it in code
provision-and-authorize.sh
# 1. Provision an agent in ONE call (as a signed-in owner)
curl -X POST https://metamynd.ai/api/v1/onboarding/agent \
-H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
-d '{ "name": "Support Bot", "scope": "flight-purchase", "perTxnMax": 500 }'
# → agent.metamynd.json { agentDid, agentKey, mandate, bundleUrl, issuer }
# 2. Every governed action passes the signed authorize gate
# → { decision: "allow" | "block" | "escalate", reasonCode, authorizationId }