Skip to content
Metamynd
Developers · API

The Governance API

A resource-oriented REST API for identity, mandates, the authorize gate, evidence and human review — served under /api/v1.

01

Onboarding

  • POST /onboarding/agent — provision in one call
  • POST /onboarding/sandbox — a ready sandbox agent (no auth)
  • POST /onboarding/requests — delegated issuance
  • POST /agent-identity/:id/verify-key — prove a BYOK key
02

The gate

  • POST /policy/mandate/authorize — allow / observe / block / escalate; every verdict also carries principalVerified
  • POST /policy/mandate/authorize/:id/capture — settle a hold
  • GET /policy/mandate/:ref/status — cap, spend, principalVerified & principalTierReason
  • GET /policy/bundle/:did — the signed policy bundle
  • GET /policy/escalations — the human-review queue
03

Conventions

Every request is Ed25519-signed over a canonical message with a single-use nonce, so the gate is server-authoritative and can't be bypassed or replayed. Responses share one envelope ({ success, message, data }) and every verdict carries a stable reasonCode (e.g. SOP_SPEND_CAP, RISK_REVIEW, AGENT_KEY_UNVERIFIED). Fetch the machine-readable schema at GET /magp/schema.

Example

See it in code

provision-and-authorize.sh
# 1. Provision an agent in ONE call (as a signed-in owner)
curl -X POST https://metamynd.ai/api/v1/onboarding/agent \
  -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
  -d '{ "name": "Support Bot", "scope": "flight-purchase", "perTxnMax": 500 }'
# → agent.metamynd.json { agentDid, agentKey, mandate, bundleUrl, issuer }

# 2. Every governed action passes the signed authorize gate
#    → { decision: "allow" | "block" | "escalate", reasonCode, authorizationId }

Prepare your organisation for the Agentic Economy