Klineo/Docs
Open app ↗

API reference

Proof, vaults, receipts and passports

Paths on this page are relative to /api/liquidity-studio/v2. Authentication and required headers vary by operation.

API reference overview · OpenAPI download

Operations on this page#

Method Path Operation
GET /passports listPassports
POST /passports publishLiquidityPassport
GET /passports/{id} getPassports
GET /vaults listQualifiedVaultsV2
GET /vaults/{id} getQualifiedVaultV2
GET /receipts listExecutionReceiptsV2
GET /receipts/{id} getExecutionReceiptV2
GET /proof listProofV2
POST /passports/{id}/revoke revokeLiquidityPassport
GET /public/passports/{slug} getPublicLiquidityPassport
GET /public/passports/{slug}/formats/{format} downloadPublicLiquidityPassport
GET /public/passports/{slug}/verification-bundle downloadLiquidityPassportVerificationBundle
GET /public/studies/{slug} getSharedSimulationStudy

List liquidity passports#

GET /passports

Operation ID: listPassports

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with proof:read (serviceCredential)

Service scope: proof:read. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
cursor query No string Opaque cursor returned in the previous response metadata.
limit query No integer Default: 50; Minimum: 1; Maximum: 100

Responses#

Status Description Content type and schema
200 Latest tenant-isolated aggregate versions application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes Array of All of: RecordEnvelope; object —
data[].allOf[2].payload Yes LiquidityPassport —
meta Yes object Additional properties rejected
meta.count Yes integer Minimum: 0
meta.hasMore Yes boolean —
meta.nextCursor No string —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Publish issuer-signed claims recomputed from exact current server evidence#

POST /passports

Operation ID: publishLiquidityPassport

Authentication: __Host-klineo_session cookie (sessionCookie)

Conditional version precondition: A passport already exists for payload.slug.

Parameters#

Name Location Required Type Description and constraints
Idempotency-Key header Yes string Min length: 8; Max length: 160
x-klineo-organization-id header Yes string —
If-Match header No string Pattern: ^"[^"\\ ]+"$

Request body#

Required: yes.

application/json

object — Additional properties rejected

Field Required at this level Type Description and constraints
payload Yes object Additional properties rejected
payload.passportVersion Yes Constant liquidity-passport-v1 —
payload.artifactRendererVersion Yes string Allowed: liquidity-passport-artifacts-v1, liquidity-passport-artifacts-v2
payload.signatureAlgorithm Yes Constant Ed25519 —
payload.signerProviderId Yes string —
payload.signerKeyResourceVersion Yes Hash —
payload.slug Yes string —
payload.vaultId Yes string —
payload.issuerName Yes string —
payload.reportBrand No object Additional properties rejected
payload.reportBrand.partnerId Yes string —
payload.reportBrand.name Yes string —
payload.reportBrand.accentColor Yes string Pattern: ^#[0-9a-fA-F]{6}$
payload.reportBrand.logoContentHash No Hash —
payload.reportBrand.sourceBinding Yes object Additional properties rejected
payload.reportBrand.sourceBinding.partnerOrganizationId Yes string —
payload.reportBrand.sourceBinding.partnerConfigurationResourceVersion Yes Hash —
payload.reportBrand.sourceBinding.partnerConfigurationArtifactHash Yes Hash —
payload.reportBrand.sourceBinding.consentId Yes string —
payload.reportBrand.sourceBinding.consentResourceVersion Yes Hash —
payload.reportBrand.sourceBinding.consentArtifactHash Yes Hash —
payload.generatedAt Yes string Format: date-time
payload.validUntil Yes string Format: date-time
payload.usableDepthByTradeSize Yes Array of object Min items: 1
payload.usableDepthByTradeSize[].tradeSizeQuote Yes AtomicAmount —
payload.usableDepthByTradeSize[].buySlippagePips Yes Pips —
payload.usableDepthByTradeSize[].sellSlippagePips Yes Pips —
payload.historicalReliabilityPips Yes Pips —
payload.policyCompliancePips Yes At least one of: Pips; null —
payload.policyLimits No object Additional properties rejected
payload.policyLimits.level Yes integer Allowed: 0, 1, 2, 3, 4
payload.policyLimits.maximumAmountPerTransaction Yes AtomicAmount —
payload.policyLimits.maximumDailyTurnover Yes AtomicAmount —
payload.policyLimits.maximumSlippagePips Yes Pips —
payload.policyLimits.approvedContracts Yes Array of Address Max items: 256
payload.policyLimits.approvedAssets Yes Array of Address Max items: 256
payload.policyLimits.approvedAdapterIds Yes Array of string Max items: 256
payload.policyLimits.minimumSecondsBetweenActions Yes integer Minimum: 0; Maximum: 31536000
payload.policyLimits.minimumPriceX18 No AtomicAmount —
payload.policyLimits.maximumPriceX18 No AtomicAmount —
payload.policyLimits.oracleMaximumAgeSeconds Yes integer Minimum: 1; Maximum: 86400
payload.policyLimits.expiresAt Yes string Format: date-time
payload.policyLimits.controlEpoch Yes AtomicAmount —
payload.policyLimits.publicMempoolFallbackAllowed Yes boolean —
payload.reconciledPositionCount Yes integer Minimum: 0
payload.majorIncidentCount Yes integer Minimum: 0
payload.treasuryOwnedLiquidityQuote No AtomicAmount —
payload.rentedLiquidityQuote No AtomicAmount —
payload.incidentDetails No object Additional properties rejected
payload.incidentDetails.v1IncidentEvidenceHashes Yes Array of Hash Max items: 256
payload.incidentDetails.anomalies Yes Array of object Max items: 256
payload.incidentDetails.anomalies[].detectorVersion Yes Constant robust-mad-v1 —
payload.incidentDetails.anomalies[].kind Yes string Allowed: LIQUIDITY_DISAPPEARANCE, ONE_SIDED_FLOW, INACTIVE_RANGE, STABLECOIN_DEPEG, ORACLE_DISAGREEMENT, INVENTORY_ACCUMULATION, EXCESSIVE_TURNOVER, MANIPULATION_INDICATOR, SIMULATED_REALIZED_DIVERGENCE
payload.incidentDetails.anomalies[].severity Yes string Allowed: INFO, WARNING, CRITICAL
payload.incidentDetails.anomalies[].artifactHash Yes Hash —
payload.externalManagerExposureQuote No AtomicAmount —
payload.externalManagerNames No Array of string —
payload.dataFreshnessSeconds Yes integer Minimum: 0
payload.disclosure Yes object Additional properties rejected
payload.disclosure.showTreasuryOwnership Yes boolean —
payload.disclosure.showExternalManagerNames Yes boolean —
payload.disclosure.showIncidentDetails Yes boolean —
payload.disclosure.showPolicyLimits Yes boolean —
payload.reportHashes Yes Array of Hash Min items: 1; Max items: 128
payload.sourceBindings Yes LiquidityPassportSourceBindings —
payload.resultsRegistryProviderId No string —
payload.resultsRegistryProviderResourceVersion No Hash —
payload.resultsRegistryProviderAttestationHash No Hash —
payload.resultsRegistryCommitmentHash No Hash —
payload.resultsRegistryReceipt No object Additional properties rejected
payload.resultsRegistryReceipt.receiptVersion Yes Constant liquidity-passport-results-registry-receipt-v1 —
payload.resultsRegistryReceipt.providerId Yes string —
payload.resultsRegistryReceipt.providerResourceVersion Yes Hash —
payload.resultsRegistryReceipt.providerAttestationHash Yes Hash —
payload.resultsRegistryReceipt.passportSubjectHash Yes Hash —
payload.resultsRegistryReceipt.commitmentHash Yes Hash —
payload.resultsRegistryReceipt.issuedAt Yes string Format: date-time
payload.resultsRegistryReceipt.signature Yes string Content encoding: base64
payload.supersedesPassportHash No Hash —
payload.contentHash Yes Hash —
payload.signature Yes string Content encoding: base64
payload.marketQualityScoreId Yes string Min length: 3; Max length: 160
reason Yes string Min length: 3; Max length: 500

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Responses#

Status Description Content type and schema
201 Source-grounded canonical passport and immutable report job application/json: object
409 A numeric claim, freshness window, provider generation, or source binding differs No response body declared
412 Superseded passport generation changed No response body declared

201 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes object Additional properties rejected
data.passport Yes All of: RecordEnvelope; object —
data.passport.allOf[2].payload Yes LiquidityPassport —
data.reportJob Yes OperatingSystemJob —
data.signedFormatsReady Yes Array of string —
data.artifactState Yes Constant PENDING_IMMUTABLE_OBJECT_REGISTRATION —
data.executionAuthorityGranted Yes Constant false —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Get one liquidity passports aggregate#

GET /passports/{id}

Operation ID: getPassports

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with proof:read (serviceCredential)

Service scope: proof:read. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
id path Yes string —

Responses#

Status Description Content type and schema
200 Current immutable aggregate version application/json: object
404 Not found No response body declared

200 response headers

Header Required Type Description and constraints
ETag Yes string —

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes All of: RecordEnvelope; object —
data.allOf[2].payload Yes LiquidityPassport —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

List tenant-isolated qualified vault metadata projected from authoritative v1 custody records#

GET /vaults

Operation ID: listQualifiedVaultsV2

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with vaults:read (serviceCredential)

Service scope: vaults:read. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
cursor query No string Opaque cursor returned in the previous response metadata.
limit query No integer Default: 50; Minimum: 1; Maximum: 100

Responses#

Status Description Content type and schema
200 Cursor-paginated vault projections application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes Array of QualifiedVaultV2 —
meta Yes object Additional properties rejected
meta.count Yes integer Minimum: 0
meta.hasMore Yes boolean —
meta.nextCursor No string —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Read one qualified vault and immutable deployment/control evidence#

GET /vaults/{id}

Operation ID: getQualifiedVaultV2

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with vaults:read (serviceCredential)

Service scope: vaults:read. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
id path Yes string —

Responses#

Status Description Content type and schema
200 Vault projection application/json: object
404 Not found No response body declared

200 response headers

Header Required Type Description and constraints
ETag Yes string —

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes QualifiedVaultV2 —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

List canonical inclusion, finality, reconciliation, and attribution receipts#

GET /receipts

Operation ID: listExecutionReceiptsV2

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with receipts:read (serviceCredential)

Service scope: receipts:read. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
cursor query No string Opaque cursor returned in the previous response metadata.
limit query No integer Default: 50; Minimum: 1; Maximum: 100

Responses#

Status Description Content type and schema
200 Cursor-paginated receipt projections application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes Array of ExecutionReceiptV2 —
meta Yes object Additional properties rejected
meta.count Yes integer Minimum: 0
meta.hasMore Yes boolean —
meta.nextCursor No string —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Read one canonical execution receipt projection#

GET /receipts/{id}

Operation ID: getExecutionReceiptV2

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with receipts:read (serviceCredential)

Service scope: receipts:read. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
id path Yes string —

Responses#

Status Description Content type and schema
200 Receipt projection application/json: object
404 Not found or not yet included No response body declared

200 response headers

Header Required Type Description and constraints
ETag Yes string —

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes ExecutionReceiptV2 —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

List signed passports and content-addressed proof artifacts#

GET /proof

Operation ID: listProofV2

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with proof:read (serviceCredential)

Service scope: proof:read. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
cursor query No string Opaque cursor returned in the previous response metadata.
limit query No integer Default: 50; Minimum: 1; Maximum: 100

Responses#

Status Description Content type and schema
200 Cursor-paginated proof resources application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes Array of ProofResource —
meta Yes object Additional properties rejected
meta.count Yes integer Minimum: 0
meta.hasMore Yes boolean —
meta.nextCursor No string —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Immediately revoke a published passport without deleting signed evidence#

POST /passports/{id}/revoke

Operation ID: revokeLiquidityPassport

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
Idempotency-Key header Yes string Min length: 8; Max length: 160
x-klineo-organization-id header Yes string —
id path Yes string —
If-Match header Yes string Pattern: ^"[^"\\ ]+"$

Request body#

Required: yes.

application/json

object — Additional properties rejected

Field Required at this level Type Description and constraints
reason Yes string Min length: 3; Max length: 500

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Responses#

Status Description Content type and schema
200 Append-only revoked passport generation application/json: object
409 Passport is not active No response body declared
412 Strong precondition failed No response body declared

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes All of: RecordEnvelope; object —
data.allOf[2].payload Yes LiquidityPassport —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Verify an issuer-disclosed signed Liquidity Passport#

GET /public/passports/{slug}

Operation ID: getPublicLiquidityPassport

Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

Parameters#

Name Location Required Type Description and constraints
slug path Yes string —

Responses#

Status Description Content type and schema
200 Canonical public passport application/json: object
404 Not published, revoked, or expired No response body declared

200 response headers

Header Required Type Description and constraints
ETag Yes string —

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes PublicPassportResult —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Download deterministic signed JSON, HTML, PDF, or CSV#

GET /public/passports/{slug}/formats/{format}

Operation ID: downloadPublicLiquidityPassport

Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

Parameters#

Name Location Required Type Description and constraints
slug path Yes string —
format path Yes string Allowed: json, html, pdf, csv

Responses#

Status Description Content type and schema
200 Content-addressed passport artifact application/json: LiquidityPassport; text/html: string; application/pdf: string; text/csv: string
404 Not published, revoked, expired, or trust anchor disabled No response body declared

200 response headers

Header Required Type Description and constraints
Content-Disposition Yes string —
X-KlineO-Passport-Hash Yes Hash —
X-KlineO-Artifact-Hash Yes Hash —
X-KlineO-Signature-Algorithm Yes Constant Ed25519 —
X-KlineO-Signer-Key-Version Yes Hash —

200 text/html body

string — Format: binary

200 application/pdf body

string — Format: binary

200 text/csv body

string — Format: binary

Download canonical passport, trust anchor, artifact hashes, and registry commitment#

GET /public/passports/{slug}/verification-bundle

Operation ID: downloadLiquidityPassportVerificationBundle

Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

Parameters#

Name Location Required Type Description and constraints
slug path Yes string —

Responses#

Status Description Content type and schema
200 Verification bundle application/json: LiquidityPassportVerificationBundle
404 Passport unavailable No response body declared

Read a non-revoked study share#

GET /public/studies/{slug}

Operation ID: getSharedSimulationStudy

Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

Parameters#

Name Location Required Type Description and constraints
slug path Yes string —

Responses#

Status Description Content type and schema
200 Disclosed study artifact application/json: object
404 Not published, revoked, or expired No response body declared

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes SharedSimulationStudy —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.