# Treasury custody and project control

Paths on this page are relative to <code>/api/liquidity-studio/v2</code>. Authentication and required headers vary by operation.

[API reference overview](/api-reference/overview/) · [OpenAPI download](/openapi/liquidity-operating-system-v2.openapi.json)

## Operations on this page

| Method | Path | Operation |
| --- | --- | --- |
| <code>GET</code> | <code>/treasury/custody-evidence</code> | [listTreasuryCustodyEvidence](#listTreasuryCustodyEvidence) |
| <code>POST</code> | <code>/treasury/custody-evidence</code> | [admitTreasuryCustodyEvidence](#admitTreasuryCustodyEvidence) |
| <code>GET</code> | <code>/treasury/custody-evidence/{evidenceId}</code> | [getTreasuryCustodyEvidence](#getTreasuryCustodyEvidence) |
| <code>POST</code> | <code>/treasury/project-control/challenges</code> | [issueProjectControlChallenge](#issueProjectControlChallenge) |
| <code>GET</code> | <code>/treasury/project-control/challenges/{nonce}</code> | [getProjectControlChallenge](#getProjectControlChallenge) |
| <code>POST</code> | <code>/treasury/project-control/proofs</code> | [acceptProjectControlProof](#acceptProjectControlProof) |

<a id="listTreasuryCustodyEvidence"></a>

## listTreasuryCustodyEvidence

`GET /treasury/custody-evidence`

Operation ID: <code>listTreasuryCustodyEvidence</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>)

Interactive current workspace membership required. Evidence is a historical finalized balance observation, not current spendable funds or financial permission. New admission requires separately provisioned current project/custody and provider authorities and configured independent RPC verification. Signed evidenceId is the tenant-scoped exact-content replay identity; callers cannot supply verification receipts.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>cursor</code> | query | No | <code>string</code> | Pattern: <code>^&#91;a-zA-Z0-9&#93;&#91;a-zA-Z0-9:&#95;-&#93;{2,159}$</code> |
| <code>limit</code> | query | No | <code>integer</code> | Default: <code>20</code>; Minimum: <code>1</code>; Maximum: <code>20</code> |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Authorized historical custody evidence; spendability is not established. | <code>application/json</code>: <code>object</code> |
| <code>400</code> | Invalid closed request. | <code>application/json</code>: <code>object</code> |
| <code>401</code> | Interactive session and recent authentication for admission required. | <code>application/json</code>: <code>object</code> |
| <code>403</code> | Current workspace role required. | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Evidence unavailable in this workspace. | <code>application/json</code>: <code>object</code> |
| <code>429</code> | Request limit exceeded. | <code>application/json</code>: <code>object</code> |
| <code>503</code> | Storage or verification unavailable. | <code>application/json</code>: <code>object</code> |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [TreasuryEvidenceList](/api-reference/schemas/treasury-evidence-list/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>400</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>400</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>401</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>401</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>403</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>403</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>404</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>404</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>429</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>429</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>503</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>503</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="admitTreasuryCustodyEvidence"></a>

## admitTreasuryCustodyEvidence

`POST /treasury/custody-evidence`

Operation ID: <code>admitTreasuryCustodyEvidence</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>)

Interactive current workspace membership required. Evidence is a historical finalized balance observation, not current spendable funds or financial permission. New admission requires separately provisioned current project/custody and provider authorities and configured independent RPC verification. Signed evidenceId is the tenant-scoped exact-content replay identity; callers cannot supply verification receipts.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |

### Request body

Required: **yes**.

**<code>application/json</code>**

[SignedTreasuryEvidence](/api-reference/schemas/signed-treasury-evidence/)

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Authorized historical custody evidence; spendability is not established. | <code>application/json</code>: <code>object</code> |
| <code>201</code> | Authorized historical custody evidence; spendability is not established. | <code>application/json</code>: <code>object</code> |
| <code>400</code> | Invalid closed request. | <code>application/json</code>: <code>object</code> |
| <code>401</code> | Interactive session and recent authentication for admission required. | <code>application/json</code>: <code>object</code> |
| <code>403</code> | Current workspace role required. | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Evidence unavailable in this workspace. | <code>application/json</code>: <code>object</code> |
| <code>409</code> | Evidence identity already binds different signed content. | <code>application/json</code>: <code>object</code> |
| <code>412</code> | Current authority changed or expired. | <code>application/json</code>: <code>object</code> |
| <code>429</code> | Request limit exceeded. | <code>application/json</code>: <code>object</code> |
| <code>503</code> | Storage or verification unavailable. | <code>application/json</code>: <code>object</code> |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |
| <code>ETag</code> | Yes | <code>string</code> | Pattern: <code>^"0x&#91;0-9a-f&#93;{64}"$</code> |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [TreasuryEvidenceWrite](/api-reference/schemas/treasury-evidence-write/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>201</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |
| <code>ETag</code> | Yes | <code>string</code> | Pattern: <code>^"0x&#91;0-9a-f&#93;{64}"$</code> |

**<code>201</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [TreasuryEvidenceWrite](/api-reference/schemas/treasury-evidence-write/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>400</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>400</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>401</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>401</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>403</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>403</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>404</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>404</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>409</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>409</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>412</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>412</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>429</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>429</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>503</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>503</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="getTreasuryCustodyEvidence"></a>

## getTreasuryCustodyEvidence

`GET /treasury/custody-evidence/{evidenceId}`

Operation ID: <code>getTreasuryCustodyEvidence</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>)

Interactive current workspace membership required. Evidence is a historical finalized balance observation, not current spendable funds or financial permission. New admission requires separately provisioned current project/custody and provider authorities and configured independent RPC verification. Signed evidenceId is the tenant-scoped exact-content replay identity; callers cannot supply verification receipts.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>evidenceId</code> | path | Yes | <code>string</code> | Pattern: <code>^&#91;a-zA-Z0-9&#93;&#91;a-zA-Z0-9:&#95;-&#93;{2,159}$</code> |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Authorized historical custody evidence; spendability is not established. | <code>application/json</code>: <code>object</code> |
| <code>400</code> | Invalid closed request. | <code>application/json</code>: <code>object</code> |
| <code>401</code> | Interactive session and recent authentication for admission required. | <code>application/json</code>: <code>object</code> |
| <code>403</code> | Current workspace role required. | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Evidence unavailable in this workspace. | <code>application/json</code>: <code>object</code> |
| <code>429</code> | Request limit exceeded. | <code>application/json</code>: <code>object</code> |
| <code>503</code> | Storage or verification unavailable. | <code>application/json</code>: <code>object</code> |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |
| <code>ETag</code> | Yes | <code>string</code> | Pattern: <code>^"0x&#91;0-9a-f&#93;{64}"$</code> |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [PersistedTreasuryEvidence](/api-reference/schemas/persisted-treasury-evidence/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>400</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>400</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>401</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>401</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>403</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>403</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>404</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>404</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>429</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>429</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>503</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>503</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="issueProjectControlChallenge"></a>

## issueProjectControlChallenge

`POST /treasury/project-control/challenges`

Operation ID: <code>issueProjectControlChallenge</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>)

Current interactive owner or treasury administrator only. Mutations require recent authentication. The server verifies a separately provisioned identity publisher and both controller/custody signatures against fresh canonical finalized chain state. Challenge nonce, actor and source identities are server bound. Acceptance consumes the nonce atomically and rechecks current authority. No spending, public disclosure, or paid entitlement is granted.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>Idempotency-Key</code> | header | Yes | <code>string</code> | Pattern: <code>^&#91;&#92;x21-&#92;x7E&#93;+$</code>; Min length: <code>8</code>; Max length: <code>200</code> |

### Request body

Required: **yes**.

**<code>application/json</code>**

[ProjectControlIssue](/api-reference/schemas/project-control-issue/)

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Private actor-bound proof record. Grants no financial or publication authority. | <code>application/json</code>: <code>object</code> |
| <code>201</code> | Private actor-bound proof record. Grants no financial or publication authority. | <code>application/json</code>: <code>object</code> |
| <code>400</code> | Invalid canonical input or required request key. | <code>application/json</code>: <code>object</code> |
| <code>401</code> | Interactive session and recent authentication for mutations required. | <code>application/json</code>: <code>object</code> |
| <code>403</code> | Current workspace treasury role required. | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Actor-bound challenge unavailable. | <code>application/json</code>: <code>object</code> |
| <code>409</code> | Request key or consumed nonce binds different content. | <code>application/json</code>: <code>object</code> |
| <code>412</code> | Challenge expired or current project/publisher authority changed. | <code>application/json</code>: <code>object</code> |
| <code>429</code> | Request limit exceeded. | <code>application/json</code>: <code>object</code> |
| <code>503</code> | Verification or storage unavailable. | <code>application/json</code>: <code>object</code> |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |
| <code>ETag</code> | Yes | <code>string</code> | Pattern: <code>^"0x&#91;0-9a-f&#93;{64}"$</code> |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [ProjectControlChallengeWrite](/api-reference/schemas/project-control-challenge-write/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>201</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |
| <code>ETag</code> | Yes | <code>string</code> | Pattern: <code>^"0x&#91;0-9a-f&#93;{64}"$</code> |

**<code>201</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [ProjectControlChallengeWrite](/api-reference/schemas/project-control-challenge-write/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>400</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>400</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>401</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>401</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>403</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>403</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>404</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>404</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>409</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>409</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>412</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>412</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>429</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>429</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>503</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>503</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="getProjectControlChallenge"></a>

## getProjectControlChallenge

`GET /treasury/project-control/challenges/{nonce}`

Operation ID: <code>getProjectControlChallenge</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>)

Current interactive owner or treasury administrator only. Mutations require recent authentication. The server verifies a separately provisioned identity publisher and both controller/custody signatures against fresh canonical finalized chain state. Challenge nonce, actor and source identities are server bound. Acceptance consumes the nonce atomically and rechecks current authority. No spending, public disclosure, or paid entitlement is granted.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>nonce</code> | path | Yes | <code>string</code> | Pattern: <code>^0x&#91;0-9a-f&#93;{64}$</code> |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Private actor-bound proof record. Grants no financial or publication authority. | <code>application/json</code>: <code>object</code> |
| <code>400</code> | Invalid canonical input or required request key. | <code>application/json</code>: <code>object</code> |
| <code>401</code> | Interactive session and recent authentication for mutations required. | <code>application/json</code>: <code>object</code> |
| <code>403</code> | Current workspace treasury role required. | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Actor-bound challenge unavailable. | <code>application/json</code>: <code>object</code> |
| <code>409</code> | Request key or consumed nonce binds different content. | <code>application/json</code>: <code>object</code> |
| <code>412</code> | Challenge expired or current project/publisher authority changed. | <code>application/json</code>: <code>object</code> |
| <code>429</code> | Request limit exceeded. | <code>application/json</code>: <code>object</code> |
| <code>503</code> | Verification or storage unavailable. | <code>application/json</code>: <code>object</code> |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |
| <code>ETag</code> | Yes | <code>string</code> | Pattern: <code>^"0x&#91;0-9a-f&#93;{64}"$</code> |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [PersistedProjectControlChallenge](/api-reference/schemas/persisted-project-control-challenge/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>400</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>400</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>401</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>401</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>403</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>403</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>404</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>404</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>409</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>409</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>412</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>412</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>429</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>429</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>503</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>503</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="acceptProjectControlProof"></a>

## acceptProjectControlProof

`POST /treasury/project-control/proofs`

Operation ID: <code>acceptProjectControlProof</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>)

Current interactive owner or treasury administrator only. Mutations require recent authentication. The server verifies a separately provisioned identity publisher and both controller/custody signatures against fresh canonical finalized chain state. Challenge nonce, actor and source identities are server bound. Acceptance consumes the nonce atomically and rechecks current authority. No spending, public disclosure, or paid entitlement is granted.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |

### Request body

Required: **yes**.

**<code>application/json</code>**

[ProjectControlProof](/api-reference/schemas/project-control-proof/)

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Private actor-bound proof record. Grants no financial or publication authority. | <code>application/json</code>: <code>object</code> |
| <code>201</code> | Private actor-bound proof record. Grants no financial or publication authority. | <code>application/json</code>: <code>object</code> |
| <code>400</code> | Invalid canonical input or required request key. | <code>application/json</code>: <code>object</code> |
| <code>401</code> | Interactive session and recent authentication for mutations required. | <code>application/json</code>: <code>object</code> |
| <code>403</code> | Current workspace treasury role required. | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Actor-bound challenge unavailable. | <code>application/json</code>: <code>object</code> |
| <code>409</code> | Request key or consumed nonce binds different content. | <code>application/json</code>: <code>object</code> |
| <code>412</code> | Challenge expired or current project/publisher authority changed. | <code>application/json</code>: <code>object</code> |
| <code>429</code> | Request limit exceeded. | <code>application/json</code>: <code>object</code> |
| <code>503</code> | Verification or storage unavailable. | <code>application/json</code>: <code>object</code> |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |
| <code>ETag</code> | Yes | <code>string</code> | Pattern: <code>^"0x&#91;0-9a-f&#93;{64}"$</code> |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [ProjectControlAcceptance](/api-reference/schemas/project-control-acceptance/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>201</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |
| <code>ETag</code> | Yes | <code>string</code> | Pattern: <code>^"0x&#91;0-9a-f&#93;{64}"$</code> |

**<code>201</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [ProjectControlAcceptance](/api-reference/schemas/project-control-acceptance/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>400</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>400</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>401</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>401</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>403</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>403</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>404</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>404</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>409</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>409</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>412</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>412</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>429</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>429</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

**<code>503</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Cache-Control</code> | Yes | Constant <code>private, no-store</code> | — |

**<code>503</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>error</code> | Yes | [ApiError](/api-reference/schemas/api-error/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
