Anchorage Digital Addresses API

These endpoints allow the user to create and retrieve deposit addresses for specific assets. # Verifying Deposit Addresses The addresses REST API endpoints return signatures of the address strings and other metadata that prove the address was generated by Anchorage Digital for your organization. It is critical that clients verify the address signature and any accompanying metadata before the address is used, to confirm the address authenticity and integrity. ## Address Signature Schemes The API supports two address verification schemes: - **V1 Address Signatures** - The original scheme involves verifying a signature against a public key that is unique to each organization. This public key remains fixed for the lifetime of the organization and is distributed on request by Anchorage Digital out-of-band. While the public key does not need to be kept confidential, it must be kept tamper-proof. - **V2 Address Signatures** - The newer scheme involves verifying a signature against the public key of the leaf certificate of a X509 certificate chain returned alongside the signature, and verifying the certificate chain itself against the Anchorage Digital Address Signing Root CA, provided below, which must be hard-coded by API clients. You can determine which scheme an address uses by checking the `signatureVersion` field. ## V1 Address Signature Verification The steps for verifying V1 address signatures are as follows: 1. Check the validity of the signature: a. Decode the `addressSignaturePayload` field from hex to bytes. b. Decode the `signature` field from hex to bytes. c. Using the fixed public key for this organization, verify that `signatureBytes` is a valid Ed25519 signature of the `addressSignaturePayloadBytes`. 2. Verify the signed address matches the address to be used: a. Decode the `addressSignaturePayload` field from hex to bytes. b. Parse the bytes as a JSON object. c. Verify the address to be used matches the value of the `TextAddress` property from the JSON object. **Note: It is not sufficient to validate the signature without also validating that the address contained in the JSON decoded from the `addressSignaturePayload` matches the address to be used.** ### V1 Signed Payload Fields - `TextAddress` — The text format of the on-chain address. ```json { "TextAddress": "2N19AcihQ1a4MxQW658UFHTioUNnMkiHPkw" } ``` ### Sample V1 validation code: ```go package main import ( "crypto/ed25519" "encoding/hex" "encoding/json" "fmt" ) // V1SignedPayload represents the JSON structure in the addressSignaturePayload for V1 signatures type V1SignedPayload struct { TextAddress string `json:"TextAddress"` } // verifyV1AddressSignature verifies a V1 address signature. // // Parameters: // - address: The address string from the API response // - addressSignaturePayload: Hex-encoded bytes that were signed // - signature: Hex-encoded Ed25519 signature // - orgPublicKeyHex: Hex-encoded Ed25519 public key for your organization (obtained out-of-band) // // Returns an error if verification fails. func verifyV1AddressSignature(address, addressSignaturePayload, signature, orgPublicKeyHex string) error { // Step 1: Check the validity of the signature // Decode the addressSignaturePayload from hex to bytes payloadBytes, err := hex.DecodeString(addressSignaturePayload) if err != nil { return fmt.Errorf("failed to decode addressSignaturePayload: %w", err) } // Decode the signature from hex to bytes signatureBytes, err := hex.DecodeString(signature) if err != nil { return fmt.Errorf("failed to decode signature: %w", err) } // Decode the organization public key from hex publicKeyBytes, err := hex.DecodeString(orgPublicKeyHex) if err != nil { return fmt.Errorf("failed to decode organization public key: %w", err) } if len(publicKeyBytes) != ed25519.PublicKeySize { return fmt.Errorf("invalid public key size: got %d bytes, expected %d", len(publicKeyBytes), ed25519.PublicKeySize) } publicKey := ed25519.PublicKey(publicKeyBytes) // Verify the Ed25519 signature if !ed25519.Verify(publicKey, payloadBytes, signatureBytes) { return fmt.Errorf("signature verification failed") } // Step 2: Verify the signed address matches the address to be used // Parse the payload bytes as JSON var signedPayload V1SignedPayload if err := json.Unmarshal(payloadBytes, &signedPayload); err != nil { return fmt.Errorf("failed to parse signed payload: %w", err) } // Verify the TextAddress matches if signedPayload.TextAddress != address { return fmt.Errorf("signed TextAddress does not match: signed=%q, expected=%q", signedPayload.TextAddress, address) } return nil } func main() { // Sample API response data address := "2N19AcihQ1a4MxQW658UFHTioUNnMkiHPkw" addressSignaturePayload := "7b225465787441646472657373223a22324e313941636968513161344d78515736353855464854696f554e6e4d6b6948506b77227d" signature := "b18f6848dc0fef01a069e7ac26046383bf5cd130203994dc2d72b5a9097351b1e8b67115b63124fbc8c16673566416a635913c670b676089339c62a7824baa03" // Organization public key - obtained out-of-band from Anchorage Digital beforehand // Unique per Organization, fixed for the lifetime of that Organization // Must be kept tamper-proof orgPublicKeyHex := "8a88e3dd7409f195fd52db2d3cba5d72ca6709bf1d94121bf3748801b40f6f5c" // Verify the signature if err := verifyV1AddressSignature(address, addressSignaturePayload, signature, orgPublicKeyHex); err != nil { fmt.Printf("✗ V1 Address signature verification failed: %v\n", err) return } fmt.Println("✓ V1 Address signature verified successfully!") fmt.Printf(" Address: %s\n", address) fmt.Println("\nYou may now safely use this address for deposits.") } ``` ## V2 Address Signature Verification Addresses returned with `signatureVersion` set to `V2` also include a `certChain` field containing an x509 certificate chain in PEM format. The steps for verifying V2 address signatures are as follows: 1. Verify the certificate chain: a. Parse the `certChain` field as PEM-encoded x509 certificates **Note: The leaf certificate is at the 0th index, followed by zero or more intermediate certificates. The root cert is excluded from this response. The number of certificates in the chain is subject to change.** b. Verify the certificate chain from the leaf to the trusted Anchorage Digital Root CA. c. Verify all certificates are valid at the current time (both notAfter and notBefore). d. Verify the leaf certificate's Subject Alternative Names include `address-provider.anchorage.internal`. e. Verify the leaf certificate's KeyUsage includes both `digitalSignature` and `nonRepudiation` (also known as `contentCommitment`). f. Extract the public key from the leaf certificate. Currently, we only support ed25519 keys, however this is subject to change the future. 2. Verify the signature: a. Decode the `addressSignaturePayload` field from hex to bytes b. Decode the `signature` field from hex to bytes c. Using the public key from the leaf certificate, verify that `signatureBytes` is a valid signature of the `addressSignaturePayload` bytes. 3. Verify the signed details: a. Parse the `addressSignaturePayload` bytes as a JSON object b. Verify `SignatureExpiresAt` is greater or equal to the current UTC Unix Timestamp c. Verify `TextAddress` matches the address to be used d. Verify `VaultId` matches your expected Vault ID e. Verify `NetworkId` matches the expected network for this address **Note: The signed payload also includes a `NetworkName` field for human-readable purposes, which does not need to be verified.** **Note: API clients must not use "strict" JSON parsers which will disallow extra properties, as future versions may introduce additional fields.** **Note: Anchorage Digital will periodically refresh V2 signatures and our Address Signing Root CA before expiration. The deposit address itself will not change. Only the signature, certificate chain and Root CA will be updated.** ### V2 Signed Payload Fields - `TextAddress` — The text format of the on-chain address. - `VaultId` — Identifies the vault this address belongs to. - `NetworkId` — Identifies the network that this address can receive deposits on. - `NetworkName` — A human readable version of the `NetworkId`. - `SignatureExpiresAt` — The time after which the signature should not be trusted. ```json { "VaultId": "dae6089e7c0836705f0562af0f1e4e1f", "TextAddress": "bcrt1q709skemgf5skpsnysvgme2s3ztehkutl390yl0wp29lnmum5uw7qg0qrwm", "NetworkName": "Bitcoin Regnet", "NetworkId": "BTC_R", "SignatureExpiresAt": 1769450713 } ``` ### Anchorage Digital Address Signing Root CAs Clients are encouraged to hard-code the appropriate Root CA value for the environment they are making API requests against. It is essential that this value be tamper-proof. - Production Environment: ``` -----BEGIN CERTIFICATE----- MIIBXTCCAQ+gAwIBAgIUQZI+MSvYTXQHra+3OAKnwAMzotUwBQYDK2VwMCAxHjAcBgNVBAMMFWNhLmFuY2hvcmFnZS5pbnRlcm5hbDAeFw0yNjAxMjYwMDAwMDBaFw0yNzAxMjYwMDAwMDBaMCAxHjAcBgNVBAMMFWNhLmFuY2hvcmFnZS5pbnRlcm5hbDAqMAUGAytlcAMhADTh1nctgIHtAKNW8ww/bY606pJ3OP2dyZYcQrU2kG5jo1swWTAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwICBDAUBgorBgEEAYaNHwEBBAYWBHJvb3QwIAYDVR0RBBkwF4IVY2EuYW5jaG9yYWdlLmludGVybmFsMAUGAytlcANBANkkdudEjH9RTKbRAxrRXyMSS/TgmdSrAVYOZzoRDJlyc+5oD+a0pmmwWVe86xZi37YbN1GzVlXcJAPpV6ceEQU= -----END CERTIFICATE----- ``` - Staging Environment: ``` -----BEGIN CERTIFICATE----- MIIBXDCCAQ6gAwIBAgITOfTQ4rYUsghgvdl8YCJSC67uGDAFBgMrZXAwIDEeMBwGA1UEAwwVY2EuYW5jaG9yYWdlLmludGVybmFsMB4XDTI2MDEyNDAwMDAwMFoXDTI3MDEyNDAwMDAwMFowIDEeMBwGA1UEAwwVY2EuYW5jaG9yYWdlLmludGVybmFsMCowBQYDK2VwAyEAPlBo2/+kPPL0WRpT+B/yHsU25AN/M6HP2bzC61yHb4ajWzBZMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgIEMBQGCisGAQQBho0fAQEEBhYEcm9vdDAgBgNVHREEGTAXghVjYS5hbmNob3JhZ2UuaW50ZXJuYWwwBQYDK2VwA0EAYsJxVI9n42liCF9f+Ou7uuC1QGFwaHwFsfOm0WFofSlE1trWqzj4ruzjPYSRJc8Ht2A7XCAfXkG0mzKpL/wQDg== -----END CERTIFICATE----- ``` ### Sample V2 validation code: ```go package main import ( "crypto/ed25519" "crypto/x509" "encoding/hex" "encoding/json" "encoding/pem" "fmt" "time" ) // V2SignedPayload represents the JSON structure in the addressSignaturePayload for V2 signatures type V2SignedPayload struct { TextAddress string `json:"TextAddress"` VaultId string `json:"VaultId"` NetworkId string `json:"NetworkId"` NetworkName string `json:"NetworkName"` SignatureExpiresAt int64 `json:"SignatureExpiresAt"` // Unix timestamp } // verifyV2AddressSignature verifies a V2 address signature. // // Parameters: // - now: The "current" time. Note that conforming implementations must use // a trusted source for the current time. // - address: The address string from the API response // - addressSignaturePayload: Hex-encoded bytes that were signed // - signature: Hex-encoded signature // - certChainPEM: PEM-encoded certificate chain (leaf first, then intermediates) // - rootCAPEM: PEM-encoded Root CA certificate (hard-coded by client) // - expectedVaultId: Your Vault ID to verify against the signed VaultId // - expectedNetworkId: Expected network ID for this address (e.g., "BTC", "ETH") // // Returns an error if verification fails. func verifyV2AddressSignature( now time.Time, address, addressSignaturePayload, signature, certChainPEM, rootCAPEM, expectedVaultId, expectedNetworkId string, ) error { // Step 1: Verify the certificate chain // Parse the certificate chain from PEM certs, err := parsePEMCertificates([]byte(certChainPEM)) if err != nil { return fmt.Errorf("failed to parse certificate chain: %w", err) } if len(certs) == 0 { return fmt.Errorf("certificate chain is empty") } leafCert := certs[0] var intermediateCerts []*x509.Certificate if len(certs) > 1 { intermediateCerts = certs[1:] } // Parse the Root CA rootCACerts, err := parsePEMCertificates([]byte(rootCAPEM)) if err != nil { return fmt.Errorf("failed to parse Root CA: %w", err) } if len(rootCACerts) != 1 { return fmt.Errorf("expected exactly one Root CA certificate, got %d", len(rootCACerts)) } rootCA := rootCACerts[0] // Verify the leaf certificate's KeyUsage includes both // digitalSignature and nonRepudiation (AKA contentCommitment) if leafCert.KeyUsage&x509.KeyUsageDigitalSignature == 0 { return fmt.Errorf("leaf certificate KeyUsage missing DigitalSignature") } if leafCert.KeyUsage&x509.KeyUsageContentCommitment == 0 { return fmt.Errorf("leaf certificate KeyUsage missing NonRepudiation (ContentCommitment)") } // Verify the certificate chain from leaf to Root CA roots := x509.NewCertPool() roots.AddCert(rootCA) intermediates := x509.NewCertPool() for _, cert := range intermediateCerts { intermediates.AddCert(cert) } // NOTE: Not all x509 libraries are created equal and are not // guaranteed to verify exactly the same things! // // Always review the library you plan to use and ensure it covers the // checks described in the User Guide! // // For example, the Go implementation checks all Certificates for // temporal validity (notBefore and notAfter against CurrentTime), for // valid signatures up the chain, and checks that the Subject // Alternative Names include the values in DNSNames below. // // However it does not check the KeyUsage bits, hence the additional // checks above. opts := x509.VerifyOptions{ DNSNames: []string{"address-provider.anchorage.internal"}, Roots: roots, Intermediates: intermediates, CurrentTime: now, // NOTE: This allows for any Extended Key Usage, but does not // check the Key Usage bits, hence the additional checks above. KeyUsages: []x509.ExtKeyUsage{x509.ExtKeyUsageAny}, } if _, err := leafCert.Verify(opts); err != nil { return fmt.Errorf("certificate chain verification failed: %w", err) } // Extract the public key from the leaf certificate leafPublicKey, ok := leafCert.PublicKey.(ed25519.PublicKey) if !ok { return fmt.Errorf("leaf certificate does not use Ed25519 (got type %T)", leafCert.PublicKey) } // Step 2: Verify the signature // Decode the addressSignaturePayload from hex to bytes payloadBytes, err := hex.DecodeString(addressSignaturePayload) if err != nil { return fmt.Errorf("failed to decode addressSignaturePayload: %w", err) } // Decode the signature from hex to bytes signatureBytes, err := hex.DecodeString(signature) if err != nil { return fmt.Errorf("failed to decode signature: %w", err) } // Verify the signature using the leaf certificate's public key if !ed25519.Verify(leafPublicKey, payloadBytes, signatureBytes) { return fmt.Errorf("signature verification failed") } // Step 3: Verify the signed details // Parse the payload bytes as JSON var signedPayload V2SignedPayload if err := json.Unmarshal(payloadBytes, &signedPayload); err != nil { return fmt.Errorf("failed to parse signed payload: %w", err) } // Verify SignatureExpiresAt is not in the past if now.Unix() > signedPayload.SignatureExpiresAt { expiryTime := time.Unix(signedPayload.SignatureExpiresAt, 0) return fmt.Errorf("signature has expired at %s", expiryTime) } // Verify TextAddress matches if signedPayload.TextAddress != address { return fmt.Errorf("signed TextAddress does not match: signed=%q, expected=%q", signedPayload.TextAddress, address) } // Verify VaultId matches if signedPayload.VaultId != expectedVaultId { return fmt.Errorf("signed VaultId does not match: signed=%q, expected=%q", signedPayload.VaultId, expectedVaultId) } // Verify NetworkId matches if signedPayload.NetworkId != expectedNetworkId { return fmt.Errorf("signed NetworkId does not match: signed=%q, expected=%q", signedPayload.NetworkId, expectedNetworkId) } return nil } // parsePEMCertificates parses PEM-encoded certificates and returns them as a slice func parsePEMCertificates(pemData []byte) ([]*x509.Certificate, error) { var certs []*x509.Certificate for { block, rest := pem.Decode(pemData) if block == nil { break } if block.Type != "CERTIFICATE" { pemData = rest continue } cert, err := x509.ParseCertificate(block.Bytes) if err != nil { return nil, fmt.Errorf("failed to parse certificate: %w", err) } certs = append(certs, cert) pemData = rest } return certs, nil } func main() { // Sample API response data address := "bcrt1q709skemgf5skpsnysvgme2s3ztehkutl390yl0wp29lnmum5uw7qg0qrwm" addressSignaturePayload := "7b225661756c744964223a226461653630383965376330383336373035663035363261663066316534653166222c225465787441646472657373223a22626372743171373039736b656d676635736b70736e797376676d653273337a7465686b75746c333930796c30777032396c6e6d756d357577377167307172776d222c224e6574776f726b4e616d65223a22426974636f696e205265676e6574222c224e6574776f726b4964223a224254435f52222c225369676e6174757265457870697265734174223a313736393435303731337d" signature := "951eb2fb560e660aa9c3d1ccd120d3ad1a19d90d8747347057e48bf174330eb386089e3232d822fd66b8183cce8059c91183afde299b920a0e0c05c5b167360e" certChainPEM := `-----BEGIN CERTIFICATE----- MIIBYTCCAROgAwIBAgIUMLKt+K9eFku+P7BbefE1xAHg0hcwBQYDK2VwMAAwHhcNMjYwMTI2MTcwNDEzWhcNMjcwMTI2MTcwNTEzWjAuMSwwKgYDVQQDEyNhZGRyZXNzLXByb3ZpZGVyLmFuY2hvcmFnZS5pbnRlcm5hbDAqMAUGAytlcAMhAPsgM70aWFYsZaLHawtYJpl42BkiTLyCq96+OXe4FxrVo3EwbzAOBgNVHQ8BAf8EBAMCBsAwDAYDVR0TAQH/BAIwADAfBgNVHSMEGDAWgBS0usSFeB2gjC+wcowtxN3MeKSH7zAuBgNVHREEJzAlgiNhZGRyZXNzLXByb3ZpZGVyLmFuY2hvcmFnZS5pbnRlcm5hbDAFBgMrZXADQQCXmvIkuPnUgCHxWmFmzvgWdv9lUlt84oZCel+OeJW9n8PR88tGxAcD1E3+KDBXVpO0GcRA0W9+xqqICAo2ROEJ -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- MIIBKDCB26ADAgECAhRGsD05KldIse+uIEa976AijTqlxjAFBgMrZXAwADAeFw0yNjAxMjYxNzA0MTNaFw0yNzAxMjYxNzA1MTNaMAAwKjAFBgMrZXADIQCNpyY5Sr21FHNvvLkBKG8AEMKdhqtajmV5d2QaZlmtAqNnMGUwDgYDVR0PAQH/BAQDAgIEMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFLS6xIV4HaCML7ByjC3E3cx4pIfvMCAGA1UdEQEB/wQWMBSCEmFuY2hvcmFnZS5pbnRlcm5hbDAFBgMrZXADQQCIgw6kLMIwhd3ACjG03cJ5z/ZZp8aXXycFq2ZC9TLhieJ3rncyMH6ZdyJ3Ai1eVaHs4vnDCv54Vdh83vvSky4K -----END CERTIFICATE----- ` // NOTE: This is a FAKE Root CA used just for this example. // NOTE: Conforming client implementations should hard-code the real // Anchorage Digital Address Signing Root CA for the environment they // are making requests to. rootCAPEM := `-----BEGIN CERTIFICATE----- MIIBGzCBzqADAgECAhQ2qQwArneTuF0dbNDs8i/ExuyW2DAFBgMrZXAwADAeFw0yNjAxMjYxNzA0MTNaFw0yNzAxMjYxNzA1MTNaMAAwKjAFBgMrZXADIQB+gEnytXKnuAMonIWGWnB0qyTqa0aw3l9u5VRbu86UgaNaMFgwDgYDVR0PAQH/BAQDAgIEMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFOj64tL1teJHkojsiblnnK34Tw+EMBYGA1UdEQEB/wQMMAqCCGludGVybmFsMAUGAytlcANBAAg2IcVEXmWKSivhUNSatNfMmASxi83QscIuyP/sIW2sRIuCqQJoo9lN6TaxzyV62cQMzthFOCZcgRE+k0JV7Ao= -----END CERTIFICATE----- ` // Your Vault ID - obtained from your application context expectedVaultId := "dae6089e7c0836705f0562af0f1e4e1f" // Expected network ID for this address expectedNetworkId := "BTC_R" // Implementations should use the actual current time // now := time.Now() now := time.Unix(1769450600, 0) // Fake time so that this example passes. // Verify the signature if err := verifyV2AddressSignature( now, address, addressSignaturePayload, signature, certChainPEM, rootCAPEM, expectedVaultId, expectedNetworkId, ); err != nil { fmt.Printf("✗ V2 Address signature verification failed: %v\n", err) return } fmt.Println("✓ V2 Address signature verified successfully!") fmt.Printf(" Address: %s\n", address) fmt.Printf(" Vault ID: %s\n", expectedVaultId) fmt.Printf(" Network: %s\n", expectedNetworkId) fmt.Println("\nYou may now safely use this address for deposits.") } ```

Operations 6

GET /vaults/{vaultId}/addresses List all addresses for an asset #
POST /wallets/{walletId}/addresses Provision a deposit address for a wallet #
GET /addresses List Addresses #
POST /batch/addresses Create Addresses Batch #
GET /batch/addresses/{batchId} Get Addresses Batch Status #
POST /addresses/validate-destination Validate Destination Address #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/anchorage-addresses-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

anchorage-addresses-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Anchorage Addresses API
  version: 2.0.0
  contact:
    email: api@anchorage.com
  description: 'Operations tagged Addresses across 2 of this provider''s published API definitions: anchorage-v2-openapi-original.yml, anchorage-v3-openapi-original.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://api.anchorage-staging.com/v2
- url: https://api.anchorage-staging.com/v3
security:
- Api-Access-Key: []
tags:
- description: These endpoints allow the user to create and retrieve deposit addresses for specific assets.
  name: Addresses
paths:
  /vaults/{vaultId}/addresses:
    get:
      operationId: getAddresses
      summary: List all addresses for an asset
      description: 'Permissions required: **Read vault activity** or **Create address**


        Get all addresses for the asset type within the specified `vaultId`.'
      parameters:
      - name: vaultId
        in: path
        description: The ID of the vault containing the asset type
        required: true
        schema:
          type: string
      - name: assetType
        in: query
        description: The asset type to display addresses for
        required: true
        schema:
          type: string
      - name: afterId
        in: query
        description: When paginating this is used to provide the starting point for the page to fetch (retrieved from the previous response body)
        schema:
          type: string
      - name: limit
        in: query
        description: Maximum number of results to return per query
        schema:
          type: integer
          format: int64
          default: 25
          maximum: 100
          minimum: 1
      responses:
        '200':
          description: List of signed addresses for this asset
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultsAddressesResponse'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '401':
          description: Unauthenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '429':
          description: Too Many Requests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
      tags:
      - Addresses
      x-security:
        Read vault activity: checkSourceVault
        Create address: checkSourceVault
    servers:
    - url: https://api.anchorage-staging.com/v2
  /wallets/{walletId}/addresses:
    post:
      operationId: provisionWalletAddress
      summary: Provision a deposit address for a wallet
      description: 'Permissions required: **Create address**


        This endpoint allows you to request an asynchronous provision of a signed deposit address for a given wallet. For UTXO-based wallets a new address will always be provisioned upon request. For account-based wallets only one address may be provisioned per wallet and subsequent attempts will return the previously provisioned address.


        Newly requested addresses may not be available for several minutes once requested.'
      parameters:
      - name: walletId
        in: path
        description: An ID uniquely identifying an Anchorage Digital wallet
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Provisioned address
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WalletsAddressesResponse'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '401':
          description: Unauthenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '422':
          description: Provision address in progress
          content:
            application/json:
              examples:
                response:
                  value:
                    errorType: UnprocessableEntity
                    message: An address for this wallet is being created and is not yet available. Please try again in 5 minutes.
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '429':
          description: Too Many Requests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails'
      tags:
      - Addresses
      x-security:
        Create address: checkSourceVault
    servers:
    - url: https://api.anchorage-staging.com/v2
  /addresses:
    get:
      operationId: listAddresses
      summary: List Addresses
      description: 'Permissions required: **Read vault activity**


        List all addresses across wallets in the organization.'
      parameters:
      - name: after
        in: query
        description: When paginating this is used to provide the starting point for the page to fetch (retrieved from the previous response body)
        schema:
          type: string
      - name: address
        in: query
        description: Filter by specific blockchain address
        required: false
        schema:
          type: string
      - name: networkId
        in: query
        description: A unique string identifying a combination of blockchain and environment (testnet, mainnet).
        required: false
        schema:
          type: string
      - name: vaultId
        in: query
        description: Filter by vault ID
        required: false
        schema:
          type: string
      - name: walletId
        in: query
        description: Filter by wallet ID
        required: false
        schema:
          type: string
      - name: batchId
        in: query
        description: Filter by batch creation ID
        required: false
        schema:
          type: string
      - name: publicKey
        in: query
        description: Filter by public key string
        required: false
        schema:
          type: string
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListAddressesResponse'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '401':
          description: Unauthenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '429':
          description: Too Many Requests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
      tags:
      - Addresses
    servers:
    - url: https://api.anchorage-staging.com/v3
  /batch/addresses:
    post:
      operationId: createAddressesBatch
      summary: Create Addresses Batch
      description: 'Permissions required: **Create addresses**


        Create multiple blockchain addresses in a single batch operation. This endpoint returns immediately with a batchId.

        Poll GET /batch/addresses/{batchId} to check the status and retrieve results once the batch is complete.'
      parameters: []
      requestBody:
        description: Batch address creation request
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateAddressesBatchRequest'
      responses:
        '202':
          description: Batch address creation initiated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateBatchResponse'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '401':
          description: Unauthenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '429':
          description: Too Many Requests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
      tags:
      - Addresses
    servers:
    - url: https://api.anchorage-staging.com/v3
  /batch/addresses/{batchId}:
    get:
      operationId: getAddressesBatchStatus
      summary: Get Addresses Batch Status
      description: 'Permissions required: **Read vault activity**


        Get the status and results of a batch address creation operation.'
      parameters:
      - name: batchId
        in: path
        description: The unique identifier for the batch operation
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BatchStatusResponse'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '401':
          description: Unauthenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '429':
          description: Too Many Requests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
      tags:
      - Addresses
    servers:
    - url: https://api.anchorage-staging.com/v3
  /addresses/validate-destination:
    post:
      operationId: validateDestinationAddress
      summary: Validate Destination Address
      description: 'Permissions required: **None**


        Validate that a given address for a given networkId is valid as a transfer destination.

        Returns 200 if the address is valid, or an invalid request error if it is not.'
      parameters: []
      requestBody:
        description: Destination address validation request
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ValidateDestinationAddressRequest'
      responses:
        '200':
          description: Address is valid as a transfer destination
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '401':
          description: Unauthenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '429':
          description: Too Many Requests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDetails_2'
      tags:
      - Addresses
    servers:
    - url: https://api.anchorage-staging.com/v3
components:
  schemas:
    SignedAddress:
      type: object
      properties:
        address:
          description: A crypto address for the intended asset
          type: string
          example: 2N19AcihQ1a4MxQW658UFHTioUNnMkiHPkw
        addressId:
          description: An id uniquely identifying an Anchorage Digital address.
          type: string
          example: a33f83d96ca95cac000a344aa478a8b8
        addressSignaturePayload:
          description: The hex-encoding of the bytes that were signed.
          type: string
          example: 7b225465787441646472657373223a22324e313941636968513161344d78515736353855464854696f554e6e4d6b6948506b77227d
        certChain:
          description: An x509 certificate chain in PEM format. When present, indicates that this address uses a V2 signature scheme where the signature is verified against the public key in the leaf certificate, and the certificate chain must verify up to a trusted Anchorage Digital Root CA. The Root CA is provided out-of-band. When absent, the signature is verified against the Organization Public Key (V1 signature scheme).
          type: string
          example: '-----BEGIN CERTIFICATE-----

            MIIBkTCCATigAwIBAgIQExample...

            -----END CERTIFICATE-----

            -----BEGIN CERTIFICATE-----

            MIIBkTCCATigAwIBAgIQExample...

            -----END CERTIFICATE-----

            '
        signature:
          description: A hex-encoded signature of the addressSignaturePayload
          type: string
          example: 1642000aa9cca8e8610981aefbdb204b361c9dca3fa067b88fdacfba7a0f620d721378a33f4bbadad3923e633a4d712646d1e8e314e9fcb4aa4102c0581f6503
        signatureVersion:
          description: The address signature scheme used for this address
          type: string
          example: V2
          enum:
          - V1
          - V2
        walletId:
          description: An ID uniquely identifying an Anchorage Digital wallet
          type: string
          example: a33f83d96ca95cac000a344aa478a8b8
      required:
      - address
      - addressId
      - addressSignaturePayload
      - signature
      title: SignedAddress
    VaultsAddressesResponse:
      type: object
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/SignedAddress'
        page:
          $ref: '#/components/schemas/Page'
      required:
      - data
      - page
      title: VaultsAddressesResponse
    WalletsAddressesResponse:
      type: object
      properties:
        data:
          $ref: '#/components/schemas/Data'
      required:
      - data
      title: WalletsAddressesResponse
    Result:
      type: string
      enum:
      - RETURNING_UNUSED_ADDRESS
      - RETURNING_USED_ADDRESS
      title: Result
    ErrorType:
      description: The type of error returned.
      type: string
      enum:
      - InternalError
      - InvalidRequest
      - Unauthenticated
      - Forbidden
      - NotFound
      - Conflict
      - UnprocessableEntity
      - TooManyRequests
      - ServiceUnavailable
      - QuoteExpired
      - InsufficientFunds
      - NotImplemented
      title: ErrorType
    Data:
      type: object
      properties:
        result:
          $ref: '#/components/schemas/Result'
        signedAddress:
          $ref: '#/components/schemas/SignedAddress'
      required:
      - result
      - signedAddress
      title: Data
    ErrorDetails:
      type: object
      properties:
        errorType:
          $ref: '#/components/schemas/ErrorType'
        message:
          description: A human-readable message providing more details about the error.
          type: string
          example: Missing required field 'amount'.
      required:
      - errorType
      - message
      title: ErrorDetails
    Page:
      description: Pagination info
      type: object
      properties:
        next:
          description: URL to use to query for the next page or null if no additional results are available
          type:
          - string
          - 'null'
          example: <next page url>
          x-omitempty: false
      title: Page
    ValidateDestinationAddressRequest:
      description: Request to validate an address as a transfer destination
      type: object
      properties:
        address:
          description: A unique string identifying an account on a blockchain. This is sometimes dervied from a public key and sometimes decided by the blockchain.
          type: string
        memo:
          description: Optional memo/tag/destination tag (required by some blockchain networks)
          type:
          - string
          - 'null'
          maxLength: 256
        networkId:
          description: A unique string identifying a combination of blockchain and environment (testnet, mainnet).
          type: string
      required:
      - address
      - networkId
    ListAddressesResponse:
      type: object
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/WalletAddress'
        page:
          $ref: '#/components/schemas/Page_2'
      required:
      - data
      - page
    Page_2:
      description: Pagination info
      type: object
      properties:
        endCursor:
          description: Submit this parameter in the "after" field to fetch the next page.
          type:
          - string
          - 'null'
      title: Page
    CreateAddressesBatchRequest:
      description: Request to create multiple addresses in a batch within a single wallet
      type: object
      properties:
        count:
          description: Number of addresses to create
          type: integer
          minimum: 1
        idempotencyKey:
          description: Client-provided idempotency key to ensure request is processed only once
          type: string
          example: e763a50d-aa82-4ec7-b5a3-89ad0462d248
          maxLength: 128
        walletId:
          description: The wallet ID in which to create addresses
          type: string
      additionalProperties: false
      required:
      - walletId
      - count
    WalletAddressSignatureVersion:
      description: 'Version of the address signature scheme used.


        * `V1` - The original scheme. Verify the `signature` against your organization''s fixed Ed25519 public key (provided by Anchorage Digital out-of-band).

        * `V2` - The newer scheme. Verify the `signature` against the leaf certificate''s public key from the `certChain` field, and verify the certificate chain against the Anchorage Digital Address Signing Root CA.'
      type: string
      enum:
      - V1
      - V2
    ErrorDetails_2:
      type: object
      properties:
        message:
          description: A human-readable message providing more details about the error.
          type: string
          example: Missing required field 'amount'.
      required:
      - message
      title: ErrorDetails
    BatchStatusResponse:
      description: Status of a batch operation
      type: object
      properties:
        batchId:
          description: The unique identifier for the batch operation
          type: string
        status:
          description: Overall status of the batch operation
          type: string
          enum:
          - PENDING
          - COMPLETED
          - FAILED
      required:
      - batchId
      - status
    CreateBatchResponse:
      description: Response from creating a batch operation
      type: object
      properties:
        batchId:
          description: The unique identifier for the batch operation. Poll the corresponding batch status endpoint to retrieve results.
          type: string
          example: batch_abc123xyz
      required:
      - batchId
    WalletAddress:
      description: "A blockchain address in a wallet. Each address includes a cryptographic signature that proves the address was generated by Anchorage Digital for your organization.\n\n## Signature Verification\n\nThe signature allows you to verify that an address string is authentic before using it for sensitive operations (like withdrawals to that address).\n\nCheck the `signatureVersion` field to determine which verification scheme applies. For complete verification steps, sample code, and Root CA values, see the Address verification guide docs.\n\n### V1 Address Signatures\n\nThe steps for verifying V1 address signatures are as follows:\n1. Check the validity of the signature\n   - Decode the `signedJson` field from hex to bytes\n   - Decode the `signature` field from hex to bytes\n   - Using your organization's verification public key (provided by Anchorage Digital), verify that the signature bytes are a valid Ed25519 signature of the signedJson bytes\n2. Verify the address that was signed matches the one that will be used\n   - Decode the `signedJson` field from hex to bytes\n   - Parse the bytes as a JSON object (e.g., `{\"TextAddress\":\"0x123...\"}`)\n   - Verify the address to be used matches the value of the `TextAddress` property from the JSON object\n\n**Important**: It is not sufficient to validate the signature without also validating that the address signed matches the address to be used.\n\n**Note**: The JSON object may contain additional properties in future versions. API clients must not use strict JSON parsers which disallow extra, unknown properties.\n\n**Verification Public Key**: Contact your Anchorage Digital representative to obtain the verification public key for your organization. This key is unique per organization and fixed for the lifetime of that organization.\n\n### V2 Address Signatures\n\nAddresses with `signatureVersion` set to `V2` also include a `certChain` field containing an X.509 certificate chain in PEM format.\n\nThe steps for verifying V2 address signatures are as follows:\n1. Verify the certificate chain:\n   - Parse the `certChain` field as PEM-encoded X.509 certificates (leaf at index 0, then intermediates)\n   - Verify the chain up to the hard-coded Anchorage Digital Address Signing Root CA (see Address verification guide docs)\n   - Verify all certificates are valid at the current time (both notAfter and notBefore)\n   - Verify the leaf certificate's Subject Alternative Names include `address-provider.anchorage.internal`\n   - Verify the leaf certificate's KeyUsage includes both `digitalSignature` and `nonRepudiation` (also known as `contentCommitment`)\n   - Extract the public key from the leaf certificate\n2. Verify the signature:\n   - Decode the `signedJson` field from hex to bytes\n   - Decode the `signature` field from hex to bytes\n   - Using the public key from the leaf certificate, verify that `signature` is a valid signature of the `signedJson` bytes\n3. Verify the signed details:\n   - Parse the `signedJson` bytes as JSON\n   - Verify `SignatureExpiresAt` is greater than or equal to the current UTC Unix timestamp\n   - Verify `TextAddress` matches the address to be used\n   - Verify `VaultId` matches your expected Vault ID\n   - Verify `NetworkId` matches the expected network for this address\n\n**Note**: API clients must not use strict JSON parsers which disallow unknown properties, as future versions may add new fields to the signed payload.\n\n**Note**: Anchorage Digital periodically refreshes V2 signatures and the certificate chain before expiration. The address itself does not change."
      type: object
      properties:
        address:
          description: A unique string identifying an account on a blockchain. This is sometimes dervied from a public key and sometimes decided by the blockchain.
          type: string
        certChain:
          description: PEM-encoded X.509 certificate chain used for V2 signature verification. The leaf certificate is at index 0, followed by zero or more intermediate certificates. The root CA is excluded and must be hard-coded by clients. Only present when `signatureVersion` is `V2`.
          type: string
        networkId:
          description: A unique string identifying a combination of blockchain and environment (testnet, mainnet).
          type: string
        publicKey:
          description: 'The public key that the blockchain address is derived from. Note: This is NOT the key used to verify the signature field - that requires a separate organization-wide verification public key provided by Anchorage Digital.'
          type: string
        signature:
          description: Hex-encoded Ed25519 signature of the `signedJson` bytes. For V1 signatures, verify against your organization's fixed public key. For V2 signatures, verify against the leaf certificate's public key from the `certChain` field.
          type: string
          example: 1642000aa9cca8e8610981aefbdb204b361c9dca3fa067b88fdacfba7a0f620d721378a33f4bbadad3923e633a4d712646d1e8e314e9fcb4aa4102c0581f6503
        signatureVersion:
          description: Version of the address signature scheme used. Check this field to determine how to verify the `signature` field.
          allOf:
          - $ref: '#/components/schemas/WalletAddressSignatureVersion'
        signedJson:
          description: Hex-encoded bytes that were signed to produce the `signature`. Decode from hex to get the signed content. For V1 signatures, the content is a JSON object with a `TextAddress` field. For V2 signatures, the content is a JSON object with `TextAddress`, `VaultId`, `NetworkId`, `NetworkName`, and `SignatureExpiresAt` fields.
          type: string
          example: 7b225465787441646472657373223a22307831323334227d
        walletId:
          description: The wallet ID containing this address.
          type: string
      required:
      - address
      - networkId
      - publicKey
      - signedJson
      - signature
      - walletId
      - signatureVersion
  securitySchemes:
    Api-Access-Key:
      type: apiKey
      name: Api-Access-Key
      in: header
      description: An API key associated with a security role
x-refined-from:
- anchorage-v2-openapi-original.yml
- anchorage-v3-openapi-original.yml
x-tagGroups:
- name: Under Development
  tags:
  - Collateral Management
  - Holds
  - Deposit Attribution
  - Onboarding
  - Trusted Destinations
  - Atlas Settlement Network
  - Tax
- name: API Endpoints
  tags:
  - Addresses
  - Asset Types
  - Transactions
  - Transfers
  - Wallets
  - Vaults
  - Vesting
  - Tagging
  - Subaccounts
  - Stablecoins
  - Webhook Notifications
  - API Key
  - Statements
  - Tax Reporting
  - Trading
- name: Models
  tags:
  - Transfer Model
  - Transaction Model
  - Vault Model
  - Deposit Attribution Model