Cubist Contact API

The Contact API from Cubist — 3 operation(s) for contact.

OpenAPI Specification

cubist-contact-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: CubeSigner Account Contact API
  description: The CubeSigner management and signing service.
  contact:
    name: Cubist Inc.
    email: hello@cubist.dev
  version: v0.1.0
servers:
- url: https://gamma.signer.cubist.dev
  description: Testing and staging environment
- url: https://prod.signer.cubist.dev
  description: Production environment
security:
- Cognito: []
tags:
- name: Contact
paths:
  /v0/org/{org_id}/contacts:
    get:
      tags:
      - Contact
      summary: List Contacts
      description: 'List Contacts


        List all contacts in the org.

        Any org member is allowed to list all contacts in the org.


        ## Search Condition

        The search condition is optional.


        - If the search condition starts with "label:...", this list will only hold contacts with

        the label provided after the ":". For example, "label:cubist:erc20_token" would return contacts that

        hold the label "cubist:erc20_token".


        - Otherwise, the result will contain only the contacts who have an address starting with, or

        equaling, the given search string. For example, "0xee" would return all contacts holding an

        address starting with "0xee". The search is case-insensitive.


        If a search term is defined, we do not guarantee

        the number of results in a page. The behavior of this parameter may change

        in the future (for example, making results more strictly paginated or

        performing a fuzzy search rather than a prefix search).'
      operationId: listContacts
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: page.size
        in: query
        description: 'Max number of items to return per page.


          If the actual number of returned items may be less that this, even if there exist more

          data in the result set. To reliably determine if more data is left in the result set,

          inspect the [UnencryptedLastEvalKey] value in the response object.'
        required: false
        schema:
          type: integer
          format: int32
          default: 100
          maximum: 1001
          minimum: 1
        style: form
      - name: page.start
        in: query
        description: 'The start of the page.  Omit to start from the beginning; otherwise, only specify a

          the exact value previously returned as ''last_evaluated_key'' from the same endpoint.'
        required: false
        schema:
          type: string
          nullable: true
        style: form
      - name: search
        in: query
        description: Either 'label:...', which lists contacts with the label provided after the ':'. Or, an entire address, or prefix of an address, that returned contacts must have. When searching by address, it must be at least 3 characters.
        required: false
        schema:
          type: string
          nullable: true
      responses:
        '200':
          $ref: '#/components/responses/PaginatedListContactsResponse'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:contact:list
    post:
      tags:
      - Contact
      summary: Create Contact
      description: 'Create Contact


        Creates a new contact in the organization-wide address book. The

        user making the request is the owner of the contact, giving them edit access

        to the contact along with the org owners.'
      operationId: createContact
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateContactRequest'
        required: true
      responses:
        '200':
          $ref: '#/components/responses/ContactInfoResponse'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:contact:create
  /v0/org/{org_id}/contacts/by-address:
    post:
      tags:
      - Contact
      summary: Lookup Contacts by Address
      description: 'Lookup Contacts by Address


        Returns all contacts in the org that have the given address.


        When querying with an EVM address without a chain, this endpoint returns

        contacts with that address on *any* chain, including those without a chain

        defined.'
      operationId: lookupContactsByAddress
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ContactAddressData'
        required: true
      responses:
        '200':
          $ref: '#/components/responses/PaginatedListContactsResponse'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:contact:lookup:address
  /v0/org/{org_id}/contacts/{contact_id}:
    get:
      tags:
      - Contact
      summary: Get Contact
      description: 'Get Contact


        Returns the properties of a Contact.'
      operationId: getContact
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: contact_id
        in: path
        description: ID of the desired Contact
        required: true
        schema:
          type: string
        example: Contact#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      responses:
        '200':
          $ref: '#/components/responses/ContactInfoResponse'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:contact:get
    delete:
      tags:
      - Contact
      summary: Delete Contact
      description: 'Delete Contact


        Delete a contact, specified by its ID.


        Only the contact owner and org owners are allowed to delete contacts.

        Additionally, the contact''s edit policy (if set) must permit the deletion.'
      operationId: deleteContact
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: contact_id
        in: path
        description: ID of the desired Contact
        required: true
        schema:
          type: string
        example: Contact#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Empty'
        required: true
      responses:
        '200':
          $ref: '#/components/responses/EmptyImpl'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:contact:delete
    patch:
      tags:
      - Contact
      summary: Update Contact
      description: 'Update Contact


        Updates an existing contact in the organization-wide address book. Only

        the contact owner or an org owner can update contacts.


        *Updates will overwrite the existing value of the field.*

        '
      operationId: updateContact
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: contact_id
        in: path
        description: ID of the desired Contact
        required: true
        schema:
          type: string
        example: Contact#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateContactRequest'
        required: true
      responses:
        '200':
          $ref: '#/components/responses/ContactInfoResponse'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:contact:update:name
        - manage:contact:update:addresses
        - manage:contact:update:owner
        - manage:contact:update:metadata
        - manage:contact:update:editPolicy
components:
  schemas:
    EpochDateTime:
      type: integer
      format: int64
      description: 'DateTime measured in seconds since unix epoch.

        A wrapper type for serialization that encodes a [`SystemTime`] as a [`u64`]

        representing the number of seconds since [`SystemTime::UNIX_EPOCH`].'
      minimum: 0
    Empty:
      default: null
      nullable: true
    SuiAddressInfo:
      type: object
      description: A Sui address and its chain.
      required:
      - chain
      - address
      properties:
        address:
          type: string
          description: The Sui address.
          example: '0x4e8712e38b09b5467c10fdc40fa7865a65563983eeb74b246df981e61a66b98d'
        chain:
          $ref: '#/components/schemas/SuiChain'
    MfaRequiredArgs:
      type: object
      required:
      - id
      - ids
      - org_id
      properties:
        id:
          type: string
          description: Always set to first MFA id from `Self::ids`
        ids:
          type: array
          items:
            type: string
            minLength: 1
          description: Non-empty MFA request IDs
        org_id:
          type: string
          description: Organization id
        policy_eval_tree:
          description: Optional policy evaluation tree (included in signer responses, when requested)
          nullable: true
        session:
          allOf:
          - $ref: '#/components/schemas/NewSessionResponse'
          nullable: true
    B32:
      type: string
      description: Wrapper around a zeroizing 32-byte fixed-size array
    ContactAddressData:
      oneOf:
      - allOf:
        - $ref: '#/components/schemas/BitcoinAddressInfo'
        - type: object
          required:
          - network
          properties:
            network:
              type: string
              enum:
              - Bitcoin
      - allOf:
        - $ref: '#/components/schemas/EvmAddressInfo'
        - type: object
          required:
          - network
          properties:
            network:
              type: string
              enum:
              - Evm
      - allOf:
        - $ref: '#/components/schemas/SuiAddressInfo'
        - type: object
          required:
          - network
          properties:
            network:
              type: string
              enum:
              - Sui
      - allOf:
        - $ref: '#/components/schemas/SolanaAddressInfo'
        - type: object
          required:
          - network
          properties:
            network:
              type: string
              enum:
              - Solana
      - allOf:
        - $ref: '#/components/schemas/CantonPartyInfo'
        - type: object
          required:
          - network
          properties:
            network:
              type: string
              enum:
              - Canton
      description: An address associated with a contact.
      discriminator:
        propertyName: network
    ScopeSet:
      oneOf:
      - type: string
        description: All scopes
        enum:
        - All
      - type: object
        required:
        - AllExcept
        properties:
          AllExcept:
            type: array
            items:
              $ref: '#/components/schemas/Scope'
            description: All scopes except these (including those transitively implied).
      - type: object
        required:
        - AllOf
        properties:
          AllOf:
            type: array
            items:
              $ref: '#/components/schemas/Scope'
            description: All of these scopes (including those transitively implied).
      description: A set of scopes.
    CommonFields:
      allOf:
      - type: object
        description: 'Versioning fields (e.g., version number, creation time, and last modified times)

          that are common to different types of resources.'
        properties:
          created:
            allOf:
            - $ref: '#/components/schemas/EpochDateTime'
            nullable: true
          last_modified:
            allOf:
            - $ref: '#/components/schemas/EpochDateTime'
            nullable: true
          version:
            type: integer
            format: int64
            description: Version of this object
            minimum: 0
      - type: object
        properties:
          edit_policy:
            $ref: '#/components/schemas/EditPolicy'
          metadata:
            description: 'User-defined metadata. When rendering (e.g., in the browser) you should treat

              it as untrusted user data (and avoid injecting metadata into HTML directly) if

              untrusted users can create/update keys (or their metadata).'
      description: 'Fields that are common to different types of resources such as keys, roles, etc.

        Includes versioning fields plus metadata, edit policy, etc.'
    AcceptedValue:
      oneOf:
      - type: object
        required:
        - SignDryRun
        properties:
          SignDryRun:
            $ref: '#/components/schemas/SignDryRunArgs'
      - type: object
        required:
        - BinanceDryRun
        properties:
          BinanceDryRun:
            $ref: '#/components/schemas/BinanceDryRunArgs'
      - type: object
        required:
        - BybitDryRun
        properties:
          BybitDryRun:
            $ref: '#/components/schemas/BybitDryRunArgs'
      - type: object
        required:
        - CoinbaseDryRun
        properties:
          CoinbaseDryRun:
            $ref: '#/components/schemas/CoinbaseDryRunArgs'
      - type: object
        required:
        - MfaRequired
        properties:
          MfaRequired:
            $ref: '#/components/schemas/MfaRequiredArgs'
      description: Different responses we return for success status codes.
    NotFoundErrorCode:
      type: string
      enum:
      - UriSegmentMissing
      - UriSegmentInvalid
      - TotpNotConfigured
      - FidoKeyNotFound
      - FidoChallengeNotFound
      - TotpChallengeNotFound
      - UserExportRequestNotFound
      - UserExportCiphertextNotFound
      - OrgExportCiphertextNotFound
      - UploadObjectNotFound
      - PolicySecretNotFound
      - BucketMetaNotFound
      - TimestreamDisabled
      - CustomChainNotFound
      - InvitationNotFound
      - TransactionNotFound
      - EmailConfigNotFound
    HttpRequestCmp:
      oneOf:
      - type: string
        description: The requests must match exactly. Any given MFA receipt can be used at most once.
        enum:
        - Eq
      - type: object
        required:
        - EvmTx
        properties:
          EvmTx:
            $ref: '#/components/schemas/EvmTxCmp'
      - type: object
        required:
        - SolanaTx
        properties:
          SolanaTx:
            $ref: '#/components/schemas/SolanaTxCmp'
      description: How to compare HTTP requests when verifying MFA receipt (see [MfaRequest::verify_request])
    Contact:
      allOf:
      - $ref: '#/components/schemas/CommonFields'
      - type: object
        required:
        - name
        - owner
        properties:
          labels:
            type: array
            items:
              $ref: '#/components/schemas/ContactLabel'
            description: Labels to categorize this contact.
            example:
            - cubist:erc20_token
            uniqueItems: true
          name:
            type: string
            description: 'The name for the contact. Must be a unique name among contacts in the

              org. The name must consist of alphanumeric characters, spaces, `.` and `-`,

              and cannot be longer than 50 characters.'
            example: Satoshi Nakamoto
            pattern: ^[a-zA-Z0-9 .-]{1,50}$
          owner:
            $ref: '#/components/schemas/Id'
      description: A contact in the org.
    SolanaTxCmp:
      type: object
      properties:
        ignore_blockhash:
          type: boolean
          description: Whether the 'recent_blockhash' property of the Solana transaction is allowed to be different.
    BadGatewayErrorCode:
      type: string
      enum:
      - Generic
      - CustomChainRpcError
      - EsploraApiError
      - SentryApiError
      - CallWebhookError
      - OAuthProviderError
      - OidcDisoveryFailed
      - OidcIssuerJwkEndpointUnavailable
      - SmtpServerUnavailable
    InternalErrorCode:
      type: string
      enum:
      - NoMaterialId
      - InvalidAuditLogEntry
      - UnexpectedCheckerRule
      - UnresolvedPolicyReference
      - UnexpectedAclAction
      - FidoKeyAssociatedWithMultipleUsers
      - ClaimsParseError
      - InvalidThrottleId
      - InvalidEmailAddress
      - EmailTemplateRender
      - OidcIdentityHeaderMissing
      - OidcIdentityParseError
      - SystemTimeError
      - PasswordHashParseError
      - SendMailError
      - ReqwestError
      - EmailConstructionError
      - TsWriteError
      - TsQueryError
      - DbQueryError
      - DbGetError
      - DbDeleteError
      - DbPutError
      - DbUpdateError
      - SerdeError
      - TestAndSetError
      - DbGetItemsError
      - DbWriteError
      - CubistSignerError
      - CwListMetricsError
      - CwPutMetricDataError
      - GetAwsSecretError
      - SecretNotFound
      - KmsGenerateRandomError
      - MalformedTotpBytes
      - KmsGenerateRandomNoResponseError
      - CreateKeyError
      - ParseDerivationPathError
      - SplitSignerError
      - CreateImportKeyError
      - CreateEotsNoncesError
      - EotsSignError
      - BabylonCovSignError
      - CognitoDeleteUserError
      - CognitoListUsersError
      - CognitoGetUserError
      - MissingUserEmail
      - CognitoResendUserInvitation
      - CognitoSetUserPasswordError
      - GenericInternalError
      - AssumeRoleWithoutEvidence
      - OidcAuthWithoutOrg
      - MissingKeyMetadata
      - KmsEnableKeyError
      - KmsDisableKeyError
      - LambdaInvokeError
      - LambdaNoResponseError
      - LambdaFailure
      - LambdaUnparsableResponse
      - SerializeEncryptedExportKeyError
      - DeserializeEncryptedExportKeyError
      - ReEncryptUserExport
      - S3UploadError
      - S3DownloadError
      - S3CopyError
      - S3ListObjectsError
      - S3DeleteObjectsError
      - S3BuildError
      - S3PresignedUrlError
      - ManagedStateMissing
      - InternalHeaderMissing
      - InvalidInternalHeaderValue
      - RequestLocalStateAlreadySet
      - OidcOrgMismatch
      - OidcIssuerInvalidJwk
      - InvalidPkForMaterialId
      - SegwitTweakFailed
      - UncheckedOrg
      - SessionOrgIdMissing
      - AvaSignCredsMissing
      - AvaSignSignatureMissing
      - ExpectedRoleSession
      - InvalidThirdPartyIdentity
      - CognitoGetUser
      - SnsSubscribeError
      - SnsUnsubscribeError
      - SnsGetSubscriptionAttributesError
      - SnsSubscriptionAttributesMissing
      - SnsSetSubscriptionAttributesError
      - SnsPublishBatchError
      - InconsistentMultiValueTestAndSet
      - MaterialIdError
      - InvalidBtcAddress
      - HistoricalTxBodyMissing
      - InvalidOperation
      - ParentOrgNotFound
      - OrgParentLoop
      - ResolvedParentOrgWithNoScopeCeiling
      - InvalidUploadObjectId
      - PolicyEngineNotFound
      - PolicyEngineError
      - PolicySecretsEncryptionError
      - CreatePolicyImportKeyError
      - InvalidAlias
      - EmptyUpdateModifiedObject
      - EmptyUpdateModifiedActions
      - DbContactAddressesInvalid
      - InvalidEvmSigedRlp
      - InvalidErc20Data
      - InvalidRpcUrl
    EvmTxCmp:
      type: object
      properties:
        grace:
          type: integer
          format: int64
          description: 'To prevent replay attacks, any given MFA receipt is normally allowed to be used only once.


            In this case, however, because EVM transactions already have a replay prevention mechanism

            (namely the ''nonce'' property), we allow the user to specify a grace period (in seconds) to

            indicate how long an MFA receipt should remain valid after its first use.


            Note that we allow both ''grace'' and ''ignore_nonce'' to be set because once an MFA request

            enters its grace period we unconditionally set its ''ignore_nonce'' property to ''false'' to

            ensure that any subsequent requests that claim the same receipt must sign for the same

            nonce as the request we signed originally with that receipt.


            Also note that the grace period cannot extend the lifetime of an MFA request beyond its

            original expiration date.


            The grace period must not be greater than 30 days.'
          nullable: true
          minimum: 0
        ignore_gas:
          type: boolean
          description: Whether the 'gas' property of the EVM transaction is allowed to be different.
        ignore_nonce:
          type: boolean
          description: Whether the 'nonce' property of the EVM transaction is allowed to be different.
    SuiChain:
      type: string
      description: Supported Sui chains.
      enum:
      - mainnet
      - devnet
      - testnet
    SignerErrorCode:
      oneOf:
      - $ref: '#/components/schemas/SignerErrorOwnCodes'
      - $ref: '#/components/schemas/AcceptedValueCode'
      - $ref: '#/components/schemas/BadRequestErrorCode'
      - $ref: '#/components/schemas/BadGatewayErrorCode'
      - $ref: '#/components/schemas/NotFoundErrorCode'
      - $ref: '#/components/schemas/ForbiddenErrorCode'
      - $ref: '#/components/schemas/UnauthorizedErrorCode'
      - $ref: '#/components/schemas/PreconditionErrorCode'
      - $ref: '#/components/schemas/TimeoutErrorCode'
      - $ref: '#/components/schemas/ConflictErrorCode'
      - $ref: '#/components/schemas/InternalErrorCode'
    EvmTxDepositErrorCode:
      type: string
      enum:
      - EvmTxDepositReceiverMismatch
      - EvmTxDepositEmptyData
      - EvmTxDepositEmptyChainId
      - EvmTxDepositEmptyReceiver
      - EvmTxDepositUnexpectedValue
      - EvmTxDepositUnexpectedDataLength
      - EvmTxDepositNoAbi
      - EvmTxDepositNoDepositFunction
      - EvmTxDepositUnexpectedFunctionName
      - EvmTxDepositUnexpectedValidatorKey
      - EvmTxDepositInvalidValidatorKey
      - EvmTxDepositMissingDepositArg
      - EvmTxDepositWrongDepositArgType
      - EvmTxDepositValidatorKeyNotInRole
      - EvmTxDepositUnexpectedWithdrawalCredentials
      - EvmTxDepositUnresolvedRole
      - EvmTxDepositInvalidDepositEncoding
    EditPolicy:
      type: object
      description: 'A policy which governs when and who is allowed to update the entity this policy is

        attached to (e.g., a role or a key).


        When attached to a role, by default, this policy applies to role deletion and all

        role updates (including adding/removing keys and users); in terms of scopes,

        it applies to `manage:role:update:*` and `manage:role:delete`.


        When attached to a key, by default, this policy applies to key deletion, all

        key updates, and adding/removing that key to/from a role; in terms of scopes,

        it applies to `manage:key:update:*`, `manage:key:delete`, `manage:role:update:key:*`.


        This default can be changed by setting the `applies_to_scopes` property.'
      properties:
        applies_to_scopes:
          $ref: '#/components/schemas/ScopeSet'
        mfa:
          allOf:
          - $ref: '#/components/schemas/MfaPolicy'
          nullable: true
        time_lock_until:
          allOf:
          - $ref: '#/components/schemas/EpochDateTime'
          nullable: true
    OperationKind:
      type: string
      description: All different kinds of sensitive operations
      enum:
      - AvaSign
      - AvaChainTxSign
      - BabylonCovSign
      - BabylonRegistration
      - BabylonStaking
      - BinanceSubToMaster
      - BinanceSubToSub
      - BinanceUniversalTransfer
      - BinanceSubAccountAssets
      - BinanceAccountInfo
      - BinanceSubAccountTransferHistory
      - BinanceUniversalTransferHistory
      - BinanceWithdraw
      - BinanceWithdrawHistory
      - BinanceDeposit
      - BinanceDepositHistory
      - BinanceListSubAccounts
      - BinanceCoinInfo
      - BlobSign
      - BtcMessageSign
      - BtcSign
      - BybitQueryUser
      - BybitQuerySubMembers
      - BybitQueryCoinsBalance
      - BybitQueryDepositAddress
      - BybitUniversalTransfer
      - BybitWithdraw
      - BybitWithdrawals
      - CoinbaseListAccounts
      - CoinbaseListPortfolios
      - CoinbaseMoveFunds
      - DiffieHellman
      - PsbtSign
      - TaprootSign
      - Eip191Sign
      - Eip712Sign
      - Eip7702Sign
      - EotsNonces
      - EotsSign
      - Eth1Sign
      - Eth2Sign
      - Eth2Stake
      - Eth2Unstake
      - SolanaSign
      - SuiSign
      - TendermintSign
      - RoleUpdate
    ErrorResponse:
      type: object
      description: The structure of ErrorResponse must match the response template that AWS uses
      required:
      - message
      - error_code
      properties:
        accepted:
          allOf:
          - $ref: '#/components/schemas/AcceptedValue'
          nullable: true
        error_code:
          $ref: '#/components/schemas/SignerErrorCode'
        message:
          type: string
          description: Error message
        policy_eval_tree:
          description: Optional policy evaluation tree (included in signer responses, when requested)
          nullable: true
        request_id:
          type: string
          description: Optional request identifier
    PreconditionErrorOwnCodes:
      type: string
      enum:
      - FailOnMfaRequired
      - KeyRegionLocked
      - KeyRegionChangedRecently
      - MfaRegionLocked
      - Eth2ProposerSlotTooLow
      - Eth2AttestationSourceEpochTooLow
      - Eth2AttestationTargetEpochTooLow
      - Eth2ConcurrentBlockSigning
      - Eth2ConcurrentAttestationSigning
      - Eth2MultiDepositToNonGeneratedKey
      - Eth2MultiDepositUnknownInitialDeposit
      - Eth2MultiDepositWithdrawalAddressMismatch
      - ConcurrentSigningWhenTimeLimitPolicyIsDefined
      - BabylonEotsConcurrentSigning
      - TendermintStateError
      - TendermintConcurrentSigning
      - MfaApprovalsNotYetValid
    BitcoinAddressInfo:
      type: object
      description: A bitcoin address and its network.
      required:
      - chain
      - address
      properties:
        address:
          type: string
          description: The bitcoin address.
          example: bc1puc0q8jhx3knc2stlfhl35nja89nvkmqr4c5e2ldyuq2mcckhr3msavj99j
        chain:
          $ref: '#/components/schemas/BtcChain'
    ExplicitScope:
      type: string
      title: ExplicitScope
      description: Explicitly named scopes for accessing CubeSigner APIs
      enum:
      - sign:*
      - sign:ava
      - sign:binance:*
      - sign:binance:subToMaster
      - sign:binance:subToSub
      - sign:binance:universalTransfer
      - sign:binance:subAccountAssets
      - sign:binance:accountInfo
      - sign:binance:subAccountTransferHistory
      - sign:binance:universalTransferHistory
      - sign:binance:withdraw
      - sign:binance:withdrawHistory
      - sign:binance:deposit
      - sign:binance:depositHistory
      - sign:binance:listSubAccounts
      - sign:binance:coinInfo
      - sign:bybit:*
      - sign:bybit:queryUser
      - sign:bybit:querySubMembers
      - sign:bybit:queryCoinsBalance
      - sign:bybit:queryDepositAddress
      - sign:bybit:universalTransfer
      - sign:bybit:withdraw
      - sign:bybit:withdrawals
      - sign:coinbase:*
      - sign:coinbase:accounts:list
      - sign:coinbase:portfolios:list
      - sign:coinbase:funds:move
      - sign:blob
      - sign:diffieHellman
      - sign:btc:*
      - sign:btc:segwit
      - sign:btc:taproot
      - sign:btc:psbt:*
      - sign:btc:psbt:doge
      - sign:btc:psbt:legacy
      - sign:btc:psbt:segwit
      - sign:btc:psbt:taproot
      - sign:btc:psbt:ltcSegwit
      - sign:btc:message:*
      - sign:btc:message:segwit
      - sign:btc:message:legacy
      - sign:babylon:*
      - sign:babylon:eots:*
      - sign:babylon:eots:nonces
      - sign:babylon:eots:sign
      - sign:babylon:staking:*
      - sign:babylon:staking:deposit
      - sign:babylon:staking:unbond
      - sign:babylon:staking:withdraw
      - sign:babylon:staking:slash
      - sign:babylon:registration
      - sign:babylon:covenant
      - sign:evm:*
      - sign:evm:tx
      - sign:evm:eip191
      - sign:evm:eip712
      - sign:evm:eip7702
      - sign:eth2:*
      - sign:eth2:validate
      - sign:eth2:stake
      - sign:eth2:unstake
      - sign:solana
      - sign:sui
      - sign:tendermint
      - sign:mmi
      - manage:*
      - manage:readonly
      - manage:email:*
      - manage:email:get
      - manage:email:update
      - manage:email:delete
      - manage:mfa:*
      - manage:mfa:readonly
      - manage:mfa:list
      - manage:mfa:vote:*
      - manage:mfa:vote:cs
      - manage:mfa:vote:email
      - manage:mfa:vote:fido
      - manage:mfa:vote:totp
      - manage:mfa:register:*
      - manage:mfa:register:fido
      - manage:mfa:register:totp
      - manage:mfa:register:email
      - manage:mfa:unregister:*
      - manage:mfa:unregister:fido
      - manage:mfa:unregister:totp
      - manage:mfa:verify:*
      - manage:mfa:verify:totp
      - manage:key:*
      - manage:key:readonly
      - manage:key:get
      - manage:key:attest
      - manage:key:listRoles
      - manage:key:list
      - manage:key:history:tx:list
      - manage:key:create
      - manage:key:import
      - manage:key:update:*
      - manage:key:update:owner
      - manage:key:update:policy
      - manage:key:update:enabled
      - manage:key:update:region
      - manage:key:update:metadata
      - manage:key:update:properties
      - manage:key:update:editPolicy
      - manage:key:delete
      - manage:policy:*
      - manage:policy:readonly
      - manage:policy:create
      - manage:policy:get
      - manage:policy:list
      - manage:policy:delete
      - manage:policy:update:*
      - manage:policy:update:owner
      - manage:policy:update:name
      - manage:policy:update:acl
      - manage:policy:update:editPolicy
      - manage:policy:update:metadata
      - manage:policy:update:rule
      - manage:policy:invoke
      - manage:policy:wasm:*
      - manage:policy:wasm:upload
      - manage:policy:secrets:*
      - manage:policy:secrets:get
      - manage:policy:secrets:update:*
      - manage:policy:secrets:update:values
      - manage:policy:secrets:update:acl
      - manage:policy:secrets:update:editPolicy
      - manage:policy:buckets:*
      - manage:policy:buckets:get
      - manage:policy:buckets:list
      - manage:policy:buckets:update:*
      - manage:policy:buckets:update:owner
      - manage:policy:buckets:update:acl
      - manage:policy:buckets:update:metadata
      - manage:contact:*
      - manage:contact:readonly
      - manage:contact:create
      - manage:contact:get
      - manage:contact:list
      - manage:contact:delete
      - manage:contact:update:*
      - manage:contact:update:name
      - manage:contact:update:addresses
      - manage:contact:update:owner
      - manage:contact:update:labels
      - manage:contact:update:metadata
      - manage:contact:updat

# --- truncated at 32 KB (66 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cubist/refs/heads/main/openapi/cubist-contact-api-openapi.yml