Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
openapi: 3.2.0
info:
title: Fipto - OpenAPI 3.0 Assets API
version: 4.3.0
description: This is a REST API specifications based on OpenAPI 3.0 for Fipto solution.
contact:
url: https://www.fipto.com/
servers:
- url: https://api.fipto.app
description: The API server on production
tags:
- name: Assets
description: Retrieve information about assets supported by Fipto.
paths:
/companies/{company_id}/assets:
get:
summary: Get supported assets
description: Retrieve the list of supported assets of a company.
operationId: listAssets
tags:
- Assets
parameters:
- $ref: '#/components/parameters/company_id'
- $ref: '#/components/parameters/page_number'
- $ref: '#/components/parameters/page_size'
- name: sort
in: query
required: false
schema:
$ref: '#/components/schemas/sort_asset_list'
responses:
'200':
description: List of all assets.
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/meta'
- $ref: '#/components/schemas/pagination'
- type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/asset_data'
/companies/{company_id}/request-usd:
post:
summary: Request USD onboarding
description: Request USD onboarding for a company.
operationId: requestUsdOnboarding
tags:
- Assets
parameters:
- $ref: '#/components/parameters/company_id'
responses:
'204':
description: Request USD onboarding initiated.
components:
schemas:
sort:
type: string
default: created_at
example: created_at
description: The sort field used to filter data.
meta:
description: Metadata of the request
type: object
required:
- meta
properties:
meta:
type: object
required:
- request_id
properties:
request_id:
oneOf:
- $ref: '#/components/schemas/uuid'
- $ref: '#/components/schemas/request_id'
query_parameters:
$ref: '#/components/schemas/query_parameters'
asset:
description: The symbol/ticker of the crypto asset.
type: string
example: BTC
request_id:
type: string
pattern: '[0-9]-[0-9a-fA-F]{8}-[0-9a-fA-F]{24}'
description: Request identifier.
network_name:
description: Name of network.
type: string
example: Bitcoin
asset_type:
description: Type of the asset.
type: string
enum:
- digital
- fiat
example: digital
asset_data:
description: Asset data.
type: object
properties:
type:
type: string
enum:
- asset
asset_code:
$ref: '#/components/schemas/asset'
attributes:
properties:
currency_code:
description: The currency code of the asset.
example: BTC
allOf:
- $ref: '#/components/schemas/asset'
currency_name:
type: string
description: The currency name of the asset.
example: Bitcoin
decimals:
description: The maximum number of decimal places for the given asset.
allOf:
- $ref: '#/components/schemas/positive_integer'
asset_type:
$ref: '#/components/schemas/asset_type'
network_name:
$ref: '#/components/schemas/network_name'
has_access:
$ref: '#/components/schemas/has_access'
sort_asset_list:
description: Possible sort for the list asset.
allOf:
- $ref: '#/components/schemas/sort'
enum:
- created_at
- currency_code
- currency_name
- asset_code
- asset_type
- network_name
has_access:
description: Specify if the company can interact with a specific asset.
type: boolean
uuid:
type: string
pattern: '[0-9a-fA-F]{8}\b-[0-9a-fA-F]{4}\b-[0-9a-fA-F]{4}\b-[0-9a-fA-F]{4}\b-[0-9a-fA-F]{12}'
description: 128-bit value used to uniquely identify an object.
example: 123e4567-e89b-12d3-a456-426614174000
pagination:
description: Information about the pagination of the request
type: object
required:
- meta
properties:
meta:
type: object
required:
- total_results
- query_parameters
properties:
total_results:
description: The total number of results
type: number
example: 100
query_parameters:
allOf:
- $ref: '#/components/schemas/query_parameters'
required:
- page_number
- page_size
- sort
properties:
page_number:
type: number
example: 1
page_size:
type: number
example: 100
sort:
type: string
example: created_at
query_parameters:
description: Information about the parameters in the request. All query string parameters provided (or implicit/with default value) will be returned
type: object
positive_integer:
type: integer
example: 10000
maximum: 2147483647
minimum: 0
description: Strictly positive int32.
parameters:
page_size:
name: page_size
in: query
required: false
description: The number of items to include in each page of the paginated results. The default value is 100.
schema:
type: number
example: 100
company_id:
name: company_id
in: path
required: true
description: The Company ID given by Fipto.
example: 9de0691c-bc8d-409b-8f40-75d4f45db2f3
schema:
$ref: '#/components/schemas/uuid'
page_number:
name: page_number
in: query
required: false
description: The page number retrieved in the paginated results. The default value is 1.
schema:
type: number
example: 1
x-topics:
- title: Authentication
content: "# Getting Started\n\nBefore using the API you need to generate a private/public key pair using:\n\n openssl genrsa -out private-key.rsa 2048\n openssl pkcs8 -topk8 -inform PEM -outform PEM -nocrypt -in private-key.rsa -out private-key.pem\n openssl rsa -in private-key.rsa -pubout -out public-key.pem\n\nAfter sending us the public key by email, you will receive an api key, referred below as `keyId`.\n\n## HTTP request signing\n\nAll authenticated requests must include the following headers:\n\n- `Host`: target host of the request, e.g. \"api.fipto.app\"\n- `Date`: time of creation of the request, in RFC1123 format\n- `Signature`: signature of the request (see below)\n\nIn addition, requests with a body (POST, PUT, PATCH) must include:\n\n- `Content-Type`: MIME type of the body, e.g. \"application/json\"\n- `Digest`: base64-encoded SHA-256 hash of the body, in the format SHA-256=<hash>\n\n`Date` values are expected to be earlier than the present time, but not\nearlier than 1 minute.\n\n`Digest` values must obviously match to the actual hashes of their request\nbodies. The way of getting the digest is language-dependent but a basic\nUNIX approach would be\n\n echo -n $BODY | openssl dgst -sha256 -binary | openssl enc -base64 -A\n\nwhere $BODY contains the string representation of the request body.\n\n### Signature header\n\nRequests are signed and verified using the [HTTP signatures protocol](https://datatracker.ietf.org/doc/html/draft-cavage-http-signatures-12).\nLibraries exist in different languages for building signed requests using that\nprotocol. We focus here on our specific requirements.\n\nWe expect the authentication data to be present in a `Signature` header.\n\nThe \"signing string\" itself should contain all the headers mentioned in the previous section,\nas well as the `(request-target)` pseudo-header (see [section 2.3](https://datatracker.ietf.org/doc/html/draft-cavage-http-signatures-12#section-2.3)).\n\nFor example, the signing string of a POST request would look like:\n\n (request-target): post /companies/c240e5bf-863e-4f44-91aa-cc74a8b3303f/wallets\n host: api.demo.fipto.tech\n date: Fri, 24 Jan 2025 08:56:30 GMT\n content-type: application/json\n digest: SHA-256=X48E9qOokqqrvdts8nOJRJN3OWDUoyWxBf7kbu9DBPE=\n\nThat string must then be signed using the RSA-256 algorithm, encoded in base64 and\nincluded in the `signature` field of the header.\n\nThe following constraints apply to other fields:\n\n- the `keyId` field must contain the UUID of your API user\n- the `headers` field must contain `(request-target)` as well as all the headers mentioned above\n- the `algorithm` field must be \"hs2019\" (or its synonym \"rsa-sha256\")\n\nThe final header of a POST request should look like:\n\n Signature: keyId=\"<uuid of your api user>\",algorithm=\"hs2019\",headers=\"(request-target) host date content-type digest\",signature=\"<base64-encoded signature>\"\n"