Fipto · OpenAPI Overlay 1.0.0

API Evangelist enhancements for the Fipto API

8 actions 8 updates documentation extends openapi/fipto-customer-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Fipto's API. It is a proposal applied on top of the contract, not a document Fipto publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-agent-notex-idempotentx-apievangelist-profilex-apievangelist-reviewedx-contract-sourcex-auth-not-declared-in-specsecuritySchemessecurity

Targets 8

$.info
$.servers
$.components
$
$.paths['/companies/{company_id}/wallets/{wallet_id}/payin-simulation'].post
$.paths['/companies/{company_id}/wallets/{wallet_id}/payouts'].post
$.paths['/companies/{company_id}/wallets/{wallet_id}/internal-transfers'].post
$.paths['/companies/{company_id}/quotes'].post

OpenAPI Overlay

Raw ↑
overlay: 1.0.0
info:
  title: API Evangelist enhancements for the Fipto API
  version: 1.0.0
extends: openapi/fipto-customer-api-openapi.yml
x-provenance:
  generated: '2026-08-17'
  method: generated
  source: openapi/fipto-customer-api-openapi.yml
  note: >-
    Non-destructive enhancements to the harvested Fipto contract. The original is preserved verbatim at
    openapi/_original/fipto-customer-api-openapi.json. The single most consequential gap this overlay
    closes is the missing securitySchemes block — the published spec declares no authentication at all,
    while every operation requires an RSA HTTP message signature. The scheme added here is transcribed
    from Fipto's own authentication guide, not invented.
actions:
- target: $.info
  update:
    x-apievangelist-profile: https://apis.io/provider/fipto
    x-apievangelist-reviewed: '2026-08-17'
    x-contract-source: https://docs.fipto.com/reference/getting-started
    x-auth-not-declared-in-spec: true
- target: $.servers
  update:
  - url: https://api.fipto.app
    description: The API server on production
  - url: https://api.demo.fipto.tech
    description: The API server on the demo environment (documented at
      https://docs.fipto.com/docs/api-authentication but absent from the published servers block)
- target: $.components
  update:
    securitySchemes:
      httpSignature:
        type: http
        scheme: signature
        description: >-
          RSA HTTP message signature per draft-cavage-http-signatures-12. The Signature header carries
          keyId (the UUID of your Fipto API user), algorithm "hs2019", and a signature over
          (request-target), host, date, and — on bodied requests — content-type and digest. See
          https://docs.fipto.com/docs/api-authentication. NOT declared in the provider's own spec;
          added by API Evangelist so the contract is self-describing.
        x-added-by: api-evangelist
        x-source: https://docs.fipto.com/docs/api-authentication
- target: $
  update:
    security:
    - httpSignature: []
    x-webhooks-documented: https://docs.fipto.com/docs/webhooks
    x-mcp-server: https://github.com/fipto/mcp-fipto
- target: $.paths['/companies/{company_id}/wallets/{wallet_id}/payin-simulation'].post
  update:
    x-environment: demo-only
    x-sandbox: true
    description: >-
      Generate a payin on the demo environment. Note that it may take up to 1 minute for the payin to
      appear in the transactions list. By default, the payin will target the first wallet details
      created within the wallet. This operation exists only on https://api.demo.fipto.tech.
- target: $.paths['/companies/{company_id}/wallets/{wallet_id}/payouts'].post
  update:
    x-idempotent: false
    x-agent-note: >-
      No idempotency key is accepted. A retried payout may duplicate. A 2xx does not mean settled —
      poll the transaction status, which can be "awaiting co-signer" or "awaiting approval".
- target: $.paths['/companies/{company_id}/wallets/{wallet_id}/internal-transfers'].post
  update:
    x-idempotent: false
    x-agent-note: No idempotency key is accepted. Retry is not safe without first reconciling by
      searching transactions.
- target: $.paths['/companies/{company_id}/quotes'].post
  update:
    x-agent-note: >-
      A quote is time-limited. It must be confirmed via confirmQuoteStatus before it executes, and can
      return "Quote is expired" or "Quote already validated".