API reference / Agent wallet

List withdrawal sources

GET/v1/users/{userId}/wallet/withdrawals/sources

Lists what the wallet can withdraw right now: each asset with a positive, transferable balance held in the agent wallet's own account, and the owner's main account a withdrawal would pay out to. Feeds wallets.prepareWithdrawal.

Authentication

Both headers are required.

  • Header: X-Api-Key: YOUR_API_KEY
  • Header: Authorization: Bearer YOUR_USER_TOKEN

Path parameters

userIdstring · uuidrequired

The user in the path; must equal the token's own account.

Validation rules
Format
"uuid"
Pattern
"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"

Request example

Illustrative request. Replace the host, credentials and resource IDs with your own. If a request file is shown, create it from the schema above. Review the requested action before sending it.

curl --request GET 'https://api.example.test/v1/users/YOUR_USER_ID/wallet/withdrawals/sources' \
  --header 'X-Api-Key: YOUR_API_KEY' \
  --header 'Authorization: Bearer YOUR_USER_TOKEN'

Responses

200 What can be withdrawn right now, and where it would go.

What can be withdrawn right now, and where it would go.

application/json · object

What the wallet can withdraw right now, and where it would go.

assetsarrayrequired

Assets the wallet holds with a positive balance and known decimals; only these can be withdrawn, richest first.

Show attributes

Assets the wallet holds with a positive balance and known decimals; only these can be withdrawn, richest first.

Array items · object
tokenIdstringrequired

Which asset this is, as the provider identifies it (for example nep141:usdc.omft.near).

Validation rules
Minimum length
1
Maximum length
512
symbolstringrequired

The asset's ticker symbol, as the provider reports it.

Validation rules
Minimum length
1
Maximum length
64
namestringrequired

The asset's display name, as the provider reports it.

Validation rules
Minimum length
1
Maximum length
256
decimalsanyOfrequired

How many decimal places amountRaw carries; null if the provider does not name this asset.

Show attributes

How many decimal places amountRaw carries; null if the provider does not name this asset.

anyOf · 2 variants
Variant 1 · integer
Validation rules
Minimum
0
Maximum
255
Variant 2 · null
amountRawstringrequired

The held amount, as a decimal string in the asset's smallest unit, never a float; scale by decimals for a human amount.

Validation rules
Maximum length
160
Pattern
"^(0|[1-9]\\d*)$"
priceUsdDecimalanyOfrequired

The asset's price in USD, as a decimal string, never a float; null if the provider has no price for it.

Show attributes

The asset's price in USD, as a decimal string, never a float; null if the provider has no price for it.

anyOf · 2 variants
Variant 1 · string
Validation rules
Maximum length
500
Pattern
"^(0|[1-9]\\d*)(\\.\\d+)?$"
Variant 2 · null
valueUsdCentsanyOfrequired

This holding's value, in US cents as a decimal integer string, never a float; null if priceUsdDecimal is null.

Show attributes

This holding's value, in US cents as a decimal integer string, never a float; null if priceUsdDecimal is null.

anyOf · 2 variants
Variant 1 · string
Validation rules
Maximum length
160
Pattern
"^(0|[1-9]\\d*)$"
Variant 2 · null
iconUrlanyOfrequired

An https icon for the asset, or null if the provider has none.

Show attributes

An https icon for the asset, or null if the provider has none.

anyOf · 2 variants
Variant 1 · string · uri
Validation rules
Format
"uri"
Variant 2 · null
mainAccountIdstringrequired

The owner's main wallet account; where a withdrawal lands. Shown for display only — the contract itself never names a destination.

agentAccountIdstringrequired

The agent wallet's own intents account; where these balances are held today.

asOfstring · date-timerequired

When these balances were read from the provider.

Validation rules
Format
"date-time"
Pattern
"^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$"
400 The request could not be read as this operation expects.

The request could not be read as this operation expects.

  • invalid_input — the body or query failed validation; issues names each field
  • invalid_cursor — the cursor is not one this list minted

application/problem+json · object

RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.

typestringrequired

The kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it

titlestringrequired

The kind's human title, for logs; never parse it

statusintegerrequired

The HTTP status, repeated in the body

Validation rules
Minimum
400
Maximum
599
reasonstringoptional

The machine-readable why. One of:

  • run_active (409) — a run already holds this conversation
  • budget_exhausted (409) — the user's spend headroom is gone, or an operator froze it
  • approval_not_pending (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation
  • execution_capacity (409) — no execution capacity is free right now; retryable says whether to try again
  • execution_unavailable (409) — the execution engine could not take the work
  • stop_pending (409) — a stop is already in progress and its cleanup is not yet confirmed
  • automation_changed (409) — the revision sent is stale; reload the automation
  • automation_held (409) — an operator holds the automation; it fires again when released
  • automation_invalid (409) — the automation's definition cannot run as written
  • automation_completed (409) — the automation has finished for good and cannot fire again
  • automation_limit (409) — the user already has as many automations as the deployment allows
  • profile_unknown_tool (409) — the run profile names a tool this deployment does not have
  • deployment_paused (409) — an operator paused a deployment control; nothing was admitted or fired
  • run_not_active (409) — the run named in the path is not the conversation's live run
  • withdrawal_changed (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress
  • credential_expired (401) — the user token has expired; obtain a fresh one
  • account_disabled (403) — an operator disabled the account
  • account_not_provisioned (412) — the identity is verified but has no account yet; call users.ensure first
  • provider_unavailable (503) — an external provider the call depends on did not answer
  • engine_unavailable (503) — the execution engine did not answer
  • invalid_input (400) — the body or query failed validation; issues names each field
  • internal (500) — a fault on our side; quote requestId when reporting it
  • partner_key_required (401) — no X-Api-Key header was sent
  • partner_key_invalid (401) — the X-Api-Key is unknown or revoked
  • subject_mismatch (403) — the {userId} in the path is not the token's user
  • origin_rejected (403) — a browser Origin other than the configured web origin
  • permission_required (403) — the operator credential lacks the scope this call needs
  • rate_limited (429) — the per-key or per-user limit is spent; honour Retry-After
  • stream_capacity (429) — no stream socket is free on this replica or for this user; honour Retry-After
  • invalid_cursor (400) — the cursor is not one this list minted
Validation rules
Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequired

The id Fin used for this request; quote it when reporting a problem

retryablebooleanrequired

Whether repeating the same request later can succeed without changing it

detailstringoptional

Only on invalid_input: which part of the request failed validation

issuesarrayoptional

Only on invalid_input: one entry per failing field

Show attributes

Only on invalid_input: one entry per failing field

Array items · object
pathstringrequired

The JSON pointer of the failing field; empty for the root object

messagestringrequired

Why the field failed

401 A credential is missing, invalid or expired.

A credential is missing, invalid or expired.

  • partner_key_required — no X-Api-Key header was sent
  • partner_key_invalid — the X-Api-Key is unknown or revoked
  • credential_expired — the user token has expired; obtain a fresh one

application/problem+json · object

RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.

typestringrequired

The kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it

titlestringrequired

The kind's human title, for logs; never parse it

statusintegerrequired

The HTTP status, repeated in the body

Validation rules
Minimum
400
Maximum
599
reasonstringoptional

The machine-readable why. One of:

  • run_active (409) — a run already holds this conversation
  • budget_exhausted (409) — the user's spend headroom is gone, or an operator froze it
  • approval_not_pending (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation
  • execution_capacity (409) — no execution capacity is free right now; retryable says whether to try again
  • execution_unavailable (409) — the execution engine could not take the work
  • stop_pending (409) — a stop is already in progress and its cleanup is not yet confirmed
  • automation_changed (409) — the revision sent is stale; reload the automation
  • automation_held (409) — an operator holds the automation; it fires again when released
  • automation_invalid (409) — the automation's definition cannot run as written
  • automation_completed (409) — the automation has finished for good and cannot fire again
  • automation_limit (409) — the user already has as many automations as the deployment allows
  • profile_unknown_tool (409) — the run profile names a tool this deployment does not have
  • deployment_paused (409) — an operator paused a deployment control; nothing was admitted or fired
  • run_not_active (409) — the run named in the path is not the conversation's live run
  • withdrawal_changed (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress
  • credential_expired (401) — the user token has expired; obtain a fresh one
  • account_disabled (403) — an operator disabled the account
  • account_not_provisioned (412) — the identity is verified but has no account yet; call users.ensure first
  • provider_unavailable (503) — an external provider the call depends on did not answer
  • engine_unavailable (503) — the execution engine did not answer
  • invalid_input (400) — the body or query failed validation; issues names each field
  • internal (500) — a fault on our side; quote requestId when reporting it
  • partner_key_required (401) — no X-Api-Key header was sent
  • partner_key_invalid (401) — the X-Api-Key is unknown or revoked
  • subject_mismatch (403) — the {userId} in the path is not the token's user
  • origin_rejected (403) — a browser Origin other than the configured web origin
  • permission_required (403) — the operator credential lacks the scope this call needs
  • rate_limited (429) — the per-key or per-user limit is spent; honour Retry-After
  • stream_capacity (429) — no stream socket is free on this replica or for this user; honour Retry-After
  • invalid_cursor (400) — the cursor is not one this list minted
Validation rules
Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequired

The id Fin used for this request; quote it when reporting a problem

retryablebooleanrequired

Whether repeating the same request later can succeed without changing it

detailstringoptional

Only on invalid_input: which part of the request failed validation

issuesarrayoptional

Only on invalid_input: one entry per failing field

Show attributes

Only on invalid_input: one entry per failing field

Array items · object
pathstringrequired

The JSON pointer of the failing field; empty for the root object

messagestringrequired

Why the field failed

403 The credentials are valid but may not do this.

The credentials are valid but may not do this.

  • subject_mismatch — the {userId} in the path is not the token's user
  • account_disabled — an operator disabled the account
  • origin_rejected — a browser Origin other than the configured web origin

application/problem+json · object

RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.

typestringrequired

The kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it

titlestringrequired

The kind's human title, for logs; never parse it

statusintegerrequired

The HTTP status, repeated in the body

Validation rules
Minimum
400
Maximum
599
reasonstringoptional

The machine-readable why. One of:

  • run_active (409) — a run already holds this conversation
  • budget_exhausted (409) — the user's spend headroom is gone, or an operator froze it
  • approval_not_pending (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation
  • execution_capacity (409) — no execution capacity is free right now; retryable says whether to try again
  • execution_unavailable (409) — the execution engine could not take the work
  • stop_pending (409) — a stop is already in progress and its cleanup is not yet confirmed
  • automation_changed (409) — the revision sent is stale; reload the automation
  • automation_held (409) — an operator holds the automation; it fires again when released
  • automation_invalid (409) — the automation's definition cannot run as written
  • automation_completed (409) — the automation has finished for good and cannot fire again
  • automation_limit (409) — the user already has as many automations as the deployment allows
  • profile_unknown_tool (409) — the run profile names a tool this deployment does not have
  • deployment_paused (409) — an operator paused a deployment control; nothing was admitted or fired
  • run_not_active (409) — the run named in the path is not the conversation's live run
  • withdrawal_changed (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress
  • credential_expired (401) — the user token has expired; obtain a fresh one
  • account_disabled (403) — an operator disabled the account
  • account_not_provisioned (412) — the identity is verified but has no account yet; call users.ensure first
  • provider_unavailable (503) — an external provider the call depends on did not answer
  • engine_unavailable (503) — the execution engine did not answer
  • invalid_input (400) — the body or query failed validation; issues names each field
  • internal (500) — a fault on our side; quote requestId when reporting it
  • partner_key_required (401) — no X-Api-Key header was sent
  • partner_key_invalid (401) — the X-Api-Key is unknown or revoked
  • subject_mismatch (403) — the {userId} in the path is not the token's user
  • origin_rejected (403) — a browser Origin other than the configured web origin
  • permission_required (403) — the operator credential lacks the scope this call needs
  • rate_limited (429) — the per-key or per-user limit is spent; honour Retry-After
  • stream_capacity (429) — no stream socket is free on this replica or for this user; honour Retry-After
  • invalid_cursor (400) — the cursor is not one this list minted
Validation rules
Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequired

The id Fin used for this request; quote it when reporting a problem

retryablebooleanrequired

Whether repeating the same request later can succeed without changing it

detailstringoptional

Only on invalid_input: which part of the request failed validation

issuesarrayoptional

Only on invalid_input: one entry per failing field

Show attributes

Only on invalid_input: one entry per failing field

Array items · object
pathstringrequired

The JSON pointer of the failing field; empty for the root object

messagestringrequired

Why the field failed

404 The resource is missing, belongs to someone else, or its id is malformed: all three answer alike.

The resource is missing, belongs to someone else, or its id is malformed: all three answer alike.

application/problem+json · object

RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.

typestringrequired

The kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it

titlestringrequired

The kind's human title, for logs; never parse it

statusintegerrequired

The HTTP status, repeated in the body

Validation rules
Minimum
400
Maximum
599
reasonstringoptional

The machine-readable why. One of:

  • run_active (409) — a run already holds this conversation
  • budget_exhausted (409) — the user's spend headroom is gone, or an operator froze it
  • approval_not_pending (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation
  • execution_capacity (409) — no execution capacity is free right now; retryable says whether to try again
  • execution_unavailable (409) — the execution engine could not take the work
  • stop_pending (409) — a stop is already in progress and its cleanup is not yet confirmed
  • automation_changed (409) — the revision sent is stale; reload the automation
  • automation_held (409) — an operator holds the automation; it fires again when released
  • automation_invalid (409) — the automation's definition cannot run as written
  • automation_completed (409) — the automation has finished for good and cannot fire again
  • automation_limit (409) — the user already has as many automations as the deployment allows
  • profile_unknown_tool (409) — the run profile names a tool this deployment does not have
  • deployment_paused (409) — an operator paused a deployment control; nothing was admitted or fired
  • run_not_active (409) — the run named in the path is not the conversation's live run
  • withdrawal_changed (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress
  • credential_expired (401) — the user token has expired; obtain a fresh one
  • account_disabled (403) — an operator disabled the account
  • account_not_provisioned (412) — the identity is verified but has no account yet; call users.ensure first
  • provider_unavailable (503) — an external provider the call depends on did not answer
  • engine_unavailable (503) — the execution engine did not answer
  • invalid_input (400) — the body or query failed validation; issues names each field
  • internal (500) — a fault on our side; quote requestId when reporting it
  • partner_key_required (401) — no X-Api-Key header was sent
  • partner_key_invalid (401) — the X-Api-Key is unknown or revoked
  • subject_mismatch (403) — the {userId} in the path is not the token's user
  • origin_rejected (403) — a browser Origin other than the configured web origin
  • permission_required (403) — the operator credential lacks the scope this call needs
  • rate_limited (429) — the per-key or per-user limit is spent; honour Retry-After
  • stream_capacity (429) — no stream socket is free on this replica or for this user; honour Retry-After
  • invalid_cursor (400) — the cursor is not one this list minted
Validation rules
Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequired

The id Fin used for this request; quote it when reporting a problem

retryablebooleanrequired

Whether repeating the same request later can succeed without changing it

detailstringoptional

Only on invalid_input: which part of the request failed validation

issuesarrayoptional

Only on invalid_input: one entry per failing field

Show attributes

Only on invalid_input: one entry per failing field

Array items · object
pathstringrequired

The JSON pointer of the failing field; empty for the root object

messagestringrequired

Why the field failed

412 The identity is verified but has no account yet.

The identity is verified but has no account yet.

  • account_not_provisioned — the identity is verified but has no account yet; call users.ensure first

application/problem+json · object

RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.

typestringrequired

The kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it

titlestringrequired

The kind's human title, for logs; never parse it

statusintegerrequired

The HTTP status, repeated in the body

Validation rules
Minimum
400
Maximum
599
reasonstringoptional

The machine-readable why. One of:

  • run_active (409) — a run already holds this conversation
  • budget_exhausted (409) — the user's spend headroom is gone, or an operator froze it
  • approval_not_pending (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation
  • execution_capacity (409) — no execution capacity is free right now; retryable says whether to try again
  • execution_unavailable (409) — the execution engine could not take the work
  • stop_pending (409) — a stop is already in progress and its cleanup is not yet confirmed
  • automation_changed (409) — the revision sent is stale; reload the automation
  • automation_held (409) — an operator holds the automation; it fires again when released
  • automation_invalid (409) — the automation's definition cannot run as written
  • automation_completed (409) — the automation has finished for good and cannot fire again
  • automation_limit (409) — the user already has as many automations as the deployment allows
  • profile_unknown_tool (409) — the run profile names a tool this deployment does not have
  • deployment_paused (409) — an operator paused a deployment control; nothing was admitted or fired
  • run_not_active (409) — the run named in the path is not the conversation's live run
  • withdrawal_changed (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress
  • credential_expired (401) — the user token has expired; obtain a fresh one
  • account_disabled (403) — an operator disabled the account
  • account_not_provisioned (412) — the identity is verified but has no account yet; call users.ensure first
  • provider_unavailable (503) — an external provider the call depends on did not answer
  • engine_unavailable (503) — the execution engine did not answer
  • invalid_input (400) — the body or query failed validation; issues names each field
  • internal (500) — a fault on our side; quote requestId when reporting it
  • partner_key_required (401) — no X-Api-Key header was sent
  • partner_key_invalid (401) — the X-Api-Key is unknown or revoked
  • subject_mismatch (403) — the {userId} in the path is not the token's user
  • origin_rejected (403) — a browser Origin other than the configured web origin
  • permission_required (403) — the operator credential lacks the scope this call needs
  • rate_limited (429) — the per-key or per-user limit is spent; honour Retry-After
  • stream_capacity (429) — no stream socket is free on this replica or for this user; honour Retry-After
  • invalid_cursor (400) — the cursor is not one this list minted
Validation rules
Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequired

The id Fin used for this request; quote it when reporting a problem

retryablebooleanrequired

Whether repeating the same request later can succeed without changing it

detailstringoptional

Only on invalid_input: which part of the request failed validation

issuesarrayoptional

Only on invalid_input: one entry per failing field

Show attributes

Only on invalid_input: one entry per failing field

Array items · object
pathstringrequired

The JSON pointer of the failing field; empty for the root object

messagestringrequired

Why the field failed

429 A limiter refused the request; honour `Retry-After`.

A limiter refused the request; honour Retry-After.

  • rate_limited — the per-key or per-user limit is spent; honour Retry-After

application/problem+json · object

RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.

typestringrequired

The kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it

titlestringrequired

The kind's human title, for logs; never parse it

statusintegerrequired

The HTTP status, repeated in the body

Validation rules
Minimum
400
Maximum
599
reasonstringoptional

The machine-readable why. One of:

  • run_active (409) — a run already holds this conversation
  • budget_exhausted (409) — the user's spend headroom is gone, or an operator froze it
  • approval_not_pending (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation
  • execution_capacity (409) — no execution capacity is free right now; retryable says whether to try again
  • execution_unavailable (409) — the execution engine could not take the work
  • stop_pending (409) — a stop is already in progress and its cleanup is not yet confirmed
  • automation_changed (409) — the revision sent is stale; reload the automation
  • automation_held (409) — an operator holds the automation; it fires again when released
  • automation_invalid (409) — the automation's definition cannot run as written
  • automation_completed (409) — the automation has finished for good and cannot fire again
  • automation_limit (409) — the user already has as many automations as the deployment allows
  • profile_unknown_tool (409) — the run profile names a tool this deployment does not have
  • deployment_paused (409) — an operator paused a deployment control; nothing was admitted or fired
  • run_not_active (409) — the run named in the path is not the conversation's live run
  • withdrawal_changed (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress
  • credential_expired (401) — the user token has expired; obtain a fresh one
  • account_disabled (403) — an operator disabled the account
  • account_not_provisioned (412) — the identity is verified but has no account yet; call users.ensure first
  • provider_unavailable (503) — an external provider the call depends on did not answer
  • engine_unavailable (503) — the execution engine did not answer
  • invalid_input (400) — the body or query failed validation; issues names each field
  • internal (500) — a fault on our side; quote requestId when reporting it
  • partner_key_required (401) — no X-Api-Key header was sent
  • partner_key_invalid (401) — the X-Api-Key is unknown or revoked
  • subject_mismatch (403) — the {userId} in the path is not the token's user
  • origin_rejected (403) — a browser Origin other than the configured web origin
  • permission_required (403) — the operator credential lacks the scope this call needs
  • rate_limited (429) — the per-key or per-user limit is spent; honour Retry-After
  • stream_capacity (429) — no stream socket is free on this replica or for this user; honour Retry-After
  • invalid_cursor (400) — the cursor is not one this list minted
Validation rules
Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequired

The id Fin used for this request; quote it when reporting a problem

retryablebooleanrequired

Whether repeating the same request later can succeed without changing it

detailstringoptional

Only on invalid_input: which part of the request failed validation

issuesarrayoptional

Only on invalid_input: one entry per failing field

Show attributes

Only on invalid_input: one entry per failing field

Array items · object
pathstringrequired

The JSON pointer of the failing field; empty for the root object

messagestringrequired

Why the field failed

500 A fault on our side; quote `requestId` when reporting it.

A fault on our side; quote requestId when reporting it.

  • internal — a fault on our side; quote requestId when reporting it

application/problem+json · object

RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.

typestringrequired

The kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it

titlestringrequired

The kind's human title, for logs; never parse it

statusintegerrequired

The HTTP status, repeated in the body

Validation rules
Minimum
400
Maximum
599
reasonstringoptional

The machine-readable why. One of:

  • run_active (409) — a run already holds this conversation
  • budget_exhausted (409) — the user's spend headroom is gone, or an operator froze it
  • approval_not_pending (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation
  • execution_capacity (409) — no execution capacity is free right now; retryable says whether to try again
  • execution_unavailable (409) — the execution engine could not take the work
  • stop_pending (409) — a stop is already in progress and its cleanup is not yet confirmed
  • automation_changed (409) — the revision sent is stale; reload the automation
  • automation_held (409) — an operator holds the automation; it fires again when released
  • automation_invalid (409) — the automation's definition cannot run as written
  • automation_completed (409) — the automation has finished for good and cannot fire again
  • automation_limit (409) — the user already has as many automations as the deployment allows
  • profile_unknown_tool (409) — the run profile names a tool this deployment does not have
  • deployment_paused (409) — an operator paused a deployment control; nothing was admitted or fired
  • run_not_active (409) — the run named in the path is not the conversation's live run
  • withdrawal_changed (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress
  • credential_expired (401) — the user token has expired; obtain a fresh one
  • account_disabled (403) — an operator disabled the account
  • account_not_provisioned (412) — the identity is verified but has no account yet; call users.ensure first
  • provider_unavailable (503) — an external provider the call depends on did not answer
  • engine_unavailable (503) — the execution engine did not answer
  • invalid_input (400) — the body or query failed validation; issues names each field
  • internal (500) — a fault on our side; quote requestId when reporting it
  • partner_key_required (401) — no X-Api-Key header was sent
  • partner_key_invalid (401) — the X-Api-Key is unknown or revoked
  • subject_mismatch (403) — the {userId} in the path is not the token's user
  • origin_rejected (403) — a browser Origin other than the configured web origin
  • permission_required (403) — the operator credential lacks the scope this call needs
  • rate_limited (429) — the per-key or per-user limit is spent; honour Retry-After
  • stream_capacity (429) — no stream socket is free on this replica or for this user; honour Retry-After
  • invalid_cursor (400) — the cursor is not one this list minted
Validation rules
Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequired

The id Fin used for this request; quote it when reporting a problem

retryablebooleanrequired

Whether repeating the same request later can succeed without changing it

detailstringoptional

Only on invalid_input: which part of the request failed validation

issuesarrayoptional

Only on invalid_input: one entry per failing field

Show attributes

Only on invalid_input: one entry per failing field

Array items · object
pathstringrequired

The JSON pointer of the failing field; empty for the root object

messagestringrequired

Why the field failed

503 The replica is draining or a dependency did not answer; `retryable` says whether to try again.

The replica is draining or a dependency did not answer; retryable says whether to try again.

  • internal — a fault on our side; quote requestId when reporting it
  • provider_unavailable — an external provider the call depends on did not answer

application/problem+json · object

RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.

typestringrequired

The kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it

titlestringrequired

The kind's human title, for logs; never parse it

statusintegerrequired

The HTTP status, repeated in the body

Validation rules
Minimum
400
Maximum
599
reasonstringoptional

The machine-readable why. One of:

  • run_active (409) — a run already holds this conversation
  • budget_exhausted (409) — the user's spend headroom is gone, or an operator froze it
  • approval_not_pending (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation
  • execution_capacity (409) — no execution capacity is free right now; retryable says whether to try again
  • execution_unavailable (409) — the execution engine could not take the work
  • stop_pending (409) — a stop is already in progress and its cleanup is not yet confirmed
  • automation_changed (409) — the revision sent is stale; reload the automation
  • automation_held (409) — an operator holds the automation; it fires again when released
  • automation_invalid (409) — the automation's definition cannot run as written
  • automation_completed (409) — the automation has finished for good and cannot fire again
  • automation_limit (409) — the user already has as many automations as the deployment allows
  • profile_unknown_tool (409) — the run profile names a tool this deployment does not have
  • deployment_paused (409) — an operator paused a deployment control; nothing was admitted or fired
  • run_not_active (409) — the run named in the path is not the conversation's live run
  • withdrawal_changed (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress
  • credential_expired (401) — the user token has expired; obtain a fresh one
  • account_disabled (403) — an operator disabled the account
  • account_not_provisioned (412) — the identity is verified but has no account yet; call users.ensure first
  • provider_unavailable (503) — an external provider the call depends on did not answer
  • engine_unavailable (503) — the execution engine did not answer
  • invalid_input (400) — the body or query failed validation; issues names each field
  • internal (500) — a fault on our side; quote requestId when reporting it
  • partner_key_required (401) — no X-Api-Key header was sent
  • partner_key_invalid (401) — the X-Api-Key is unknown or revoked
  • subject_mismatch (403) — the {userId} in the path is not the token's user
  • origin_rejected (403) — a browser Origin other than the configured web origin
  • permission_required (403) — the operator credential lacks the scope this call needs
  • rate_limited (429) — the per-key or per-user limit is spent; honour Retry-After
  • stream_capacity (429) — no stream socket is free on this replica or for this user; honour Retry-After
  • invalid_cursor (400) — the cursor is not one this list minted
Validation rules
Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequired

The id Fin used for this request; quote it when reporting a problem

retryablebooleanrequired

Whether repeating the same request later can succeed without changing it

detailstringoptional

Only on invalid_input: which part of the request failed validation

issuesarrayoptional

Only on invalid_input: one entry per failing field

Show attributes

Only on invalid_input: one entry per failing field

Array items · object
pathstringrequired

The JSON pointer of the failing field; empty for the root object

messagestringrequired

Why the field failed

Complete OpenAPI definition

The exact operation and all referenced components, including recursive schemas.

{
  "operation": {
    "operationId": "wallets.withdrawalSources",
    "summary": "List withdrawal sources",
    "tags": [
      "wallets"
    ],
    "description": "Lists what the wallet can withdraw right now: each asset with a positive, transferable balance held in the agent wallet's own account, and the owner's main account a withdrawal would pay out to. Feeds `wallets.prepareWithdrawal`.",
    "parameters": [
      {
        "schema": {
          "type": "string",
          "format": "uuid",
          "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
        },
        "in": "path",
        "name": "userId",
        "required": true,
        "description": "The user in the path; must equal the token's own account."
      }
    ],
    "security": [
      {
        "apiKey": [],
        "userToken": []
      }
    ],
    "responses": {
      "200": {
        "description": "What can be withdrawn right now, and where it would go.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/WithdrawalSources"
            }
          }
        }
      },
      "400": {
        "$ref": "#/components/responses/InvalidInput"
      },
      "401": {
        "$ref": "#/components/responses/Unauthorized"
      },
      "403": {
        "$ref": "#/components/responses/Forbidden"
      },
      "404": {
        "$ref": "#/components/responses/NotFound"
      },
      "412": {
        "$ref": "#/components/responses/AccountNotProvisioned"
      },
      "429": {
        "$ref": "#/components/responses/TooManyRequests"
      },
      "500": {
        "$ref": "#/components/responses/Internal"
      },
      "503": {
        "description": "The replica is draining or a dependency did not answer; `retryable` says whether to try again.\n\n- `internal` — a fault on our side; quote `requestId` when reporting it\n- `provider_unavailable` — an external provider the call depends on did not answer",
        "content": {
          "application/problem+json": {
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "WithdrawalSources": {
        "type": "object",
        "properties": {
          "assets": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "tokenId": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 512,
                  "description": "Which asset this is, as the provider identifies it (for example `nep141:usdc.omft.near`)."
                },
                "symbol": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 64,
                  "description": "The asset's ticker symbol, as the provider reports it."
                },
                "name": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 256,
                  "description": "The asset's display name, as the provider reports it."
                },
                "decimals": {
                  "anyOf": [
                    {
                      "type": "integer",
                      "minimum": 0,
                      "maximum": 255
                    },
                    {
                      "type": "null"
                    }
                  ],
                  "description": "How many decimal places `amountRaw` carries; `null` if the provider does not name this asset."
                },
                "amountRaw": {
                  "type": "string",
                  "maxLength": 160,
                  "pattern": "^(0|[1-9]\\d*)$",
                  "description": "The held amount, as a decimal string in the asset's smallest unit, never a float; scale by `decimals` for a human amount."
                },
                "priceUsdDecimal": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 500,
                      "pattern": "^(0|[1-9]\\d*)(\\.\\d+)?$"
                    },
                    {
                      "type": "null"
                    }
                  ],
                  "description": "The asset's price in USD, as a decimal string, never a float; `null` if the provider has no price for it."
                },
                "valueUsdCents": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 160,
                      "pattern": "^(0|[1-9]\\d*)$"
                    },
                    {
                      "type": "null"
                    }
                  ],
                  "description": "This holding's value, in US cents as a decimal integer string, never a float; `null` if `priceUsdDecimal` is `null`."
                },
                "iconUrl": {
                  "anyOf": [
                    {
                      "type": "string",
                      "format": "uri"
                    },
                    {
                      "type": "null"
                    }
                  ],
                  "description": "An https icon for the asset, or `null` if the provider has none."
                }
              },
              "required": [
                "tokenId",
                "symbol",
                "name",
                "decimals",
                "amountRaw",
                "priceUsdDecimal",
                "valueUsdCents",
                "iconUrl"
              ]
            },
            "description": "Assets the wallet holds with a positive balance and known decimals; only these can be withdrawn, richest first."
          },
          "mainAccountId": {
            "type": "string",
            "description": "The owner's main wallet account; where a withdrawal lands. Shown for display only — the contract itself never names a destination."
          },
          "agentAccountId": {
            "type": "string",
            "description": "The agent wallet's own intents account; where these balances are held today."
          },
          "asOf": {
            "type": "string",
            "format": "date-time",
            "pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$",
            "description": "When these balances were read from the provider."
          }
        },
        "required": [
          "assets",
          "mainAccountId",
          "agentAccountId",
          "asOf"
        ],
        "description": "What the wallet can withdraw right now, and where it would go."
      },
      "ProblemDetails": {
        "type": "object",
        "properties": {
          "type": {
            "type": "string",
            "description": "The kind of problem as a URN, `urn:fin:error:<kind>`; stable, compare against it"
          },
          "title": {
            "type": "string",
            "description": "The kind's human title, for logs; never parse it"
          },
          "status": {
            "type": "integer",
            "minimum": 400,
            "maximum": 599,
            "description": "The HTTP status, repeated in the body"
          },
          "reason": {
            "description": "The machine-readable why. One of:\n\n- `run_active` (409) — a run already holds this conversation\n- `budget_exhausted` (409) — the user's spend headroom is gone, or an operator froze it\n- `approval_not_pending` (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation\n- `execution_capacity` (409) — no execution capacity is free right now; `retryable` says whether to try again\n- `execution_unavailable` (409) — the execution engine could not take the work\n- `stop_pending` (409) — a stop is already in progress and its cleanup is not yet confirmed\n- `automation_changed` (409) — the `revision` sent is stale; reload the automation\n- `automation_held` (409) — an operator holds the automation; it fires again when released\n- `automation_invalid` (409) — the automation's definition cannot run as written\n- `automation_completed` (409) — the automation has finished for good and cannot fire again\n- `automation_limit` (409) — the user already has as many automations as the deployment allows\n- `profile_unknown_tool` (409) — the run profile names a tool this deployment does not have\n- `deployment_paused` (409) — an operator paused a deployment control; nothing was admitted or fired\n- `run_not_active` (409) — the run named in the path is not the conversation's live run\n- `withdrawal_changed` (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress\n- `credential_expired` (401) — the user token has expired; obtain a fresh one\n- `account_disabled` (403) — an operator disabled the account\n- `account_not_provisioned` (412) — the identity is verified but has no account yet; call `users.ensure` first\n- `provider_unavailable` (503) — an external provider the call depends on did not answer\n- `engine_unavailable` (503) — the execution engine did not answer\n- `invalid_input` (400) — the body or query failed validation; `issues` names each field\n- `internal` (500) — a fault on our side; quote `requestId` when reporting it\n- `partner_key_required` (401) — no `X-Api-Key` header was sent\n- `partner_key_invalid` (401) — the `X-Api-Key` is unknown or revoked\n- `subject_mismatch` (403) — the `{userId}` in the path is not the token's user\n- `origin_rejected` (403) — a browser `Origin` other than the configured web origin\n- `permission_required` (403) — the operator credential lacks the scope this call needs\n- `rate_limited` (429) — the per-key or per-user limit is spent; honour `Retry-After`\n- `stream_capacity` (429) — no stream socket is free on this replica or for this user; honour `Retry-After`\n- `invalid_cursor` (400) — the `cursor` is not one this list minted",
            "type": "string",
            "enum": [
              "run_active",
              "budget_exhausted",
              "approval_not_pending",
              "execution_capacity",
              "execution_unavailable",
              "stop_pending",
              "automation_changed",
              "automation_held",
              "automation_invalid",
              "automation_completed",
              "automation_limit",
              "profile_unknown_tool",
              "deployment_paused",
              "run_not_active",
              "withdrawal_changed",
              "credential_expired",
              "account_disabled",
              "account_not_provisioned",
              "provider_unavailable",
              "engine_unavailable",
              "invalid_input",
              "internal",
              "partner_key_required",
              "partner_key_invalid",
              "subject_mismatch",
              "origin_rejected",
              "permission_required",
              "rate_limited",
              "stream_capacity",
              "invalid_cursor"
            ]
          },
          "requestId": {
            "type": "string",
            "description": "The id Fin used for this request; quote it when reporting a problem"
          },
          "retryable": {
            "type": "boolean",
            "description": "Whether repeating the same request later can succeed without changing it"
          },
          "detail": {
            "description": "Only on `invalid_input`: which part of the request failed validation",
            "type": "string"
          },
          "issues": {
            "description": "Only on `invalid_input`: one entry per failing field",
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "path": {
                  "type": "string",
                  "description": "The JSON pointer of the failing field; empty for the root object"
                },
                "message": {
                  "type": "string",
                  "description": "Why the field failed"
                }
              },
              "required": [
                "path",
                "message"
              ]
            }
          }
        },
        "required": [
          "type",
          "title",
          "status",
          "requestId",
          "retryable"
        ],
        "description": "RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack."
      }
    },
    "responses": {
      "InvalidInput": {
        "description": "The request could not be read as this operation expects.\n\n- `invalid_input` — the body or query failed validation; `issues` names each field\n- `invalid_cursor` — the `cursor` is not one this list minted",
        "content": {
          "application/problem+json": {
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        }
      },
      "Unauthorized": {
        "description": "A credential is missing, invalid or expired.\n\n- `partner_key_required` — no `X-Api-Key` header was sent\n- `partner_key_invalid` — the `X-Api-Key` is unknown or revoked\n- `credential_expired` — the user token has expired; obtain a fresh one",
        "content": {
          "application/problem+json": {
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        }
      },
      "Forbidden": {
        "description": "The credentials are valid but may not do this.\n\n- `subject_mismatch` — the `{userId}` in the path is not the token's user\n- `account_disabled` — an operator disabled the account\n- `origin_rejected` — a browser `Origin` other than the configured web origin",
        "content": {
          "application/problem+json": {
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        }
      },
      "NotFound": {
        "description": "The resource is missing, belongs to someone else, or its id is malformed: all three answer alike.",
        "content": {
          "application/problem+json": {
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        }
      },
      "AccountNotProvisioned": {
        "description": "The identity is verified but has no account yet.\n\n- `account_not_provisioned` — the identity is verified but has no account yet; call `users.ensure` first",
        "content": {
          "application/problem+json": {
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        }
      },
      "TooManyRequests": {
        "description": "A limiter refused the request; honour `Retry-After`.\n\n- `rate_limited` — the per-key or per-user limit is spent; honour `Retry-After`",
        "content": {
          "application/problem+json": {
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        }
      },
      "Internal": {
        "description": "A fault on our side; quote `requestId` when reporting it.\n\n- `internal` — a fault on our side; quote `requestId` when reporting it",
        "content": {
          "application/problem+json": {
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        }
      }
    },
    "securitySchemes": {
      "apiKey": {
        "type": "apiKey",
        "in": "header",
        "name": "X-Api-Key"
      },
      "userToken": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "JWT"
      }
    }
  }
}
Fin documentation Built from the API contract · v1

Search all documentation