openapi: 3.2.0 info: contact: email: support@assetfare.dev name: AssetFare support url: https://assetfare.dev/security/ description: 'Agent-native, non-custodial direct-protocol quotes and caller-signed unsigned actions on 54 active routes; 44 measured routes remain inactive. Forty-four active routes publish a verified best-from amount and ten routes are availability-only with no cheapest-price claim. Solana native USDC to Base native USDC is the canonical example. Agents confirm every fresh quote before choosing. Every quote includes direct_route_summary: an intent-bound ordered provider path with normalized chain:asset endpoints, exact base-unit bounds and the AssetFare fee step. All current public routes are direct_protocol_only; external_intent remains a compatibility enum with zero current routes. route_aggregator_used=false is scoped to AssetFare''s engine and does not rule out provider-internal liquidity sourcing. The server never signs or submits. Contract 2.6.0 uses a language-neutral continuation_v3 quote-payload hash projection and server-enforced quote binding. Legacy prepare/session remain legacy_advisory; caller_approved:true alone is not proof of human approval. ActionSafetyReceiptV1 and caller-owned session capability tokens remain required.' license: name: Proprietary public API terms url: https://assetfare.dev/terms/ termsOfService: https://assetfare.dev/terms/ title: AssetFare Active-route Agent Status API version: 2.6.0 servers: - url: https://api.assetfare.dev security: [] tags: - name: Status paths: /v2/status: get: description: 'Includes a nonblocking last-known CCTP/Circle-Iris health snapshot (cctp: status available|degraded|unknown, last_success_at, age_seconds, stale, guarantees_future_availability=false). An Iris outage degrades the snapshot but never fails this endpoint.' operationId: getMultichainStatus responses: '200': description: Route health incl. last-known cctp/iris snapshot '429': description: Rate limited '503': description: Capacity busy summary: Read route health without creating a quote tags: - Status x-assetfare-evaluation-guidance: always_compare_fresh_at_intended_amount: true documentation_example_scope: example_only_not_route_guidance_or_minimum documentation_example_usd: 1000 historical_observation: evidence_as_of: '2026-09-29' not_generalizable: true observed_competitive_bucket_usd: 500 route: solana:USDC->base:USDC not_a_minimum: true not_guaranteed_best: true reachability_smoke_scope: connectivity_only_not_economic_evaluation reachability_smoke_usd: 1 route_minimum_usd: 1 route_specific_guidance: availability_only_routes: 10 catalog_routes: 98 controls_recommendation_only_when_verified: true nullable_when_unverified: true public_active_routes: 54 public_inactive_routes: 44 required_on_every_quote: true url: https://assetfare.dev/route-economics.json values_change_with_market: true verified_best_from_only: true version: assetfare-route-economic-guidance-v3 schema_version: 4 sol_input_caveat: SOL-input routes add a source swap, so compare their full fee-inclusive route economics separately. x-assetfare-safety: action_bundle_ttl_seconds: 180 action_refresh_policy: expired_unsubmitted_only action_safety_receipt_schema: ActionSafetyReceiptV1 amount_policy: no_business_maximum amount_usd_maximum: null amount_usd_minimum: 1 api_contract_version: 2.6.0 caller_approved_boolean_is_not_human_proof: true caller_approved_required_for_prepare_and_session: true caller_owned_agent_execution: a2a_remote_skill: false assetfare_server_key_access: false assetfare_server_signing: false assetfare_server_submission: false command: assetfare-agent-runner key_location: caller_wallet_adapter_only minimum_package_version: 1.15.2 package: assetfare-mcp policy_schema: https://assetfare.dev/schemas/caller-owned-execution-policy-v2.json remote_mcp_tool: false scope: caller_process_only supported: true version: assetfare-caller-owned-agent-execution-v2 wallet_adapter_contract_version: assetfare-caller-wallet-adapter-v2 caller_verifies_signs_and_submits: true continuation_v3_enforcement: server_enforced_quote_binding direct_route_summary: assetfare_fee_step_bound: true base_unit_amounts_are_decimal_strings: true classification_values: - direct_protocol_only - external_intent economic_eligibility_is_route_and_amount_conditioned: true external_coverage_only_route_count: 0 external_intent: No public route uses an external intent protocol; provider-internal liquidity sourcing or aggregation remains possible normalized_chain_asset_endpoints: true ordered_provider_path: true primary_direct_route_count: 54 product_classification_values: - primary_direct - external_coverage_only required_on_every_quote: true route_aggregator_used_scope: assetfare_engine_only route_count: 54 server_signing: false server_submission: false step_count: 95 version: assetfare-direct-route-summary-v1 external_intent_protocol: none legacy_prepare_and_session_enforcement: legacy_advisory onchain_deadline_seconds: 240 provider_internal_dex_aggregation_possible: true public: true quote_cache: bounded_thread_safe_process_local_ttl_restart_fails_closed quote_ttl_seconds: 60 receipt_generated_from: decoded_built_action_only receipt_recomputed_before_storage_return_reload_refresh: true relay_used: false release_mode: noncustodial_public_agent_release server_signing: false server_submission: false session_ownership: caller-generated high-entropy opaque capability token (X-AssetFare-Session-Token, >=256-bit CSPRNG) supplied on session create and every read/observe/refresh; the server stores only its sha256 hash, never returns or logs the raw token, and compares in constant time. Idempotency binds to (token_hash, idempotency_key), so a retry recovers a session whose create response was lost and survives an egress-IP change; the network identity is NOT the ownership secret and is used only for capacity/telemetry; sessions created under the retired network-identity model are denied (fail-closed) subjective_safe_boolean_present: false wallet_ready_minimum_remaining_seconds: 120