openapi: 3.2.0 info: title: AAAA Nexus UCAN API version: 0.5.1 description: Formally verified AI safety APIs for autonomous agents. Supports REST, MCP, A2A (Google protocol), and x402 micropayment protocol. contact: email: atomadic69@gmail.com url: https://github.com/atomadictech/aaaa-nexus servers: - url: https://atomadic.tech description: Production security: [] tags: - name: UCAN description: UCAN token creation, verification, revocation, and delegation paths: /v1/ucan/create: post: operationId: createUcan summary: Create UCAN token description: Create a new UCAN token with specified capabilities. tags: - UCAN security: - ApiKeyAuth: [] - X402PaymentProof: [] requestBody: required: true content: application/json: schema: type: object required: - issuer - audience - capabilities properties: issuer: type: string audience: type: string capabilities: type: array items: type: object expiration: type: integer description: Unix timestamp responses: '200': description: UCAN token created content: application/json: schema: type: object properties: token: type: string issuer: type: string audience: type: string expires_at: type: string format: date-time '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '402': $ref: '#/components/responses/PaymentRequired' /v1/ucan/verify: post: operationId: verifyUcan summary: Verify UCAN token description: Verify a UCAN token and its delegation chain. tags: - UCAN security: - ApiKeyAuth: [] - X402PaymentProof: [] requestBody: required: true content: application/json: schema: type: object required: - token properties: token: type: string responses: '200': description: UCAN verification result content: application/json: schema: type: object properties: valid: type: boolean issuer: type: string audience: type: string capabilities: type: array items: type: object expired: type: boolean '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '402': $ref: '#/components/responses/PaymentRequired' /v1/ucan/revoke: post: operationId: revokeUcan summary: Revoke UCAN token description: Revoke a UCAN token. tags: - UCAN security: - ApiKeyAuth: [] - X402PaymentProof: [] requestBody: required: true content: application/json: schema: type: object required: - token properties: token: type: string responses: '200': description: UCAN revoked content: application/json: schema: type: object properties: revoked: type: boolean revoked_at: type: string format: date-time '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '402': $ref: '#/components/responses/PaymentRequired' /v1/ucan/delegate: post: operationId: delegateUcan summary: Create delegated UCAN description: Create a delegated UCAN token from an existing token, narrowing capabilities. tags: - UCAN security: - ApiKeyAuth: [] - X402PaymentProof: [] requestBody: required: true content: application/json: schema: type: object required: - parent_token - audience - capabilities properties: parent_token: type: string audience: type: string capabilities: type: array items: type: object expiration: type: integer responses: '200': description: Delegated UCAN created content: application/json: schema: type: object properties: token: type: string parent_issuer: type: string audience: type: string depth: type: integer '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '402': $ref: '#/components/responses/PaymentRequired' components: responses: PaymentRequired: description: 'Payment required. Use x402 protocol: send USDC on Base L2, Polygon, or Solana to the treasury address provided in the response, then retry with the X-Payment-Proof header.' content: application/json: schema: type: object properties: error: type: string example: Payment required amount: type: string example: '0.002' currency: type: string example: USDC treasury: type: string description: Destination wallet address chains: type: array items: type: string example: - base - polygon - solana BadRequest: description: Invalid request body or missing required fields. content: application/json: schema: type: object properties: error: type: string Unauthorized: description: Missing or invalid API key. content: application/json: schema: type: object properties: error: type: string example: Unauthorized securitySchemes: ApiKeyAuth: type: apiKey in: header name: X-API-Key description: API key obtained from https://atomadic.tech/pay X402PaymentProof: type: apiKey in: header name: X-Payment-Proof description: Base64-encoded USDC payment proof for x402 autonomous payment flow (Base L2, Polygon, or Solana) AdminTokenAuth: type: apiKey in: header name: X-Admin-Token description: Admin token for privileged operations