openapi: 3.1.0 info: title: Crown API & Webhooks Accounts Nft Transfers API version: 1.0.0 description: 'Open API 3 docs for Crown API Webhook events that Crown will POST to your configured endpoint URL. All webhooks expect a 200 OK response. Payloads use kebab-case for all keys to match the Crown API conventions.' servers: - url: https://app.crown-brlv.com description: Production server tags: - name: Nft Transfers paths: /api/v0/nft-transfers: get: responses: '200': description: NFT transfers list retrieved successfully content: application/json: schema: type: object properties: transfers: type: array items: type: object properties: id: type: string format: uuid description: Unique identifier for the NFT transfer example: 660e8400-e29b-41d4-a716-446655440010 reward-certificate-id: type: string format: uuid description: Reward certificate identifier being transferred example: 660e8400-e29b-41d4-a716-446655440010 source-address: type: string description: Source wallet address example: '0xabcdef1234567890abcdef1234567890abcdef12' target-address: type: string description: Target wallet address example: '0x1234567890abcdef1234567890abcdef12345678' state: type: string enum: - created - failed - completed - pending description: Current state of the transfer example: created created-at: type: string example: '2024-01-15T10:30:00Z' format: date-time description: ISO 8601 timestamp when the transfer was created state-updated-at: type: string example: '2024-01-15T10:30:00Z' format: date-time description: ISO 8601 timestamp when the transfer state was last updated additionalProperties: false required: - id - reward-certificate-id - source-address - target-address - state - created-at - state-updated-at description: List of reward certificate transfers additionalProperties: false required: - transfers '400': description: Bad request - Invalid input parameters content: application/json: schema: type: object properties: error: type: object properties: type: type: string message: type: string code: type: string additionalProperties: false required: - type - message - code description: Bad request error details additionalProperties: false required: - error '403': description: Forbidden - Access denied content: application/json: schema: type: object properties: error: type: object properties: type: type: string message: type: string code: type: string additionalProperties: false required: - type - message - code description: Forbidden access error details additionalProperties: false required: - error '404': description: Not found - Resource does not exist content: application/json: schema: type: object properties: error: type: object properties: type: type: string message: type: string code: type: string additionalProperties: false required: - type - message - code description: Resource not found error details additionalProperties: false required: - error '422': description: Unprocessable entity - Validation failed content: application/json: schema: type: object properties: error: type: object properties: type: type: string message: type: string code: type: string additionalProperties: false required: - type - message - code description: Validation error details additionalProperties: false required: - error summary: List reward certificate NFT transfers description: Retrieves a list of reward certificate NFT transfers for the authenticated user. tags: - Nft Transfers post: requestBody: content: application/json: schema: type: object properties: source-address: type: string description: Source wallet address (0x...) example: '0xabcdef1234567890abcdef1234567890abcdef12' target-address: type: string description: Target wallet address (0x...) example: '0x1234567890abcdef1234567890abcdef12345678' reward-certificate-id: type: string format: uuid description: Reward certificate identifier example: 660e8400-e29b-41d4-a716-446655440010 additionalProperties: false required: - source-address - target-address - reward-certificate-id responses: '200': description: NFT transfer created successfully content: application/json: schema: type: object properties: transfer: type: object properties: id: type: string format: uuid description: Unique identifier for the NFT transfer example: 660e8400-e29b-41d4-a716-446655440010 reward-certificate-id: type: string format: uuid description: Reward certificate identifier being transferred example: 660e8400-e29b-41d4-a716-446655440010 source-address: type: string description: Source wallet address example: '0xabcdef1234567890abcdef1234567890abcdef12' target-address: type: string description: Target wallet address example: '0x1234567890abcdef1234567890abcdef12345678' state: type: string enum: - created - failed - completed - pending description: Current state of the transfer example: created created-at: type: string example: '2024-01-15T10:30:00Z' format: date-time description: ISO 8601 timestamp when the transfer was created state-updated-at: type: string example: '2024-01-15T10:30:00Z' format: date-time description: ISO 8601 timestamp when the transfer state was last updated additionalProperties: false required: - id - reward-certificate-id - source-address - target-address - state - created-at - state-updated-at description: Details of the created NFT transfer additionalProperties: false required: - transfer '400': description: Bad request - Invalid input parameters content: application/json: schema: type: object properties: error: type: object properties: type: type: string message: type: string code: type: string additionalProperties: false required: - type - message - code description: Bad request error details additionalProperties: false required: - error '403': description: Forbidden - Access denied content: application/json: schema: type: object properties: error: type: object properties: type: type: string message: type: string code: type: string additionalProperties: false required: - type - message - code description: Forbidden access error details additionalProperties: false required: - error '404': description: Not found - Resource does not exist content: application/json: schema: type: object properties: error: type: object properties: type: type: string message: type: string code: type: string additionalProperties: false required: - type - message - code description: Resource not found error details additionalProperties: false required: - error '422': description: Unprocessable entity - Validation failed content: application/json: schema: type: object properties: error: type: object properties: type: type: string message: type: string code: type: string additionalProperties: false required: - type - message - code description: Validation error details additionalProperties: false required: - error summary: Transfer reward certificate NFT between wallets description: Transfers a reward certificate NFT from a source wallet to a target wallet. Source and target should be EVM wallet addresses (0x...). tags: - Nft Transfers components: securitySchemes: JwtAuth: type: http scheme: bearer bearerFormat: JWT description: JWT-based authentication. ApiKey: type: apiKey in: header name: X-API-Key description: Your account API Key signature: type: apiKey in: header name: X-Crown-Signature description: HMAC-SHA256 signature of the request body using your webhook secret. Verify this signature to ensure the webhook is from Crown. x-webhook-security: note: All webhook requests include an X-Crown-Signature header containing an HMAC-SHA256 signature of the request body. Use your webhook secret (provided when registering the webhook) to verify the signature and ensure the request is authentic. algorithm: HMAC-SHA256 header: X-Crown-Signature verification-steps: - 1. Extract the X-Crown-Signature header from the request - 2. Compute HMAC-SHA256 of the raw request body using your webhook secret - 3. Compare the computed signature with the header value - 4. Only process the webhook if signatures match example-code: node-js: "const crypto = require('crypto');\nconst signature = crypto.createHmac('sha256', webhookSecret)\n .update(JSON.stringify(requestBody))\n .digest('hex');\nconst isValid = signature === req.headers['x-crown-signature'];" python: "import hmac\nimport hashlib\nimport json\n\nsignature = hmac.new(\n webhook_secret.encode('utf-8'),\n json.dumps(request_body).encode('utf-8'),\n hashlib.sha256\n).hexdigest()\nis_valid = signature == request.headers['x-crown-signature']"