# Kusama > Kusama is the permissionless canary network of the Polkadot ecosystem — the same Polkadot SDK > (Substrate/FRAME) runtime as Polkadot, but with faster governance and real economic stakes. Runtime > upgrades and coretime/parachain mechanics ship here first. Native token KSM (12 decimals, SS58 prefix 2). Generated by the API Evangelist enrichment pipeline on 2026-07-19 from live probes and the provider's published specifications. Kusama publishes no llms.txt of its own (kusama.network/llms.txt returned 404 on 2026-07-19); the Polkadot developer docs do publish one at https://docs.polkadot.com/llms.txt, which covers the ecosystem rather than Kusama specifically. ## What you are integrating with Kusama is a blockchain, not a hosted SaaS API. There is no signup, no API key, no tenant, and no vendor support contract. Two public interfaces expose it: 1. **JSON-RPC 2.0** at `https://kusama-rpc.polkadot.io/` (HTTP POST) and `wss://kusama-rpc.polkadot.io` (WebSocket, required for subscriptions). 130 methods advertised live on 2026-07-19. 2. **REST (Substrate API Sidecar)** at `https://kusama-public-sidecar.parity-chains.parity.io/`. 119 operations described by OpenAPI 3.0. Both are unauthenticated. Both are best-effort community infrastructure with no published SLA or rate limits. Production consumers should run their own node or use a commercial RPC provider. ## Things that will bite you - **Kusama is not a testnet.** KSM has real market value; transactions are irreversible; validators are really slashed. Use Westend (`https://westend-rpc.polkadot.io/`, faucet at https://faucet.polkadot.io/) or a Chopsticks fork for testing. - **Numbers are strings.** Balances and block heights exceed IEEE-754 safe integer range. Parse with BigInt or a decimal library, never `JSON.parse` into a JS number. - **Balances are in Planck.** 1 KSM = 10^12 Planck. Only the `denominated` parameter returns human scale. - **Pin `at`.** 70 of 119 REST operations accept an `at` parameter (block height or hash). Omitting it reads a head that moves every ~6 seconds. Two reads without `at` are not consistent with each other. - **HTTP 200 on submission does not mean success.** It means accepted into the transaction pool. Inclusion and on-chain success are separate; inspect the `ExtrinsicSuccess` / `ExtrinsicFailed` event. - **Best-chain blocks can reorg.** Subscribe to `chain_subscribeFinalizedHeads`, not `newHeads`, for anything financial. - **Wrong-network addresses are silent bugs.** A Polkadot address (SS58 prefix 0) is a well-formed string but a different account. Validate with `GET /accounts/{address}/validate`. - **Runtime upgrades break encoding.** A `transactionVersion` bump invalidates cached metadata. Subscribe to `state_subscribeRuntimeVersion` and re-fetch. - **Errors are not RFC 9457.** REST returns `{code, message, stack}`; the `stack` field leaks internal paths. JSON-RPC returns the standard JSON-RPC 2.0 error object. - **The REST API is deprecated.** `substrate-api-sidecar` is superseded by `polkadot-rest-api`, a Rust rewrite with 1:1 compatibility under `/v1/`. ## Idempotency There is no `Idempotency-Key` header, and none is needed. Every signed extrinsic embeds the signing account's nonce; the runtime executes a given (account, nonce) pair at most once, and the nonce is bound inside the signature. Extrinsics are also mortal — they commit to a starting block hash and a validity era, bounding how long a retry can stay in flight. On a submission timeout, re-broadcast the *same signed payload*; do not re-sign with a fresh nonce, which is how double-submits happen. ## Repository artifacts - [apis.yml](apis.yml): APIs.json index for this provider - [OpenAPI — Sidecar REST](openapi/kusama-sidecar-openapi.yaml): 119 operations, 156 schemas, v20.14.1 - [AsyncAPI — JSON-RPC subscriptions](asyncapi/kusama-jsonrpc-asyncapi.yml): the 13 subscription methods - [Overlay](overlays/kusama-sidecar-overlay.yaml): our enhancements over the published spec - [Conventions](conventions/kusama-conventions.yml): idempotency, `at` pinning, pagination, data types - [Authentication](authentication/kusama-authentication.yml): why there is none, and how signing works - [Errors](errors/kusama-problem-types.yml): both envelopes, plus the extrinsic-failure distinction - [Data model](data-model/kusama-data-model.yml): entity graph derived from the spec - [Lifecycle](lifecycle/kusama-lifecycle.yml): versioning, deprecations, liveness - [Changelog](changelog/kusama-changelog.yml): dated release history - [Conformance](conformance/kusama-conformance.yml): which standards this does and does not implement - [Sandbox](sandbox/kusama-sandbox.yml): Westend, Chopsticks, dry-run endpoints - [Packages](packages/kusama-packages.yml): client libraries across JS, Python, Rust - [CLI](cli/kusama-cli.yml): polkadot, subxt-cli, polkadot-api - [MCP](mcp/kusama-mcp.yml): candidate read-only tool surface - [Security](security/kusama-vulnerability-disclosure.yml): Parity's disclosure program and bug bounty - [Domain security](security/kusama-domain-security.yml): TLS/DNSSEC/SPF/DMARC probe results - [Examples](examples/kusama-jsonrpc-examples.json): verbatim live request/response captures - [Agent skills](skills/_index.yml): packaged operating instructions for common flows ## Official documentation - Polkadot developer docs: https://docs.polkadot.com/ - Chain interactions: https://docs.polkadot.com/chain-interactions/ - Query on-chain state with the Sidecar REST API: https://docs.polkadot.com/chain-interactions/query-data/query-rest/ - JSON-RPC interface specification: https://paritytech.github.io/json-rpc-interface-spec/ - Kusama getting started: https://wiki.polkadot.com/kusama/kusama-getting-started/ - Polkadot-JS API docs: https://polkadot.js.org/docs/api/ - Support: https://docs.polkadot.com/get-support/ - Polkadot developer docs llms.txt: https://docs.polkadot.com/llms.txt ## Governance and community - Kusama OpenGov (SubSquare): https://kusama.subsquare.io/ - Kusama OpenGov (Polkassembly): https://kusama.polkassembly.io/ - Polkadot Forum, Kusama tag: https://forum.polkadot.network/tag/kusama - Runtime source (Polkadot Fellowship): https://github.com/polkadot-fellows/runtimes - Polkadot SDK: https://github.com/paritytech/polkadot-sdk ## Security - Polkadot Security Hub: https://security.parity.io/ - Vulnerability disclosures: https://security.parity.io/disclosures - Audits: https://security.parity.io/audits - Bug bounty (Kusama runtime explicitly in scope): https://parity.io/bug-bounty - Security policy: https://github.com/paritytech/polkadot-sdk/blob/master/docs/contributor/SECURITY.md