BUILD
ON IT.
An API that does the work.
A contract that settles it.
Full client cycle
const { KernelClient } = require('./client/http-sdk.cjs');
const client = new KernelClient({ url: 'http://127.0.0.1:4325' });
await client.loginLocal('customer'); // Local fixtures ONLY
const [project] = await client.projects();
const opened = await client.transaction(project.id, 'open', {
input: { address: '39ahtL8ynzE4amH26J29C93PA5172V3ft9UuUcqQS8fz' },
idempotency: crypto.randomUUID()
}, { local: true });
const result = await client.waitOrder(opened.order.id);
if (result.state === 'DELIVERED') {
// SDK checks encrypted bytes against the chain's hash and pinned version.
await client.accept(project.id, result.id, { local: true });
const fullReport = await client.paidResult(result.id); // decrypt + verify
}
// A source failure is REFUNDED. Missed deadlines permit a signed refund.
Wallet authentication
POST /api/auth/challenge with {wallet}. Sign the exact returned UTF-8 message with Ed25519. POST /api/auth/login with {nonce, signature: base64}. The nonce is one-use, expires in 5 minutes and binds the origin. Requests use Authorization: Bearer token. The session expires after 24 hours. Sign-in never authorizes a spend.
Transaction preparation
POST /api/projects/:id/prepare with {action, params}. Actions: launch, buy, stake, unstake, claim, withdraw, pause, close-sale, open, accept, refund, promote. Result includes an unsigned base64 Solana v0 wire transaction and review metadata. Sign the wire bytes in your wallet and POST /api/transactions/:id/submit with {wire}. The server refuses a different message or missing wallet signature. Submission is persisted before broadcasting; finality is checked before crediting execution.
buy: { amount: '1000000000', maxQuote: '1000' }
stake / unstake / withdraw: { amount: '1000000000' }
open: { input: { address: 'BASE58' }, idempotency: 'UNIQUE_SAFE_KEY' }
accept / refund: { orderId: 'ORDER_UUID' }
pause: { paused: true }
promote: { hash: '64_HEX_CANDIDATE_HASH' }
Amounts are integer strings in smallest units. Project token and configured quote use 6 decimals. A default 1,000-token primary purchase costs 0.001 fixture quote. Defaults are engineering test terms, not approved mainnet economics.
Read endpoints
GET /api/status network, quote mint, model, capabilities GET /api/projects persistent registry GET /api/projects/:id manifest, IR, onchain state, versions, events GET /api/orders authenticated buyer's orders GET /api/orders/:id sealed delivery; result/key after settlement GET /api/orders/:id/receipts paid source records (402 before settlement) GET /api/events execution tape GET /api/me current signer and actual quote balance
Evolution
POST /api/projects/generate { brief, parentId? }
POST /api/projects/:id/candidate { brief } — owner only
POST /api/projects/:id/evaluate { hash, inputs: [{address}] }
POST /api/projects/:id/prepare { action: 'promote', params: {hash} }
The actual local model generates a typed manifest. Evaluation preserves monetary terms, operations and declared history window, runs baseline/candidate on mainnet and stores receipts/metrics. Passing means the declared checks passed; it does not prove better returns, demand, or universal output correctness. Promotion requires an owner signature. Old orders stay pinned. Daughter projects have separate mints and vaults; recorded lineage does not impose a royalty on copies elsewhere.
Failure and trust boundaries
The chain protects reserved payments, payout recipients, replay and deadlines. RPC is a trusted source provider; the receipts are not a light-client proof. Results have bounded history and may explicitly list unavailable transactions. A local snapshot cannot be confused with devnet/mainnet in /api/status. HTTP mutations require a matching Origin and JSON body. The API limits body size and rate, restricts RPC methods and never accepts user-supplied execution URLs. Local fixture signing is loopback-only and disabled on public chain mode.
Before acceptance the buyer receives an AES-256-GCM encrypted report and a hash committed by the executor onchain. After settlement the API releases the key and source receipts. This prevents obtaining unpaid plaintext through this API. It relies on a trusted executor for useful content and continued key availability; ciphertext alone does not prove correct computation or atomic fair exchange. The provider may inspect its own delivery before settlement.