KKERNEL / DEVELOPER APIBACK TO LAB ↗
ONE FUNCTION / ONE RECEIPT / ONE SETTLEMENT

BUILD
ON IT.

An API that does the work.
A contract that settles it.

Default network: local SBF fixture assets. Data: actual Solana mainnet. Review /api/status before any signature.

Full client cycle

const { KernelClient } = require('./client/http-sdk.cjs');
const client = new KernelClient({ url: 'http://127.0.0.1:4325' });
await client.loginLocal('customer'); // Local fixtures ONLY
const [project] = await client.projects();
const opened = await client.transaction(project.id, 'open', {
  input: { address: '39ahtL8ynzE4amH26J29C93PA5172V3ft9UuUcqQS8fz' },
  idempotency: crypto.randomUUID()
}, { local: true });
const result = await client.waitOrder(opened.order.id);
if (result.state === 'DELIVERED') {
  // SDK checks encrypted bytes against the chain's hash and pinned version.
  await client.accept(project.id, result.id, { local: true });
  const fullReport = await client.paidResult(result.id); // decrypt + verify
}
// A source failure is REFUNDED. Missed deadlines permit a signed refund.

Wallet authentication

POST /api/auth/challenge with {wallet}. Sign the exact returned UTF-8 message with Ed25519. POST /api/auth/login with {nonce, signature: base64}. The nonce is one-use, expires in 5 minutes and binds the origin. Requests use Authorization: Bearer token. The session expires after 24 hours. Sign-in never authorizes a spend.

Transaction preparation

POST /api/projects/:id/prepare with {action, params}. Actions: launch, buy, stake, unstake, claim, withdraw, pause, close-sale, open, accept, refund, promote. Result includes an unsigned base64 Solana v0 wire transaction and review metadata. Sign the wire bytes in your wallet and POST /api/transactions/:id/submit with {wire}. The server refuses a different message or missing wallet signature. Submission is persisted before broadcasting; finality is checked before crediting execution.

buy: { amount: '1000000000', maxQuote: '1000' }
stake / unstake / withdraw: { amount: '1000000000' }
open: { input: { address: 'BASE58' }, idempotency: 'UNIQUE_SAFE_KEY' }
accept / refund: { orderId: 'ORDER_UUID' }
pause: { paused: true }
promote: { hash: '64_HEX_CANDIDATE_HASH' }

Amounts are integer strings in smallest units. Project token and configured quote use 6 decimals. A default 1,000-token primary purchase costs 0.001 fixture quote. Defaults are engineering test terms, not approved mainnet economics.

Read endpoints

GET /api/status                    network, quote mint, model, capabilities
GET /api/projects                  persistent registry
GET /api/projects/:id              manifest, IR, onchain state, versions, events
GET /api/orders                    authenticated buyer's orders
GET /api/orders/:id                sealed delivery; result/key after settlement
GET /api/orders/:id/receipts        paid source records (402 before settlement)
GET /api/events                    execution tape
GET /api/me                        current signer and actual quote balance

Evolution

POST /api/projects/generate        { brief, parentId? }
POST /api/projects/:id/candidate    { brief } — owner only
POST /api/projects/:id/evaluate     { hash, inputs: [{address}] }
POST /api/projects/:id/prepare      { action: 'promote', params: {hash} }

The actual local model generates a typed manifest. Evaluation preserves monetary terms, operations and declared history window, runs baseline/candidate on mainnet and stores receipts/metrics. Passing means the declared checks passed; it does not prove better returns, demand, or universal output correctness. Promotion requires an owner signature. Old orders stay pinned. Daughter projects have separate mints and vaults; recorded lineage does not impose a royalty on copies elsewhere.

Failure and trust boundaries

The chain protects reserved payments, payout recipients, replay and deadlines. RPC is a trusted source provider; the receipts are not a light-client proof. Results have bounded history and may explicitly list unavailable transactions. A local snapshot cannot be confused with devnet/mainnet in /api/status. HTTP mutations require a matching Origin and JSON body. The API limits body size and rate, restricts RPC methods and never accepts user-supplied execution URLs. Local fixture signing is loopback-only and disabled on public chain mode.

Before acceptance the buyer receives an AES-256-GCM encrypted report and a hash committed by the executor onchain. After settlement the API releases the key and source receipts. This prevents obtaining unpaid plaintext through this API. It relies on a trusted executor for useful content and continued key availability; ciphertext alone does not prove correct computation or atomic fair exchange. The provider may inspect its own delivery before settlement.