> ## Documentation Index
> Fetch the complete documentation index at: https://apidocs.finrock.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Finrock REST API: Overview, Base URL, and Conventions

> The Finrock REST API gives you programmatic access to wallets, transactions, AML, exchanges, and more. Base URL: https://api.finrock.io.

The Finrock REST API provides programmatic access to every capability of the platform — from creating MPC wallets and broadcasting transactions to running AML checks, managing exchange accounts, and generating invoices. All requests target a single base URL, speak JSON, and require authentication on every protected endpoint.

## Base URL

Every API request is sent to the following base URL:

```text theme={null}
https://api.finrock.io
```

Most resource endpoints are nested under the `/dac/v1/` path prefix. For example, to list transactions you call `GET https://api.finrock.io/dac/v1/transactions`.

## Request & Response Format

All request bodies must be serialised as JSON, and all successful responses are returned as JSON. Set the `Content-Type` header to `application/json` on every request that carries a body.

```http theme={null}
Content-Type: application/json
```

## Authentication

All protected endpoints require **two headers** on every request. See the [Authentication](/api-reference/authentication) page for full setup instructions, including RSA key generation and JWT signing.

| Header          | Example value                          | Description                                                                       |
| --------------- | -------------------------------------- | --------------------------------------------------------------------------------- |
| `Authorization` | `Bearer <JWT>`                         | A short-lived JWT signed with your RSA-4096 private key using the RS256 algorithm |
| `x-api-key`     | `4466c45a-7b28-4c50-a0f7-198f8d7f34c5` | The UUID API key generated from the Finrock control panel                         |

<Warning>
  Omitting either header, or supplying an expired or malformed JWT, returns a `401 Unauthorized` response. The JWT `exp` field must be within **30 seconds** of `iat` or the request is rejected immediately.
</Warning>

## Rate Limiting

Rate limits are enforced **per API key, per minute**. When your application exceeds the limit for an endpoint, the API responds with HTTP `429 Too Many Requests`. The limit resets at the start of the next minute.

Every response includes three rate-limit headers so your application can track usage in real time:

| Header                   | Type    | Description                                             |
| ------------------------ | ------- | ------------------------------------------------------- |
| `x-rate-limit-remaining` | integer | Calls remaining for this endpoint in the current window |
| `x-rate-limit-limit`     | string  | The window size for this endpoint (e.g. `1m`)           |
| `x-rate-limit-reset`     | string  | ISO 8601 timestamp when the limit window resets         |

<Info>
  Rate limits are applied globally across all your API users for the same key. To request a limit increase, contact [support@finrock.io](mailto:support@finrock.io).
</Info>

## HTTP Status Codes

The API uses standard HTTP status codes to indicate the outcome of every request.

| Status | Meaning               | When it occurs                                             |
| ------ | --------------------- | ---------------------------------------------------------- |
| `200`  | Success               | The operation completed successfully                       |
| `400`  | Bad Request           | The request body does not match the expected schema        |
| `401`  | Unauthorized          | Authentication failed — invalid, missing, or expired token |
| `403`  | Forbidden             | Authenticated but not authorised to access the resource    |
| `404`  | Not Found             | The requested path or resource does not exist              |
| `429`  | Too Many Requests     | Rate limit exceeded; retry after the reset timestamp       |
| `500`  | Internal Server Error | Unexpected server-side error; retry after a short delay    |

## API Resources

<CardGroup cols={2}>
  <Card title="Wallets & Addresses" icon="wallet" href="/api-reference/wallets/list-wallets">
    Create and manage MPC wallets, generate deposit addresses, validate addresses, and configure auto-forwarding.
  </Card>

  <Card title="Transactions" icon="arrow-right-arrow-left" href="/api-reference/transactions/list-transactions">
    Initiate withdrawals and transfers, query transaction history, estimate fees, and track transaction status.
  </Card>

  <Card title="Gas Tanks" icon="gas-pump" href="/api-reference/gas/list-gas-tanks">
    Fund and monitor gas tanks that automatically cover network fees for outgoing transactions on EVM and TRON networks.
  </Card>

  <Card title="Exchanges" icon="chart-candlestick" href="/api-reference/exchanges/list-exchanges">
    Connect exchange accounts, retrieve balances, and execute trades directly through the API.
  </Card>

  <Card title="AML" icon="shield-check" href="/api-reference/aml/aml-status">
    Run anti-money-laundering checks on addresses and transactions, manage frozen addresses, and review AML status.
  </Card>

  <Card title="Invoicing" icon="file-invoice" href="/api-reference/invoicing/create-invoice">
    Create and retrieve payment invoices and use the hosted payment widget for seamless crypto checkout flows.
  </Card>

  <Card title="Utilities" icon="wrench" href="/api-reference/utilities/supported-assets">
    Query supported assets, retrieve live asset prices, and access other platform utility endpoints.
  </Card>
</CardGroup>
