Skip to navigation

Credentials

A venue credential and its observed health

URL — No public environment serves this socket yet.

Topic credential

Request parameters

ParameterTypeRequiredDescription
opstringYessubscribe
reqIdstringYesEchoed byte-exact on the answer. Printable ASCII, escape-free; anything else answers MALFORMED.
paramsobjectYes
> topicsarray of stringsYescredential

Response parameters

ParameterTypeRequiredDescription
opstringYesOne of subscribe, unsubscribe.
reqIdstringYesEchoed byte-exact on the answer. Printable ASCII, escape-free; anything else answers MALFORMED.
successbooleanYestrue

Push data parameters

Two axes, kept apart on purpose. status is the credential’s lifecycle — what an administrator decided. health is what a connector observed. An approved credential whose venue is down and a suspended credential call for opposite actions, and one word could not say both. health is null until a report exists.

What the image holds. Every credential of the organization this member holds, keyed by credentialId, as its latest image — including revoked ones.

How a row leaves. It does not; status is the signal, exactly as on account. A revoked credential is served with its status and keeps explaining the orders and accounts that were placed through it.

ParameterTypeRequiredDescription
eventstringYescredential
msgTypestringYescredential
topicstringYescredential
seqstringYesThe stream position, as a decimal string — an int64 a JSON number would truncate.
seqTsstringYesThe stream timestamp, epoch-ns as a decimal string.
isSnapshotbooleanYesOne of true, false.
snapshotIdstringNoPresent on a snapshot part only, and the same on every part of one image; the next image of any topic carries a different one. Opaque — compare it for equality and nothing else. It is not a sequence, a version or a timestamp, and its shape may change; a client that ordered by it would be relying on how a member happens to mint it. Use it to keep two images apart. A repeat subscribe re-pushes the image — that is the resync, and there is no separate op — so a client can start image N+1 while N is still arriving, and without a name on each part it cannot tell which last: true closes which, nor stop a straggling part of N landing in the map N+1 just cleared. Discard any part whose snapshotId is not the one you are currently applying.
partintegerNoPresent on a snapshot part only; 1-based.
lastbooleanNoPresent on a snapshot part only. The image is complete when true — including for an empty channel, which is still one part.
dataarray of objectsYesOne venue credential and its observed health, keyed by credentialId. The row carries no secret material by construction: the register’s secretRef, keyFingerprint and venueKeyId are not rendered here at all.
> credentialIdintegerYes
> credentialstringYesThe credential’s name.
> versionstringYes
> statusstringYesThe LIFECYCLE — what an administrator decided. Not a health reading. One of UNKNOWN, DRAFT, PENDING_APPROVAL, ACTIVE, SUSPENDED, REVOKED.
> exchangestring, nullableYesNull until this member holds the credential’s exchange row.
> providerKindstringYesOne of UNKNOWN, EXCHANGE, CUSTODIAN, WALLET_PROVIDER, CHAIN_RPC, BANK.
> canTradebooleanYes
> canReadBalancesbooleanYes
> appGroupstring, nullableYes
> healthobject, nullableYesWhat a connector OBSERVED, kept apart from status on purpose: an approved credential whose venue is down and a suspended credential call for opposite actions, and one word could not say both. Null until a report exists — an absent object rather than a synthetic UNKNOWN row a client would have to special-case.