ARCFORM

API SERVICES

API Reference

Complete endpoint documentation for Arcform API Services v1.0

Arcform API Services provides sovereign-grade decentralised identity and encrypted messaging via a minimal REST API. All DIDComm operations are performed by Arcform's internal company wallet — developers never handle raw cryptographic material.

Base URL

arcform-api.com

Protocol

HTTPS only

Format

JSON

Version

v1.0

Authentication

Authenticated endpoints require a Bearer token in the Authorization header. Your token is provided after login. API keys (api_key_id) are passed in the request body — not as auth tokens.

Authorization: Bearer <your_session_token>

KEY ROTATION: API keys can be revoked from the dashboard at any time. Revoked keys return 403 KEY_INACTIVE. Generate a new key to replace a revoked one — there is no key rotation endpoint; revoke + create is the canonical flow.

Endpoints

Sample Code

Health Check

curl -X GET https://arcform-api.com/v1/ping

Send Envelope

curl -X POST https://arcform-api.com/v1/channel/send \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "X-DID-API-Key: ak_YOUR_SENDER_KEY" \
  -d '{
    "to": "ak_RECIPIENT_KEY",
    "message": "Hello from Arcform"
  }'

Rate Limits

Rate limits are enforced per API key. When exceeded, the API returns 429 Too Many Requests with a Retry-After header indicating when to retry.

PlanReq/MinReq/DayMonthly LimitThroughputOverage
Explorer (Free)201,0001,00010 msg/sHard block
Builder ($49/mo)20010,00010,000100 msg/sHard block
Sovereign ($199/mo)2,000100,000100,0001,000 msg/sContact sales
Enterprise (Custom)CustomCustomCustomCustomCustom SLA

Error Reference

HTTP StatusError CodeDescriptionTroubleshooting
200—Success. Envelope delivered or request completed.—
400MISSING_FIELDA required field is missing from the request body.Check your request body against the schema.
400RAW_DID_REJECTEDRaw DIDs are not accepted. Use a recipient API key or handle.Check your request body against the schema.
401UNAUTHORIZEDMissing or invalid authentication credentials.Verify your Authorization header and token.
403KEY_INACTIVEThe API key has been revoked or deactivated.Check the key status in your dashboard.
403GOVERNANCE_BLOCKEDGovernance enforcement prevented execution. Check council action status or partner suspension state.Review council actions in the governance portal.
404KEY_NOT_FOUNDThe specified API key does not exist.Verify the api_key_id is correct.
405METHOD_NOT_ALLOWEDOnly POST is accepted on /send.Use POST method only.
422BADGE_DENIED_DRIFTBadge issuance denied — drift exceeds hard limit (0.30). Signal is too unstable for any badge tier.Review the purity thresholds in the Purity Thresholds reference.
422BADGE_DENIED_THRESHOLDSBadge issuance denied — one or more purity thresholds not met (clarity ≥ 0.75, coherence ≥ 0.70, confidence ≥ 0.90, drift ≤ 0.10).Review the purity thresholds in the Purity Thresholds reference.
422COMPLIANCE_CIRCUIT_FAILEDCompliance circuit validation failed. Check the circuit-specific requirements for your jurisdiction.Review the purity thresholds in the Purity Thresholds reference.
429RATE_LIMIT_EXCEEDEDYou have exceeded your plan's rate limit. Back off and retry.Wait and retry, or upgrade your plan.
429MONTHLY_LIMIT_EXCEEDEDYou have exhausted your monthly message allowance. Upgrade your plan.Wait and retry, or upgrade your plan.
500INTERNAL_ERRORAn unexpected server error. Contact support if persistent.Contact support.

Ready to build with sovereign identity?