ARCFORM
API SERVICES
Complete endpoint documentation for Arcform API Services v1.0
Arcform API Services provides sovereign-grade decentralised identity and encrypted messaging via a minimal REST API. All DIDComm operations are performed by Arcform's internal company wallet — developers never handle raw cryptographic material.
Base URL
arcform-api.com
Protocol
HTTPS only
Format
JSON
Version
v1.0
Authenticated endpoints require a Bearer token in the Authorization header. Your token is provided after login. API keys (api_key_id) are passed in the request body — not as auth tokens.
Authorization: Bearer <your_session_token>KEY ROTATION: API keys can be revoked from the dashboard at any time. Revoked keys return 403 KEY_INACTIVE. Generate a new key to replace a revoked one — there is no key rotation endpoint; revoke + create is the canonical flow.
Health Check
curl -X GET https://arcform-api.com/v1/ping
Send Envelope
curl -X POST https://arcform-api.com/v1/channel/send \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "X-DID-API-Key: ak_YOUR_SENDER_KEY" \
-d '{
"to": "ak_RECIPIENT_KEY",
"message": "Hello from Arcform"
}'Rate limits are enforced per API key. When exceeded, the API returns 429 Too Many Requests with a Retry-After header indicating when to retry.
| Plan | Req/Min | Req/Day | Monthly Limit | Throughput | Overage |
|---|---|---|---|---|---|
| Explorer (Free) | 20 | 1,000 | 1,000 | 10 msg/s | Hard block |
| Builder ($49/mo) | 200 | 10,000 | 10,000 | 100 msg/s | Hard block |
| Sovereign ($199/mo) | 2,000 | 100,000 | 100,000 | 1,000 msg/s | Contact sales |
| Enterprise (Custom) | Custom | Custom | Custom | Custom | Custom SLA |
| HTTP Status | Error Code | Description | Troubleshooting |
|---|---|---|---|
| 200 | — | Success. Envelope delivered or request completed. | — |
| 400 | MISSING_FIELD | A required field is missing from the request body. | Check your request body against the schema. |
| 400 | RAW_DID_REJECTED | Raw DIDs are not accepted. Use a recipient API key or handle. | Check your request body against the schema. |
| 401 | UNAUTHORIZED | Missing or invalid authentication credentials. | Verify your Authorization header and token. |
| 403 | KEY_INACTIVE | The API key has been revoked or deactivated. | Check the key status in your dashboard. |
| 403 | GOVERNANCE_BLOCKED | Governance enforcement prevented execution. Check council action status or partner suspension state. | Review council actions in the governance portal. |
| 404 | KEY_NOT_FOUND | The specified API key does not exist. | Verify the api_key_id is correct. |
| 405 | METHOD_NOT_ALLOWED | Only POST is accepted on /send. | Use POST method only. |
| 422 | BADGE_DENIED_DRIFT | Badge issuance denied — drift exceeds hard limit (0.30). Signal is too unstable for any badge tier. | Review the purity thresholds in the Purity Thresholds reference. |
| 422 | BADGE_DENIED_THRESHOLDS | Badge issuance denied — one or more purity thresholds not met (clarity ≥ 0.75, coherence ≥ 0.70, confidence ≥ 0.90, drift ≤ 0.10). | Review the purity thresholds in the Purity Thresholds reference. |
| 422 | COMPLIANCE_CIRCUIT_FAILED | Compliance circuit validation failed. Check the circuit-specific requirements for your jurisdiction. | Review the purity thresholds in the Purity Thresholds reference. |
| 429 | RATE_LIMIT_EXCEEDED | You have exceeded your plan's rate limit. Back off and retry. | Wait and retry, or upgrade your plan. |
| 429 | MONTHLY_LIMIT_EXCEEDED | You have exhausted your monthly message allowance. Upgrade your plan. | Wait and retry, or upgrade your plan. |
| 500 | INTERNAL_ERROR | An unexpected server error. Contact support if persistent. | Contact support. |
Ready to build with sovereign identity?