API reference
Get workspace status
/ api/ v1/ statusWhat this workspace is, and what it can actually do. The first call a client should make: whether payments and yield are live, simulated or unavailable, the workspace clock, running totals, and a description of its configuration. Secrets are never included.
unavailable means the workspace's Circle credentials are stored but cannot be read. A cycle refuses to pay in that state rather than fall back to simulation, so status does not report it as simulate.
Send a workspace API key as Authorization: Bearer ….
Parameters
No parameters.
Try it
The key is kept in memory only, for this page.
Code samples
curl "https://www.vestiarion.xyz/api/v1/status" \
-H "Authorization: Bearer $VESTIARION_API_KEY"Response
Example{
"data": {
"businessName": "Vestiarion workspace",
"provenance": {
"payments": "live",
"yield": "simulate",
"screening": "simulate"
},
"clock": {
"mode": "simulate",
"day": 25,
"lastCycleAt": "2026-09-24T18:33:04.546517+00:00"
},
"totals": {
"decisionsLogged": 77,
"totalPaidOut": 4.815,
"flagged": 1
},
"configuration": {
"businessName": "Vestiarion workspace",
"chain": {
"circleConfigured": true,
"arcRpcConfigured": false
},
"llm": {
"pinned": null,
"available": [
"deepseek"
]
},
"compliance": {
"mode": "bundled",
"rescreenIntervalHours": 0
},
"followUp": {
"staleAfterDays": 3,
"reEscalateAfterDays": 7
},
"ledgerSigningKeyProvided": false,
"githubTokenProvided": false,
"clockMode": "simulate"
},
"apiVersion": "v1"
}
}dataobjectWhat this workspace is, and what it can actually do.
6 fields in data
businessNamestringThe workspace's name.
provenanceobjectPayments and yield differ and are reported separately, as in the UI.
unavailablemeans the workspace's Circle credentials are stored but could not be read: cycles refuse to pay then rather than simulate, so neither leg is live or simulated.3 fields in provenance
paymentsstringOne of
livesimulateunavailableyieldstringOne of
livesimulateunavailablescreeningstringOne of
livesimulate
clockobjectThe workspace's clock, and when its last cycle ran.
3 fields in clock
modestringOne of
realsimulatedaynumberlastCycleAtstring · nullable
totalsobjectRunning totals across the workspace.
3 fields in totals
decisionsLoggednumbertotalPaidOutnumberflaggednumber
configurationobjectWhat is configured for this workspace, as flags and modes. Never carries a secret.
apiVersionstringOne of
v1
Errors
| Status | Code | When |
|---|---|---|
| 401 | unauthorized | No key, or a malformed, unknown or revoked one: "A valid API key is required." |
| 403 | forbidden | The key's scopes do not cover this route: "This key cannot do that." Or, on a write, the person who created the key can no longer add records: "This key's issuer can no longer add records in this workspace." |
| 500 | internal | An unexpected server error. Implementation details are not exposed. |
Notes
Provenance
provenance says what the workspace's actions are backed by, per leg:
| Field | Values | Meaning |
|---|---|---|
payments | live, simulate, unavailable | Whether invoice and milestone payments settle on chain through Circle, or are simulated. |
yield | live, simulate, unavailable | The same, for moves to and from the yield reserve. |
screening | live, simulate | Whether this workspace's counterparties are screened against a live sanctions source (OpenSanctions) or the bundled, simulated watchlist. A sandbox always uses the bundled watchlist. |
unavailable means the workspace's Circle credentials are stored but cannot be read, for example because they are sealed under a master key this deployment does not hold. A cycle refuses to pay in that state rather than fall back to simulation, so status does not report it as simulate. Check provenance.payments before you treat a paid invoice as money that moved.
Configuration
configuration describes the workspace's setup as flags and modes, and never carries a secret. Treat it as informational: its keys can grow. Three fields describe the ledger signing key; the example above was captured before the last two were added:
ledgerSigningKeyProvided: whether the workspace's stored signing key could be read.ledgerPublicKeyProvided: alwaysfalseinside a workspace, because the public half is derived from the stored signing key rather than configured on its own.ledgerRetiredKeyCount: how many earlier public keys the deployment still accepts when verifying the ledger.