Getting started
The public API lives at /api/v1 — a stable, versioned surface for third-party integrations.
Every write call accepts an optional Idempotency-Key header, and every response echoes an
X-Correlation-Id you can use when reporting an issue.
Authenticate
There are two ways to authenticate:
- API key — a static
sk_…(org-scoped, full access) ortk_…(resource-scoped) key, created from the API keys page in an app you have Developer permissions on. Send it as a bearer token:Authorization: Bearer sk_…. - OAuth2 client credentials — for integrations that shouldn't hold a long-lived key. Exchange a client ID/secret for a short-lived access token.
import { getClientCredentialsToken } from '@mooneum/sdk';
const { access_token } = await getClientCredentialsToken({
baseUrl: 'https://api.mooneum.com',
clientId: 'tc_…',
clientSecret: 'tcs_…',
scope: 'read write',
});Make your first call
curl https://api.mooneum.com/api/v1/treasury/portfolio \
-H "Authorization: Bearer sk_…"{
"totalUsd": "128430.55",
"walletCount": 3,
"chainRollup": [
{ "chain": "ethereum", "usdValue": "94200.10" },
{ "chain": "base", "usdValue": "34230.45" }
],
"syncedAt": "2026-08-11T09:14:02.000Z"
}Access to API keys, RPC, webhooks, WebSockets, OAuth clients, and logs is scoped per business
vertical (an sk_… key is created under a specific app — Treasury, Pay, Trade, Earn, or Borrow —
and only that app's resources). Ask an org owner to grant Developer permissions on the relevant
app's Team & Permissions page if you don't see an app you expect.