MOONEUM

Getting started

The public API lives at /api/v1 — a stable, versioned surface for third-party integrations. Every write call accepts an optional Idempotency-Key header, and every response echoes an X-Correlation-Id you can use when reporting an issue.

Authenticate

There are two ways to authenticate:

  • API key — a static sk_… (org-scoped, full access) or tk_… (resource-scoped) key, created from the API keys page in an app you have Developer permissions on. Send it as a bearer token: Authorization: Bearer sk_….
  • OAuth2 client credentials — for integrations that shouldn't hold a long-lived key. Exchange a client ID/secret for a short-lived access token.
import { getClientCredentialsToken } from '@mooneum/sdk';

const { access_token } = await getClientCredentialsToken({
  baseUrl: 'https://api.mooneum.com',
  clientId: 'tc_…',
  clientSecret: 'tcs_…',
  scope: 'read write',
});

Make your first call

curl https://api.mooneum.com/api/v1/treasury/portfolio \
-H "Authorization: Bearer sk_…"
{
  "totalUsd": "128430.55",
  "walletCount": 3,
  "chainRollup": [
    { "chain": "ethereum", "usdValue": "94200.10" },
    { "chain": "base", "usdValue": "34230.45" }
  ],
  "syncedAt": "2026-08-11T09:14:02.000Z"
}

Access to API keys, RPC, webhooks, WebSockets, OAuth clients, and logs is scoped per business vertical (an sk_… key is created under a specific app — Treasury, Pay, Trade, Earn, or Borrow — and only that app's resources). Ask an org owner to grant Developer permissions on the relevant app's Team & Permissions page if you don't see an app you expect.