Skip to main content
The Moca Network REST API enables server-to-server operations that do not require user presence. Use it for backend automation, credential issuance into encrypted DStorage, programmatic status checks, and browsing the credential catalog. Issuers sign credentials with their own keys and encrypt them to the holder; AIR stores and routes opaque ciphertext and metadata only.

Base URLs

Authentication

Authentication depends on the credential surface:
  • Direct AIR endpoints (initialize-user and dstorage/vcs) use a Partner JWT in x-partner-auth.
  • Your issuer backend protects available-vc and issue-vc with x-api-key.
  • Public credential-status endpoints do not require authentication.
  • Self-hosted admin endpoints use x-admin-api-key.
For direct AIR endpoints, sign the Partner JWT with your private key (RS256 or ES256) and include: For on-demand issuance, do not put the recipient email in the v1 Partner JWT. Send it in the POST /auth/initialize-user request body instead. Other operations, such as custom user authentication, have their own claim requirements. The JWT header must include kid (Key ID) matching a key in your JWKS endpoint and typ: "JWT". For full setup instructions, key generation, and code examples see Partner Authentication. Catalog endpoints are public and require no authentication. API Playground: Requests from the Try it out playground are sent directly from your browser to the API. Your API must allow CORS from your docs origin (e.g. your Mintlify subdomain or custom domain) for the playground to work. If you see 403 from the playground, check that the API allows the request origin and that your Partner JWT is valid.

Credentials

On-demand credential issuance resolves the recipient and stores an issuer-signed, holder-encrypted credential in DStorage. See the Issuance API Reference for the initialize-user and dstorage/vcs endpoints, request and response details, and code examples.

Catalog

Sandbox only at this stage. Catalog endpoints are available exclusively on https://api.sandbox.mocachain.org/v1 during the pilot. They are under active development and may change without notice — not yet available in production.

Browse schemas

Paginated list of credential schemas with credential count and number of issuers. Sortable by popularity or title.

Schema detail

Single schema with every credential built on it, including issuer info and traction metrics.

Code examples

For end-to-end integration examples including issue-and-poll flows, webhook-driven issuance, and retry logic, see Issuance API Reference.