Skip to main content
The Moca Network REST API enables server-to-server operations that do not require user presence. Use it for backend automation, credential issuance into encrypted DStorage, programmatic status checks, and browsing the credential catalog. Issuers sign credentials with their own keys and encrypt them to the holder; AIR stores and routes opaque ciphertext and metadata only.

Base URLs

Authentication

Authentication depends on the credential surface:
  • Direct AIR endpoints (initialize-user and dstorage/vcs) use a Partner JWT in x-partner-auth.
  • AIR calls issuer-hosted available-vc and issue-vc endpoints with x-api-key.
  • Public credential-status endpoints do not require authentication.
  • Self-hosted admin endpoints use x-admin-api-key.
For direct AIR endpoints, sign the Partner JWT with your private key (RS256 or ES256) and include: For direct issuance, do not put the recipient email in the v1 Partner JWT. Send it in the POST /auth/initialize-user request body instead. Other operations, such as custom user authentication, have their own claim requirements. The JWT header must include kid (Key ID) matching a key in your JWKS endpoint and typ: "JWT". For full setup instructions, key generation, and code examples see Partner Authentication. Catalog endpoints are public and require no authentication. API Playground: Requests from the Try it out playground are sent directly from your browser to the API. Your API must allow CORS from your docs origin (e.g. your Mintlify subdomain or custom domain) for the playground to work. If you see 403 from the playground, check that the API allows the request origin and that your Partner JWT is valid.

Credentials

Server-side credential issuance resolves the recipient and stores an issuer-signed, holder-encrypted credential in DStorage. See the Issuance API Reference for the initialize-user and dstorage/vcs endpoints, request and response details, and code examples.

Catalog

Sandbox only at this stage. Catalog endpoints are available exclusively on https://api.sandbox.mocachain.org/v1 during the pilot. They are under active development and may change without notice — not yet available in production.

Browse schemas

Paginated list of credential schemas with credential count and number of issuers. Sortable by popularity or title.

Schema detail

Single schema with every credential built on it, including issuer info and traction metrics.

Credential detail

Full credential profile: data points, issuer identity, holder/issuance/verification metrics, linked programs, and availability window.

Browse programs

Paginated list of verification programs with verification counts and accepted credential types.

Program detail

Verification program with verifier identity, pricing model, accepted credentials, and ZK verification conditions.

Search catalog

Full-text search across credentials, issuers, and programs with relevance-ranked grouped results.

Code examples

For end-to-end integration examples including issue-and-poll flows, webhook-driven issuance, and retry logic, see Issuance API Reference.