Unified operations feed
MY activity in the Vault as a single feed (my transfers + deposits to my addresses), by (createdAt, id) desc, keyset pagination. userId comes from the session.
Scenarios:
- my feed: no parameters
- my deposits for March: ?direction=in&from=2026-03-01&to=2026-04-01
- my stuck transfers: ?direction=out&status=pending
- awaiting MY approval (other people's transfers): ?awaitingMyApproval=true
- movements on my address: ?addressId=... or folder: ?folderId=...
- by counterparty group: ?counterpartyGroupId=..., by counterparty address: ?counterpartyAddressId=...
- external/internal only: ?flowType=external|internal
- by category/purpose from metadata: ?category=... / ?paymentPurpose=...
Each item is enriched with reporting fields (§7): operationType, flowType, usdRate/usdValue (exact snapshot), metadata. The item's shape depends on direction: out carries the status/lifecycle, in is a completed fact from the webhook.
curl -X GET "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/history?userId=example_string&direction=in&status=awaiting_approval&awaitingMyApproval=true&asset=usdt&tokenId=example_string&network=tron&addressId=123%20Main%20St&folderId=example_string&counterpartyId=example_string&counterpartyGroupId=example_string&counterpartyAddressId=123%20Main%20St&flowType=internal&category=example_string&paymentPurpose=example_string&decisionPolicyId=example_string&includeShared=true&txHash=example_string&from=example_string&to=example_string&limit=42&cursor=example_string" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN"
import requests
import json
url = "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/history?userId=example_string&direction=in&status=awaiting_approval&awaitingMyApproval=true&asset=usdt&tokenId=example_string&network=tron&addressId=123%20Main%20St&folderId=example_string&counterpartyId=example_string&counterpartyGroupId=example_string&counterpartyAddressId=123%20Main%20St&flowType=internal&category=example_string&paymentPurpose=example_string&decisionPolicyId=example_string&includeShared=true&txHash=example_string&from=example_string&to=example_string&limit=42&cursor=example_string"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/history?userId=example_string&direction=in&status=awaiting_approval&awaitingMyApproval=true&asset=usdt&tokenId=example_string&network=tron&addressId=123%20Main%20St&folderId=example_string&counterpartyId=example_string&counterpartyGroupId=example_string&counterpartyAddressId=123%20Main%20St&flowType=internal&category=example_string&paymentPurpose=example_string&decisionPolicyId=example_string&includeShared=true&txHash=example_string&from=example_string&to=example_string&limit=42&cursor=example_string", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/history?userId=example_string&direction=in&status=awaiting_approval&awaitingMyApproval=true&asset=usdt&tokenId=example_string&network=tron&addressId=123%20Main%20St&folderId=example_string&counterpartyId=example_string&counterpartyGroupId=example_string&counterpartyAddressId=123%20Main%20St&flowType=internal&category=example_string&paymentPurpose=example_string&decisionPolicyId=example_string&includeShared=true&txHash=example_string&from=example_string&to=example_string&limit=42&cursor=example_string", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/history?userId=example_string&direction=in&status=awaiting_approval&awaitingMyApproval=true&asset=usdt&tokenId=example_string&network=tron&addressId=123%20Main%20St&folderId=example_string&counterpartyId=example_string&counterpartyGroupId=example_string&counterpartyAddressId=123%20Main%20St&flowType=internal&category=example_string&paymentPurpose=example_string&decisionPolicyId=example_string&includeShared=true&txHash=example_string&from=example_string&to=example_string&limit=42&cursor=example_string')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
response = http.request(request)
puts response.body
{
"items": [
{
"direction": "example_string",
"operationType": "transfer",
"network": "example_string",
"flowType": "internal",
"usdRate": "example_string",
"usdValue": "example_string",
"usdRateSource": "example_string",
"metadata": {
"category": "example_string",
"tags": [
"example_string"
],
"paymentPurpose": "example_string",
"note": "example_string"
},
"decisionPolicyId": "example_string",
"id": "example_string",
"status": "example_string",
"txHash": "example_string",
"amount": "example_string",
"amountDecimal": "example_string",
"asset": "example_string",
"assetSymbol": "example_string",
"fee": "example_string",
"failureReason": "example_string",
"fromAddress": {
"id": "example_string",
"address": "123 Main St",
"label": "example_string"
},
"toAddress": "123 Main St",
"initiatorId": "example_string",
"decisionPolicyCode": "example_string",
"counterparty": {
"id": "example_string",
"name": "John Doe"
},
"approvalThreshold": 42,
"approvalsCount": 10,
"createdAt": "2026-07-02T11:25:15.134000Z",
"confirmedAt": "2026-07-02T11:25:15.134000Z"
}
],
"nextCursor": "example_string"
}
{
"error": "Bad Request",
"message": "The request contains invalid parameters or malformed data",
"code": 400,
"details": [
{
"field": "email",
"message": "Invalid email format"
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Internal Server Error",
"message": "An unexpected error occurred on the server",
"code": 500,
"requestId": "req_1234567890"
}
/api/v1/vaults/{code}/historyTarget server for requests. Edit to use your own host.
Session token. Mobile/services. The web uses a cookie.
API key (sent in cookie)
Unique Vault code (slug)
Admin only: whose activity to show. Without the parameter, an admin sees the ENTIRE Vault (they have no operations of their own; it's an oversight role). A non-admin can only specify themselves, otherwise 403
Only deposits (in) or only transfers (out)
Status of outgoing items; when specified, in items are excluded
true → transfers awaiting MY vote (I'm in the approvers snapshot and haven't voted yet). Shows other people's transfers: the only exception to "own activity only." Implies direction=out
Token code
Token by id from the registry (alternative to asset)
Network.slug
My address: from for out, to for in
Operations on addresses from MY folder (address-folders)
Operations of a specific counterparty (both sides)
Operations of the group's counterparties (current membership)
Operations of a specific counterparty address
internal: the other side is the Vault's own address; external: an outside party
Category from OperationMetadata
Payment purpose from OperationMetadata
Transfers decided by a specific policy (out only)
Exact on-chain hash
createdAt >= (ISO or YYYY-MM-DD)
createdAt <= (ISO or YYYY-MM-DD)
Page size (default 20, max 100)
nextCursor from the previous page
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. Session token. Mobile/services. The web uses a cookie.
API Key for authentication. Provide your API key in the cookie.
Path Parameters
Query Parameters
Admin only: whose activity to show. Without the parameter, an admin sees the ENTIRE Vault (they have no operations of their own; it's an oversight role). A non-admin can only specify themselves, otherwise 403
Status of outgoing items; when specified, in items are excluded
awaiting_approvalpendingconfirmedfailedrejectedcancelledtrue → transfers awaiting MY vote (I'm in the approvers snapshot and haven't voted yet). Shows other people's transfers: the only exception to "own activity only." Implies direction=out
truefalseToken by id from the registry (alternative to asset)
My address: from for out, to for in
Operations on addresses from MY folder (address-folders)
Operations of a specific counterparty (both sides)
Operations of the group's counterparties (current membership)
Operations of a specific counterparty address
internal: the other side is the Vault's own address; external: an outside party
internalexternalCategory from OperationMetadata
Payment purpose from OperationMetadata
Transfers decided by a specific policy (out only)
Exact on-chain hash
createdAt >= (ISO or YYYY-MM-DD)
createdAt <= (ISO or YYYY-MM-DD)
Page size (default 20, max 100)
nextCursor from the previous page
Responses
Sorted by (createdAt, id) desc
Next page cursor; null means the end