Send a transfer
The full outgoing transfer flow (demo invariant: a successful broadcast = confirmed):
- Resolve fromAddress and the token (network match), convert amount by decimals
- Balance check (raw units)
- evaluatePolicy (action=transfer): 403 on deny/block
- Record + reserve ledger entry (available → reserved, an atomic batch with a sufficiency guard): funds are locked FOR BOTH branches
- allow → executed immediately: GasStation → 2s → broadcast → confirm | release+failed → 201 response
- requireApproval → status=awaiting_approval, 202 response; then votes via POST /transfers/{id}/approvals, and the final approve executes the transfer
Idempotency: pass an idempotencyKey (unique for each transfer attempt): the record reserves the key and funds BEFORE broadcast; a repeated request with the same key returns 200 with the existing transaction instead of a second transfer. The reserve is atomic (concurrent requests can't drive the balance negative); after failed/rejected, retry with a new key.
curl -X POST "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/transfers" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN" \
-d '{
"fromAddressId": "123 Main St",
"toAddress": "123 Main St",
"amount": "1.5",
"asset": "usdt",
"idempotencyKey": "3f2c1e58-7b0a-4d2c-9a41-8a1f0e6b2d90"
}'
import requests
import json
url = "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/transfers"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
data = {
"fromAddressId": "123 Main St",
"toAddress": "123 Main St",
"amount": "1.5",
"asset": "usdt",
"idempotencyKey": "3f2c1e58-7b0a-4d2c-9a41-8a1f0e6b2d90"
}
response = requests.post(url, headers=headers, json=data)
print(response.json())
const response = await fetch("https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/transfers", {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
},
body: JSON.stringify({
"fromAddressId": "123 Main St",
"toAddress": "123 Main St",
"amount": "1.5",
"asset": "usdt",
"idempotencyKey": "3f2c1e58-7b0a-4d2c-9a41-8a1f0e6b2d90"
})
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
"bytes"
"encoding/json"
)
func main() {
data := []byte(`{
"fromAddressId": "123 Main St",
"toAddress": "123 Main St",
"amount": "1.5",
"asset": "usdt",
"idempotencyKey": "3f2c1e58-7b0a-4d2c-9a41-8a1f0e6b2d90"
}`)
req, err := http.NewRequest("POST", "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/transfers", bytes.NewBuffer(data))
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/transfers')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Post.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
request.body = '{
"fromAddressId": "123 Main St",
"toAddress": "123 Main St",
"amount": "1.5",
"asset": "usdt",
"idempotencyKey": "3f2c1e58-7b0a-4d2c-9a41-8a1f0e6b2d90"
}'
response = http.request(request)
puts response.body
{
"transaction": {
"id": "cmr3f41z20001psp7phmyapw3",
"fromAddress": "123 Main St",
"toAddress": "123 Main St",
"amount": "example_string",
"amountDecimal": "example_string",
"asset": "example_string",
"network": "example_string",
"status": "confirmed",
"txHash": "example_string",
"fee": "example_string",
"counterpartyId": "example_string",
"approvalThreshold": 42,
"createdAt": "2026-07-02T11:25:15.134000Z"
}
}
{
"transaction": {
"id": "cmr3f41z20001psp7phmyapw3",
"fromAddress": "123 Main St",
"toAddress": "123 Main St",
"amount": "example_string",
"amountDecimal": "example_string",
"asset": "example_string",
"network": "example_string",
"status": "confirmed",
"txHash": "example_string",
"fee": "example_string",
"counterpartyId": "example_string",
"approvalThreshold": 42,
"createdAt": "2026-07-02T11:25:15.134000Z"
}
}
{
"transaction": {
"id": "cmr3f41z20001psp7phmyapw3",
"fromAddress": "123 Main St",
"toAddress": "123 Main St",
"amount": "example_string",
"amountDecimal": "example_string",
"asset": "example_string",
"network": "example_string",
"status": "confirmed",
"txHash": "example_string",
"fee": "example_string",
"counterpartyId": "example_string",
"approvalThreshold": 42,
"createdAt": "2026-07-02T11:25:15.134000Z"
}
}
{
"error": "Bad Request",
"message": "The request contains invalid parameters or malformed data",
"code": 400,
"details": [
{
"field": "email",
"message": "Invalid email format"
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Internal Server Error",
"message": "An unexpected error occurred on the server",
"code": 500,
"requestId": "req_1234567890"
}
{
"error": "Error",
"message": "GasStation or Wallet Service error",
"code": 502
}
/api/v1/vaults/{code}/transfersTarget server for requests. Edit to use your own host.
Session token. Mobile/services. The web uses a cookie.
API key (sent in cookie)
Unique Vault code (slug)
The media type of the request body
DECIMAL string, converted by token.decimals
A unique key for the transfer attempt (recommended: uuid). A repeated request with the same key returns the existing transaction without a second broadcast. For a new attempt after failed, use a new key.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. Session token. Mobile/services. The web uses a cookie.
API Key for authentication. Provide your API key in the cookie.
Path Parameters
Body
usdtA unique key for the transfer attempt (recommended: uuid). A repeated request with the same key returns the existing transaction without a second broadcast. For a new attempt after failed, use a new key.
3f2c1e58-7b0a-4d2c-9a41-8a1f0e6b2d90