MMashDiv

API endpoints

Every Instant Convert route - the seven user routes with their bodies, limits and refusals, the admin console routes and the permission each demands, and the core house page's endpoints that work while the addon is off.

1 min readUpdated 29 September 2026reference, api, routes, endpoints, rate-limits

Lookup material. How each flow works is in the guides and the admin pages.

Everything under /api/convert and /api/admin/convert sits behind the extension gate for convert: a disabled addon answers 404 and an unlicensed one 403 before any handler runs. Every handler then checks, in order, the Convert core level, that the addon is installed and enabled, the licence, and (for anything that starts a convert) the quoting pause and drain mode, answering 503 with a sentence that says which. Amounts travel as decimal strings both ways; times are ISO strings; list routes answer { items, pagination }.

User routes

All need a signed-in account, and are classified as trade for geographic restrictions. A system account is refused.

GET/api/convert/asset
What the caller may convert: every open asset per wallet type with its directions and USD limits, the caller's daily limit and today's use (UTC), the fee in bps (zero for a Super Admin), the quote lifetime, whether Send is open and whether a convert needs two-factor. Each Ecosystem asset the caller may receive lists the chains it can be sent on, with a network fee estimate. A Send-only asset is listed with both directions closed, sendOnly true and the sentence a quote would refuse with. Open while quoting is paused.
POST/api/convert/quote
Create a quote and hold it for convertQuoteTtlSeconds. Body from, to, walletType (SPOT or ECO; fromWalletType is an alias), amount (a decimal string), side ("from" when amount is what the caller gives, "to" when it is what they receive), and optionally send (chain and address) for a Convert and Send, or withdrawTo (chain and address) for an Ecosystem convert and withdraw. Answers id, kind, the amounts (amountIn includes the fee), rate, inverseRate, feeAmount, feeCurrency, feeBps, networkFee, sendChain, expiresAt, ttlSeconds, usdValue; a Send quote adds sendAddress, grossAmount and twoFactorRequired, and a withdrawTo quote adds withdrawTo (chain, address, amount, totalFee, twoFactorRequired). Refusals are 409 with a sentence. Rate limit 60 per minute per user.
POST/api/convert/order
Execute a quote exactly as quoted. Body quoteId, withdrawTo (optional; when given it must name the quote's own chain and address), and twoFactorToken when a second factor is required (an authenticator or recovery code, or a single-use token from the verification routes). Answers order, send (for a Convert and Send), and withdrawal (for a convert and withdraw). Posting an executed quote again answers the same order with replayed true. 409 on an expired quote, a moved price, or a cap, balance or inventory re-check. Rate limit 20 per minute per user. An API key needs the trade scope.
GET/api/convert/order
The caller's converts, newest first, paginated, with the payout status of any Send. Filter status (COMPLETED, PENDING_SEND, SENT, FAILED, REVERSED). An API key needs the trade scope here too.
GET/api/convert/order/{id}
One of the caller's converts, with its payout. A payout that FAILED or was REVERSED carries refund: cause (PLATFORM, the whole convert refunded with its fee; DESTINATION, the fee kept), currency, walletType and feeRefunded, plus amount, feeAmount and at once the reversal has run; refund is null for any other payout, and the list above carries the same view. An API key needs the trade scope here too.
POST/api/convert/verification/send
Deliver a one-time code over the caller's enrolled channel, for the optional two-factor on converts. An authenticator-app user gets no message. Not for Sends, which use the withdrawal verification.
POST/api/convert/verification/verify
Check a one-time or recovery code and return a short-lived, single-use token for one convert, sent as twoFactorToken. Five wrong codes in ten minutes lock the caller out for the window.

Admin: dashboard and orders

GET/api/admin/convert/dashboardpermission: view.convert
Volume in USD over 24 hours, 7 days and all time; the order count over 24 hours and all time; fees in USD over 24 hours and all time; realised spread profit and loss (realised, costs and net) over 24 hours, 7 days and all time, in whole UTC days; exposure per currency with where it came from, house inventory, hedge and Send health, alerts.
GET/api/admin/convert/orderpermission: view.convert.order
Every convert across all users, newest first, with the user and, for a Send, the payout. Filter userId, status, kind, currency (either side), dateFrom, dateTo.
GET/api/admin/convert/order/{id}permission: view.convert.order
One convert with its quote and price inputs (the books read and their age, the reference mids, the impact, the spread and fee), its user and its payout.

Admin: assets

GET/api/admin/convert/assetpermission: view.convert.asset
Every asset row with its directions, limits, spread override, floor and target; Ecosystem rows add chains, family, pooled, ledgerFundable and the refusal sentence on each side.
POST/api/admin/convert/assetpermission: edit.convert.asset
Add an asset row. The currency must be an enabled exchange currency (Spot) or have an enabled ecosystem token (Ecosystem); a spread override may not be below the global spread.
GET/api/admin/convert/asset/{id}permission: view.convert.asset
One asset row.
PUT/api/admin/convert/asset/{id}permission: edit.convert.asset
Partially update an asset row. Currency and wallet type are fixed.
DELETE/api/admin/convert/asset/{id}permission: edit.convert.asset
Delete a disabled asset row. An enabled one is refused.
DELETE/api/admin/convert/assetpermission: edit.convert.asset
Delete several disabled asset rows; refused as a whole when any is enabled.

Admin: inventory

GET/api/admin/convert/inventorypermission: view.convert.inventory
The house's ledger balances per currency and wallet type, with floor, target, available, state, and the funding addresses; and chainInventory: per Send chain, the house's address, its tracked holding, open reservations and what is available above the chain's floor.
POST/api/admin/convert/inventory/fundpermission: edit.convert.inventory
Move a balance from the Super Admin to the house. Body currency, walletType, amount, requestId, note. Spot, or single-chain pooled Ecosystem only.
POST/api/admin/convert/inventory/defundpermission: edit.convert.inventory
Move a balance from the house to the Super Admin, never below the floor plus what open work holds.
POST/api/admin/convert/inventory/rescanpermission: edit.convert.inventory
Register the house's Ecosystem deposit addresses with the scanner and scan now. Answers what was registered and what was skipped, and why.
PUT/api/admin/convert/inventory/{id}/floorpermission: edit.convert.inventory
Set an asset's floor and target.
GET/api/admin/convert/inventory/chainpermission: view.convert.inventory
The Send chain settings rows: currency, chain, whether house-paid Sends are on, and the on-chain floor and target. The house's holding, reservations and availability per chain are in chainInventory on GET /api/admin/convert/inventory.
POST/api/admin/convert/inventory/chainpermission: edit.convert.inventory
Add a Send chain row: whether house-paid Sends may run on this currency and chain, and its on-chain floor and target.
PUT/api/admin/convert/inventory/chain/{id}permission: edit.convert.inventory
Update a Send chain row. Currency and chain are fixed.
DELETE/api/admin/convert/inventory/chain/{id}permission: edit.convert.inventory
Delete a Send chain row; refused while Sends are on for it or an open Send holds a reservation there.
DELETE/api/admin/convert/inventory/chainpermission: edit.convert.inventory
Delete several Send chain rows; refused as a whole on the same conditions.

Admin: Sends

GET/api/admin/convert/sendpermission: view.convert.send
Every Convert and Send payout, newest first, with its amounts, status, hashes and reservation. Filter by status.
GET/api/admin/convert/send/{id}permission: view.convert.send
One Send with its figures, the evidence recorded before each broadcast, the actions open now, and what a reversal would ask to be typed.
POST/api/admin/convert/send/{id}/approvepermission: manage.convert.send
Release a Send waiting for approval to the payout job. Records the approver. To refuse it, reverse it.
POST/api/admin/convert/send/{id}/confirmpermission: manage.convert.send
Book a Send as sent with a hash it recorded, once the chain confirms it as this Send's transfer.
POST/api/admin/convert/send/{id}/cancelpermission: manage.convert.send
EVM only: replace an in-flight payout with a zero-value self-send at the same nonce and higher fees, so the reversal's proof can hold.
POST/api/admin/convert/send/{id}/reversepermission: manage.convert.send
Reverse a Send. Needs a reason of at least 10 characters and the typed confirmation; refused unless the chain proves nothing will land, the Send failed with a definite verdict, or nothing was signed.

Admin: hedges

GET/api/admin/convert/hedgepermission: view.convert.hedge
Hedge orders, newest first.
GET/api/admin/convert/hedge/{id}permission: view.convert.hedge
One hedge with its fills, its currency's state and the decisions open for it.
POST/api/admin/convert/hedge/{id}/resolvepermission: manage.convert.hedge
Resolve a hedge in review: confirm_fill, mark_failed or retry_adoption.
GET/api/admin/convert/hedge/statepermission: view.convert.hedge
Exposure per currency, the hedge settings in force, and each currency's freeze, pause and quoting state.
POST/api/admin/convert/hedge/state/{currency}/unfreezepermission: manage.convert.hedge
Clear a currency's freeze, auto-pause, failure count and any quoting closure; refused while any of its hedges is in review (for USDT, while any hedge is).
POST/api/admin/convert/hedge/state/{currency}/reopenpermission: manage.convert.hedge
Reopen quoting for a currency closed by a slippage breach or by pool-backing drift (drift must be acknowledged first).

Admin: movements

GET/api/admin/convert/rebalancepermission: view.convert.rebalance
House movements, newest first. Filter by status.
POST/api/admin/convert/rebalancepermission: edit.convert.rebalance
Start a movement by hand: currency, direction (TO_CHAIN or TO_EXCHANGE), amount, optional chain.
GET/api/admin/convert/rebalance/{id}permission: view.convert.rebalance
One movement.
POST/api/admin/convert/rebalance/{id}/resolvepermission: manage.convert.rebalance
Resolve a movement: confirm_completed, confirm_arrived, mark_failed, attach_txid or retry_adoption.

Admin: profit and loss

GET/api/admin/convert/pnlpermission: view.convert.pnl
Realised (gross), fees, house costs, master-paid costs (shown apart, never swept) and net (realised minus house costs) per UTC day and currency; totals for 24 hours, 7 and 30 days and all time; open cost lots; the sweep history; the days not yet swept; and the time the figures are complete up to. Filters from and to (YYYY-MM-DD) and currency. Read-only.
POST/api/admin/convert/pnl/sweeppermission: edit.convert.settings
Sweep every finished, processed, unswept day up to and including the given day, oldest first. Body day (YYYY-MM-DD). Works whatever the sweep switch says; the hourly job sweeps only when it is on.

Admin: settings

GET/api/admin/convert/settingspermission: view.convert.settings
Every Convert setting as stored, with defaults applied.
PUT/api/admin/convert/settingspermission: edit.convert.settings
Change settings, all or nothing. Unknown keys are ignored and listed; the three house-page keys are refused with 403 and their editor's path; protected keys need the Super Admin role; an invalid value is refused with 400, never clamped.

Core house page

Core routes, outside the addon's gate. Every action needs a fresh second factor bound to that action and target: request a code from the verification route, verify it, and send the token it returns with the action.

GET/api/admin/finance/pool-backing/housepermission: view.pool.backing
The house: wallets with holds and what a defund may take, per-chain trackers and bands, open Sends, hedges and movements, the kill switches, whether the viewer may change them, and the addon's state (present, absent or broken).
POST/api/admin/finance/pool-backing/house/defundpermission: manage.pool.backing
Defund Spot or single-chain pooled Ecosystem inventory to the Super Admin, never below what open work holds.
PUT/api/admin/finance/pool-backing/house/settingspermission: manage.pool.backing
Change convertHedgeMode, convertHedgePause and convertRebalanceEnabled. Super Admin only.
POST/api/admin/finance/pool-backing/house/send/{id}/confirmpermission: manage.pool.backing
Confirm a Send as sent, through the addon's own code.
POST/api/admin/finance/pool-backing/house/send/{id}/reversepermission: manage.pool.backing
Reverse a Send, through the addon's own code and on the chain's proof.
POST/api/admin/finance/pool-backing/house/hedge/{id}/resolvepermission: manage.pool.backing
Resolve a hedge in review.
POST/api/admin/finance/pool-backing/house/movement/{id}/resolvepermission: manage.pool.backing
Resolve a house movement.
GET/api/admin/finance/pool-backing/house/verificationpermission: manage.pool.backing
The house page's two-factor policy for the caller.
POST/api/admin/finance/pool-backing/house/verificationpermission: manage.pool.backing
Send the code for one action on one target.
POST/api/admin/finance/pool-backing/house/verification/verifypermission: manage.pool.backing
Verify the code and mint the single-use token for that action.