Skip to main content
These docs describe only the network interfaces that application developers need to build compatible OpenPayload clients.

Public developer APIs

The examples explain HTTP methods, paths, fields, encodings, signatures, responses, and errors. You do not need to understand how a node stores data or communicates with other nodes. Public clients submit original envelopes and never create or submit policy provenance. Node-to-node routes, attestations, and graph cursors are intentionally outside this public contract.

What is intentionally excluded

This reference does not describe:
  • Private keys, seed phrases, or account secrets
  • Administrative cleanup or maintenance operations
  • Health checks intended only for operators
  • Chain RPC credentials or server signing configuration
A legitimate public OpenPayload endpoint never needs your private key or seed phrase. Sign locally and send only the resulting public payload and signature.

Public does not mean unencrypted

DIDs, public keys, aliases, Personas, service endpoints, delivery policies, policy conditions, and top-level message tags may be publicly discoverable. Message contents should remain encrypted inside the DDN envelope. Relay and Cache nodes route or store the envelope without needing to decrypt its payload. Persona DNS validation proves control of a DNS name at validation time. It does not establish organizational identity, reputation, or trustworthiness.