Overview

The following types of APIs are exposed by the Universal Wallet as a Service (UWaaS) REST API proxy.

Organization management

Organizations are the top-level tenant boundary for UWaaS resources.

  • List organizations.
  • Create an organization.
  • Retrieve an organization by external orgId
  • Update organization metadata and status.

Organization-network management

Organization networks associate an organization with a blockchain infrastructure instance and wallet service.

Capabilities include:

  • List networks globally, optionally filtered by organization or instance.
  • List networks for a specific organization.
  • Bulk-create one to ten network configurations synchronously.
  • Retrieve a specific organization-network configuration.
  • Update an existing configuration.

Wallet management

Wallet APIs manage wallet inventory and wallet lifecycle across organizations and networks.

Capabilities include:

  • List wallets, filtered by organization, user, or instance.
  • Create a wallet for a user within an organization network.
  • Retrieve a wallet by wallet ID.
  • Update wallet label, status, and tags.
  • Resolve a wallet using a supported lookup value; the specification currently documents IBAN lookup.
  • Import or create a wallet from a Base64-encoded private key.

User management

User APIs support organization-scoped and cross-organization administration.

Capabilities include:

  • List users for a specific organization using cursor pagination.
  • Create a user and assign a role.
  • List users across organizations.
  • Filter cross-organization results by organization, role, status, or search text.
  • Retrieve a user within an organization.
  • Update editable user properties.

Role management

Role APIs provide read-only role discovery:

  • List roles using page/size pagination.
  • Retrieve a role by numeric identifier.

Rules administration and evaluation

Rules provide configurable policy enforcement for wallet and transaction-related operations.

Administration endpoints support:

  • List all rules.
  • Create a rule.
  • Retrieve a rule by numeric ID.
  • Partially update a rule.

Creating or updating a rule refreshes the rules engine.

A rule contains:

  • A name and description.
  • Nested logical conditions using all, any, not, or condition references.
  • Facts, operators, comparison values, optional paths and parameters.
  • An ALLOW or BLOCK response with arbitrary response parameters.
  • Enabled state and priority.
  • Scope levels: global, org, instance, wallet, or asset.
  • Optional target organization, instance, wallet, or asset IDs.
  • Tags and category metadata.

Evaluation endpoints support two modes:

  • Evaluate facts against all active rules filtered by scope, tags, and targets.
  • Evaluate facts against one rule by ID.

Evaluation returns an overall ALLOW or BLOCK result plus the individual rule responses and parameters that contributed to the result.

Health and readiness

The service exposes operational endpoints outside the /v1/uwaas namespace:

  • GET /ready - basic readiness check.
  • GET /observe/health - health observation endpoint returning status, timestamp, and optional diagnostic details.

Note:

  • Operations use Bearer JWT authentication.