Header Background

API Overview

Table of contents

API Overview

Status: Limited

The T-Suite marketplace API is the API that Libertum’s own web apps use. It is not yet a supported public product: there is no published, maintained OpenAPI reference, and paths and fields can change between releases. Use this page to understand the shape of the API; agree any integration with Libertum before building on it. A public OpenAPI reference is planned.

Base path and hosts

All marketplace API routes are served under the base path:

/marketplace/v1

on the T-Suite API host for your deployment. The host is provided as part of an integration arrangement.

Requests and responses are JSON over HTTPS, except file uploads (multipart) and the real-time notification stream (Server-Sent Events).

Route groups

GroupPrefixAuthentication
Accountsign-up, sign-in, code verification and password reset at the root of the base pathNone (these routes create the session)
Authenticated/auth/...User access token — see Authentication
Other authenticated groupsorders, dividends and subscription management have their own prefixesUser access token
Public/public/...None — read-only data that is already public, plus a few token-gated flows
Stablecoin developer API/api/stablecoin/v1Issuer API key

Most product routes behind /auth/... also pass the onboarding gate, and paid products additionally check the subscription module.

Resource groups

The main resource groups, by product area. This is a map, not an endpoint reference.

Investing and offerings

Resource groupPurpose
OfferingsCreate, configure, deploy and list offerings; offering documents; Coming Soon listings and interest
OrdersPrimary subscription orders and their payment rails (card, bank wire, USDC/USDT via Escrow)
AgreementsAgreement templates, investor signature specimens, signing, executed PDFs and audit trails
DividendsDividend distributions to token holders
TransfersToken transfer requests and the transfer journal
Secondary market (P2P)Peer-to-peer order book for listed tokens
RedemptionsRedemption windows, redemption requests and investor payout accounts
GovernanceProposals and investor voting
Investor statementsInvestor summary and combined transaction feed
HoldingsA user’s token holdings

Accounts and billing

Resource groupPurpose
Profile and securityProfile, password, two-factor authentication and backup codes, sign-out
KYC / KYBIdentity-verification sessions and status (via SumSub)
SubscriptionsPlan and module catalogue, checkout, plan changes, add-ons, billing portal
Issuer teamInviting team members and managing roles
Issuer billing and paymentsIssuer invoices, payment settings, bank accounts and saved payment methods
Linked walletsExternal wallets a user has connected
Country restrictionsThe platform’s country grey-list and black-list
SupportSupport tickets and disputes

Wallets and payments

Resource groupPurpose
Custodian WalletBalances, deposit details, saved withdrawal addresses and withdrawals
Gas treasuryPrepaid gas balance and network-fee charges for custodian transactions
T-PayFiat on/off-ramp via Bridge.xyz (limited availability)

Distribution, structuring and other products

Resource groupPurpose
Distribution HubInvestor CRM, AI matching, campaigns, pipeline, communications and Libby AI features
HostingCross-marketplace hosting requests and the Ecosystem Directory
StructuringStructuring projects, intake, research, document generation, artefacts and guest review links
TradingPaper-trading accounts, signals and the Discover feed
Stablecoin StudioStablecoin configuration, mint and redeem orders, and the minter portal
WhitelabelTenant branding and custom-domain settings
Asset ManagementAssets, portfolios, clients, work orders, tags, compliance items, reports and migration
NotificationsIn-app notifications and the real-time stream — see Real-time & webhooks
AccreditationInvestor accreditation evidence (coming soon — not yet reviewed)
XRPL platformXRPL infrastructure (not yet selectable by issuers)

Public routes cover data that is already visible on public pages — a public offering view and its NAV history, the country restriction lists, tenant branding, the platform fee, Distribution Hub investor self-registration, and the Structuring guest review page that outside counsel opens from a share link.

Token metadata. ERC-721 token metadata is served at a separate, permanent path outside /marketplace/v1, because that URL is written into token contracts and must never change. It resolves only for approved, deployed ERC-721 offerings.

Response format

Responses use a single envelope:

{
  "message": "Human-readable message",
  "status": 200,
  "data": { },
  "error": false
}
  • error is true on any failure, and status repeats the HTTP status code.
  • data carries the payload on success. On some failures it carries machine-readable detail — for example requiresOnboarding and missingStep from the onboarding gate, or reason and moduleId from a subscription check.
  • Branch on status and on fields in data, not on the message text, which can change.

Exceptions: the real-time stream sends Server-Sent Events, and token metadata returns raw ERC-721 metadata without the envelope.

Status codes

StatusWhen you will see it
200 / 201Success
400Validation failed or the request is not allowed in the current state
401Missing, invalid, expired or superseded access token
402The account does not have the subscription module this product requires. data.reason names the case (for example, not subscribed versus a lapsed subscription that is now read-only) and data.moduleId names the module to add
403Signed in but not allowed: 2FA step pending, onboarding incomplete, wrong role or persona, or a blocked account
404The route or resource was not found
409Conflict with existing data, such as a duplicate
429Rate limit reached
500Unexpected server error
503A dependency, such as the session store, is temporarily unavailable — retry with backoff

Products that answer 402 today include Distribution Hub, Libby AI features, Structuring, Trading and Stablecoin Studio. A lapsed Structuring subscription keeps read access and answers 402 only on write actions.

Rate limits

Rate limits apply to specific sensitive routes — for example, requesting withdrawal verification codes, the public Structuring review page, and the Stablecoin developer API (300 requests per minute per client). When a limit is reached the API answers 429; limits are advertised in standard RateLimit-* response headers where they apply. Clients should back off and retry rather than hammering a route.

Stablecoin Studio developer API

Status: Limited

Stablecoin Studio issuers have a small, read-only developer API at /api/stablecoin/v1:

  • Authentication: an issuer API key, created and revoked on the Developer page in Stablecoin Studio, sent as a Bearer token or in an API-key header.
  • Scope: each key reads only its own issuer’s data — tokens, mint orders, redeem orders and API usage — plus a connectivity check.
  • No writes: creating mint orders and other changes stay in the Stablecoin Studio app.
  • Billing: API usage is metered per issuer; billing for developer API usage is coming soon.

OpenAPI reference

A maintained public OpenAPI reference is planned. Until it is published, treat this page as the authoritative description of the API’s shape, and request endpoint-level detail from Libertum as part of an integration agreement.