01URL de base
Tous les endpoints se trouvent sous l’URL ci-dessous et renvoient du application/json. Lorsqu’une authentification est requise, le jeton est transmis dans l’en-tête Authorization: Bearer <token> ; la liste indique quels endpoints en exigent un.
https://priamnetwork.com/api/v1
02Endpoints
Les valeurs des exemples de réponse sont indicatives ; les champs et la structure sont réels. La liste des endpoints est générée à partir du registre du code source, et non écrite à la main.
Authentication
Creates an account. The username doubles as the referral code.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| accept_terms | string | oui | Terms acceptance. Must be <code>1</code>. |
| username | string | oui | 3–32 chars, letters/digits/underscore |
| password | string | oui | At least 8 characters |
| confirm_age | string | oui | Age declaration. Must be <code>1</code>. |
| referrer | string | — | Referrer username |
| string | oui | Required and unique; the only password recovery path | |
| device_id | string | oui | Stable per-device identifier |
| locale | string | — | Language code |
username_taken
email_taken
invalid_username
invalid_email
weak_password
unknown_referrer
Whether a username is available. Gates the sign-up button.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| username | string | oui | 3–32 chars, letters/digits/underscore |
invalid_username
Whether an email address is available. ⚠️ Tight limit — this is a user-enumeration surface.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| string | oui | Address to check |
invalid_email
Signs in with username and password, returns an access token.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| username | string | oui | Username |
| password | string | oui | Password |
| device_id | string | oui | Device id |
invalid_credentials
account_suspended
Issues a single-use nonce for the device account picker (Credential Manager). Valid 5 minutes, bound to the device.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| device_id | string | oui | The nonce is bound to this device. |
bad_request
rate_limited
Verifies the Google id_token from the native account picker. Signs in when the account exists. When it does NOT, no account is created — returns `signup_required` with a `pending_token`; the signup finishes via `auth/social-complete`.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| provider | string | oui | Only `google` for now. |
| id_token | string | oui | The signed token returned by Credential Manager. |
| nonce | string | oui | The value obtained from `auth/social-nonce`. |
| device_id | string | oui | The SAME device id used for the nonce. |
| locale | string | — | Device language code (`tr`, `en`). Used only for a NEW account. |
| signup_flow | string | — | When non-empty, no account is created; returns `signup_required`. |
bad_request
unauthorized
forbidden
unavailable
rate_limited
Completes a pending social signup with the chosen username and starts a session. The referral code is optional; without it the account is linked to the system account.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| accept_terms | string | oui | Terms acceptance. Must be <code>1</code>. |
| confirm_age | string | oui | Age declaration. Must be <code>1</code>. |
| pending_token | string | oui | The value from `auth/social-token`. Single-use, 30 minutes. |
| username | string | oui | 3–32 chars; lowercase letters, digits, underscore. |
| device_id | string | oui | The SAME device id used for `auth/social-token`. |
| referrer | string | — | Username of the referrer. The account must be `active`. |
bad_request
invalid_username
username_taken
unknown_referrer
email_taken
rate_limited
Sends a password reset link. Returns the same response whether or not the address is registered, to prevent account enumeration. No code is sent to an account that is linked to a social login and whose address is not verified yet (the response is still the same), so the owner of a mistyped address cannot take the account; the real owner can still sign in with the social login.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| string | oui | The account email address. |
bad_request
rate_limited
Verifies the 6-digit code from the email and returns a short-lived ticket, required by step 3 to set the new password.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| string | oui | The address the code was sent to. | |
| code | string | oui | Six digits. Valid for 10 minutes, dies after 5 wrong tries. |
bad_request
rate_limited
Spends the ticket and writes the new password. All of the user's sessions are revoked.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| ticket | string | oui | The ticket returned by step 2. |
| new_password | string | oui | At least 8 characters. |
bad_request
rate_limited
Changes the password. The current password is required. Sessions on other devices are NOT closed.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| current_password | string | oui | The password in use |
| new_password | string | oui | At least 8 characters |
invalid_password
weak_password
same_password
Rotates the token. Only tokens within 7 days of expiry rotate; the old one is revoked at once.
Aucun paramètre.
too_early
Revokes this device's token.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| all_devices | bool | — | Sign out everywhere |
Account
Uploads a profile photo (multipart, field name `file`). JPEG/PNG, max 5 MB. The server re-encodes to a 512×512 square and stores it as JPEG.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| file | file | oui | JPEG or PNG, max 5 MB. |
bad_request
rate_limited
Removes the profile photo and deletes the file from disk.
Aucun paramètre.
rate_limited
Sends a 6-digit verification code to the account email address (the code is also in the subject). No email is sent if the address is already verified. Within 60 seconds of the last code no new code is issued and no email is sent: the response is `sent:false`, `already_sent:true` and `retry_after` (seconds); the code already sent stays valid.
Aucun paramètre.
unavailable
Verifies the 6-digit code from the email and confirms the address.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| code | string | oui | 6 digits. Whitespace is ignored. |
bad_request
rate_limited
Profile, balance, current multiplier and open session state.
Aucun paramètre.
Updates the display name and email address. ⚠️ Changing the email RESETS verification and sends a 6-digit code to the new address. Once the new address is verified, social sign-in links (Google) that do not match it are removed and a `security` notification is written for the user.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| display_name | string | — | Up to 64 characters; empty falls back to the username |
| string | — | New address; verification resets when it changes | |
| referral_nudge_optout | string | — | "1" turns off the inviter reminder, "0" turns it on |
| locale | string | — | Account language. ⚠️ NOTIFICATION TEXT IS WRITTEN FROM THIS COLUMN and frozen at send time. An inactive code falls back to the default. |
email_taken
no_changes
Deletes the account from inside the app. ⚠️ The username must be typed to confirm. The account closes immediately, sessions are revoked and after 30 days the identity is erased irreversibly; until then support can undo it.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| username | string | oui | The account username — intent confirmation |
username_mismatch
deletion_failed
Balance ledger: every movement, its amount and the balance at that moment. Cursor pagination (`before_id`) — no row is skipped when new entries arrive.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| limit | int | — | 1–100, default 50 |
| before_id | int | — | `next_before_id` from the previous response |
Social login
Starts a social login flow and returns the URL to open in a browser.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| provider | string | oui | Only `google`. |
| device_id | string | oui | Device id |
| handover_challenge | string | oui | PKCE S256 (base64url, 43 chars) — binds the handover code to this app |
| native_failure | string | — | Why the on-device account picker failed, if it did; only written to the server log |
bad_request
unavailable
Exchanges the handover code from social login for an access token. Single use, valid 60 seconds.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| code | string | oui | Handover code from the deep link |
| handover_verifier | string | oui | Plain verifier for the challenge sent to social-start |
| device_id | string | oui | Device id |
invalid_grant
account_suspended
Redirects the flow to the provider (302). Opened in a browser; does not return JSON.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| f | string | oui | Flow id returned by auth/social-start |
not_found
Google callback. THIS IS THE URL TO PASTE INTO THE GOOGLE CONSOLE. Not called by the app.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| code | string | oui | Authorization code from Google |
| state | string | oui | CSRF value identifying the flow |
not_found
Missions
Published missions and the user's status on each. ⚠️ When the system is off it returns `enabled: false` and an EMPTY list.
Aucun paramètre.
Submits an entry for a mission. ⚠️ The reward lands on the balance when an admin APPROVES it, not on submission.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| mission_id | int | oui | Mission id |
| payload | string | oui | The requested value (max 2000 chars) |
missions_disabled
not_found
already_submitted
quota_full
payload_too_long
image_required
Submits a SCREENSHOT for a mission (multipart). ⚠️ Only missions with `answer_type = image` accept it. The reward lands on the balance when an admin APPROVES it, not on submission.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| mission_id | int | oui | Mission id |
| file | file | oui | JPEG or PNG, up to 5 MB. ⚠️ PDF and SVG are refused: both can carry executable code. The image is re-encoded on the server (EXIF/GPS is stripped). |
missions_disabled
not_found
already_submitted
quota_full
text_required
proof_rejected
Support
The user's own support tickets. ⚠️ Message BODIES are not returned, only the header; use `support/thread` for the conversation.
Aucun paramètre.
Messages of one ticket. ⚠️ Does NOT mark as read — that is `support/read`. If fetching counted as reading, an app opened and closed on a notification would clear the unread mark unseen.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| ticket_id | int | oui | Ticket id |
not_found
Returns the attachment (screenshot) of a message as BYTES; only to the ticket owner. Someone else's, missing or attachment-less messages get the SAME `not_found`. The response is `no-store`: it must not be cached or written to disk.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| message_id | int | oui | Message id (`id` in the thread) |
not_found
Opens a new support ticket. ⚠️ LINKS ARE REFUSED in the text (it keeps a phishing address from being opened in the admin panel); a screenshot can be attached with `support/reply-image`.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| topic | string | — | Topic code (see `topics` in the `support` response). Empty means `general`. |
| subject | string | — | Subject (max 120 chars). Empty means the first line of the message. |
| body | string | oui | Message (max 2000 chars) |
link_not_allowed
body_too_long
too_many_tickets
too_many_messages
too_fast
Opens a new support ticket WITH A SCREENSHOT (multipart). Same rules as `support/open`; a body is still required.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| body | string | oui | Message (max 2000 chars) |
| file | file | oui | JPEG or PNG, up to 5 MB. Re-encoded on the server. |
link_not_allowed
body_too_long
image_rejected
too_many_tickets
too_many_messages
too_fast
Replies to an existing ticket. ⚠️ A `solved` ticket REOPENS — otherwise a "no, it did not work" message would fall outside the queue. A `closed` ticket is refused.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| ticket_id | int | oui | Ticket id |
| body | string | oui | Message (max 2000 chars) |
not_found
ticket_closed
link_not_allowed
body_too_long
too_many_messages
too_fast
Replies to a ticket with a SCREENSHOT (multipart). ⚠️ A body is still REQUIRED: an image-only message does not tell the person in the admin panel what they are looking at.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| ticket_id | int | oui | Ticket id |
| body | string | oui | Message (max 2000 chars) |
| file | file | oui | JPEG or PNG, up to 5 MB. ⚠️ PDF and SVG are refused: both can carry executable code. The image is re-encoded on the server (EXIF/GPS is stripped). |
not_found
ticket_closed
link_not_allowed
body_too_long
image_rejected
too_many_messages
too_fast
Marks admin replies as read.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| ticket_id | int | oui | Ticket id |
not_found
Mining
Starts a session. The multiplier is computed now and frozen onto the session; later changes in referral activity do not alter it.
Aucun paramètre.
session_already_active
mining_disabled
account_suspended
ad_required
Remaining time and expected reward of the open session.
Aucun paramètre.
Credits a finished session. A session is never credited twice.
Aucun paramètre.
no_session
session_not_finished
already_claimed
Referrals
People you referred and how many are mining right now. Only active ones count. Cursor pagination (`before_id`), ordered by `id DESC` — `mining_now` is live and stays out of the ordering, otherwise rows would repeat or vanish across pages. `total` and `active` come from their own query, not from the page.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| limit | int | — | Max 100 (default 50) |
| before_id | int | — | `next_before_id` from the previous response |
Sends a reminder notification to someone you referred whose mining session is off. Once per 12 hours per target. Only your own referrals can be reached.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| user_id | int | oui | `items[].id` from the `referrals` list. |
not_eligible
rate_limited
Ads
Ads watched in the current slice of the running session (the session is split into `slices` equal parts), ads watched across the whole session (`session_watched`, capped by `daily_total`), remaining quota, when the next slice starts and any live boost. Rewards are NOT granted here — Google verifies server-to-server.
Aucun paramètre.
Reports the outcome of a rewarded-ad load attempt. Sessions start with an ad, so fill rate is a direct measure of revenue: every unfilled attempt means a session that started without an ad.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| result | string | oui | filled · no_fill · error · consent · offline |
| unit | string | — | primary · fallback · none (defaults to none) |
Notifications
Registers the device FCM token. The app must call this on every <code>onNewToken</code>, independently of the login flow. Safe to call repeatedly for the same device.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| device_id | string | oui | Persistent device id (same as in the login request). |
| fcm_token | string | oui | Firebase registration token. |
| lang | string | — | Device language. Notification text is picked by this; the default language is used when empty. |
bad_request
In-app notification list. Push is not lossless (device off, permission denied, dead token) — this list is the durable record, and the text is stored already resolved to the language used at send time. `type` values: `announcement`, `mining` (session closed and reward credited), `kyc`, `withdrawal`, `wallet`.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| limit | int | — | Max rows (default 30, max 100). |
Marks a notification read. Without <code>id</code>, marks all of the user's unread notifications.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| id | int | — | Notification id. All when empty. |
Deletes a notification. Without <code>id</code>, deletes the user's READ notifications — unread ones are kept, because destroying an unseen notification in one tap would lose something the user never saw.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| id | int | — | Notification id. All read ones when empty. |
Content
Startup configuration — which sign-in methods are ENABLED. <b>No auth</b>: social buttons are drawn before sign-in, when no token exists yet. ⚠️ Returns only availability; never a key, app id or secret.
Aucun paramètre.
unavailable
Languages enabled for the app, and the default.
Aucun paramètre.
The app language pack. Returns an `ETag`; send `If-None-Match` and get **304** when unchanged. Editing a string in the panel changes the stamp immediately — no app release needed to fix wording.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| lang | string | — | Language code; default if omitted |
unknown_language
Published announcements.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| lang | string | — | Language code |
Social media accounts. An account left empty or `#` in the panel is OMITTED from the response, so the app never draws a dead button.
Aucun paramètre.
Published partners. No pagination by design: the list is entered by hand and is dozens of rows, not thousands. Rows with `is_active = 0` are never returned. Unlike blog, this endpoint DOES fall back to the default language — a partner name is a proper noun and hiding an untranslated row would drop the organisation from the list. `link_url` is raw; the client filters the scheme.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| lang | string | — | Language code |
Frequently asked questions and their categories.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| lang | string | — | Language code |
Legal documents; a single document when `slug` is given.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| lang | string | — | Language code |
| slug | string | — | terms · privacy · cookies · kvkk |
not_found
Protocol whitepaper, section by section.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| lang | string | — | Language code |
Blog
Published blog posts. Pagination uses a TWO-PART cursor: `before_published_at` + `before_id`, ordered by `published_at DESC, id DESC` — an id-only cursor is not enough because publish dates can be scheduled. `featured` is NOT part of the ordering. No language fallback: a post without text in the requested language does not appear at all.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| lang | string | — | Language code; unknown values fall back to the default |
| limit | int | — | 1–50, default 20 |
| before_published_at | string | — | `next_before_published_at` from the previous response — send WITH `before_id` |
| before_id | int | — | `next_before_id` from the previous response |
Full body of one post, addressed by SLUG (slug is per-language and is the post identity in that language). Unpublished posts also return `post_not_found` — saying "exists but draft" would leak draft titles. Body is `blocks` format: newline-separated lines in a markdown subset. The server emits no HTML; parsing is the client's job.
| Paramètre | Type | Obligatoire | Description |
|---|---|---|---|
| lang | string | — | Language code |
| slug | string | oui | Post slug in that language |
post_not_found
03Erreurs
Les erreurs utilisent les codes d’état HTTP standard ; le champ error.code du corps de la réponse est lisible par machine et indépendant de la langue. Les clients doivent se baser sur le code, pas sur le message — les messages suivent Accept-Language.
Codes d’erreur courants
| Code | HTTP | Signification |
|---|---|---|
| bad_request | 400 | Malformed request or missing parameter. |
| unauthorized | 401 | Missing, expired or revoked token. |
| forbidden | 403 | Account suspended. |
| not_found | 404 | No such endpoint. |
| method_not_allowed | 405 | Method not accepted by this endpoint. |
| rate_limited | 429 | Rate limit exceeded. Retry after retry_after seconds. |
| app_outdated | 426 | App version too old, update required. |
| server_error | 500 | Unexpected server error. |
| unavailable | 503 | Service temporarily unavailable. |
04Limites de débit
Les limites sont définies par endpoint et indiquées sur chaque carte. Pour les requêtes authentifiées, le compteur est lié à l’utilisateur ; pour les requêtes anonymes, à l’IP. Le dépassement d’une limite renvoie 429 avec Retry-After ; chaque réponse contient aussi X-RateLimit-Limit, X-RateLimit-Remaining et X-RateLimit-Reset.
Si vous avez besoin d’un quota plus élevé, écrivez-nous via l’assistance.
