01URL gốc
Tất cả endpoint đều nằm dưới URL bên dưới và trả về application/json. Khi cần xác thực, token được gửi trong header Authorization: Bearer <token>; danh sách có đánh dấu những endpoint cần token.
https://priamnetwork.com/api/v1
02Endpoint
Các giá trị trong phản hồi mẫu chỉ mang tính minh họa; các trường và cấu trúc là thật. Danh sách endpoint được tạo từ bảng đăng ký trong mã nguồn, không phải viết tay.
Authentication
Creates an account. The username doubles as the referral code.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| accept_terms | string | có | Terms acceptance. Must be <code>1</code>. |
| username | string | có | 3–32 chars, letters/digits/underscore |
| password | string | có | At least 8 characters |
| confirm_age | string | có | Age declaration. Must be <code>1</code>. |
| referrer | string | — | Referrer username |
| string | có | Required and unique; the only password recovery path | |
| device_id | string | có | Stable per-device identifier |
| locale | string | — | Language code |
username_taken
email_taken
invalid_username
invalid_email
weak_password
unknown_referrer
Whether a username is available. Gates the sign-up button.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| username | string | có | 3–32 chars, letters/digits/underscore |
invalid_username
Whether an email address is available. ⚠️ Tight limit — this is a user-enumeration surface.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| string | có | Address to check |
invalid_email
Signs in with username and password, returns an access token.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| username | string | có | Username |
| password | string | có | Password |
| device_id | string | có | Device id |
invalid_credentials
account_suspended
Issues a single-use nonce for the device account picker (Credential Manager). Valid 5 minutes, bound to the device.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| device_id | string | có | The nonce is bound to this device. |
bad_request
rate_limited
Verifies the Google id_token from the native account picker. Signs in when the account exists. When it does NOT, no account is created — returns `signup_required` with a `pending_token`; the signup finishes via `auth/social-complete`.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| provider | string | có | Only `google` for now. |
| id_token | string | có | The signed token returned by Credential Manager. |
| nonce | string | có | The value obtained from `auth/social-nonce`. |
| device_id | string | có | The SAME device id used for the nonce. |
| locale | string | — | Device language code (`tr`, `en`). Used only for a NEW account. |
| signup_flow | string | — | When non-empty, no account is created; returns `signup_required`. |
bad_request
unauthorized
forbidden
unavailable
rate_limited
Completes a pending social signup with the chosen username and starts a session. The referral code is optional; without it the account is linked to the system account.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| accept_terms | string | có | Terms acceptance. Must be <code>1</code>. |
| confirm_age | string | có | Age declaration. Must be <code>1</code>. |
| pending_token | string | có | The value from `auth/social-token`. Single-use, 30 minutes. |
| username | string | có | 3–32 chars; lowercase letters, digits, underscore. |
| device_id | string | có | The SAME device id used for `auth/social-token`. |
| referrer | string | — | Username of the referrer. The account must be `active`. |
bad_request
invalid_username
username_taken
unknown_referrer
email_taken
rate_limited
Sends a password reset link. Returns the same response whether or not the address is registered, to prevent account enumeration. No code is sent to an account that is linked to a social login and whose address is not verified yet (the response is still the same), so the owner of a mistyped address cannot take the account; the real owner can still sign in with the social login.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| string | có | The account email address. |
bad_request
rate_limited
Verifies the 6-digit code from the email and returns a short-lived ticket, required by step 3 to set the new password.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| string | có | The address the code was sent to. | |
| code | string | có | Six digits. Valid for 10 minutes, dies after 5 wrong tries. |
bad_request
rate_limited
Spends the ticket and writes the new password. All of the user's sessions are revoked.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| ticket | string | có | The ticket returned by step 2. |
| new_password | string | có | At least 8 characters. |
bad_request
rate_limited
Changes the password. The current password is required. Sessions on other devices are NOT closed.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| current_password | string | có | The password in use |
| new_password | string | có | At least 8 characters |
invalid_password
weak_password
same_password
Rotates the token. Only tokens within 7 days of expiry rotate; the old one is revoked at once.
Không nhận tham số nào.
too_early
Revokes this device's token.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| all_devices | bool | — | Sign out everywhere |
Account
Uploads a profile photo (multipart, field name `file`). JPEG/PNG, max 5 MB. The server re-encodes to a 512×512 square and stores it as JPEG.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| file | file | có | JPEG or PNG, max 5 MB. |
bad_request
rate_limited
Removes the profile photo and deletes the file from disk.
Không nhận tham số nào.
rate_limited
Sends a 6-digit verification code to the account email address (the code is also in the subject). No email is sent if the address is already verified. Within 60 seconds of the last code no new code is issued and no email is sent: the response is `sent:false`, `already_sent:true` and `retry_after` (seconds); the code already sent stays valid.
Không nhận tham số nào.
unavailable
Verifies the 6-digit code from the email and confirms the address.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| code | string | có | 6 digits. Whitespace is ignored. |
bad_request
rate_limited
Profile, balance, current multiplier and open session state.
Không nhận tham số nào.
Updates the display name and email address. ⚠️ Changing the email RESETS verification and sends a 6-digit code to the new address. Once the new address is verified, social sign-in links (Google) that do not match it are removed and a `security` notification is written for the user.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| display_name | string | — | Up to 64 characters; empty falls back to the username |
| string | — | New address; verification resets when it changes | |
| referral_nudge_optout | string | — | "1" turns off the inviter reminder, "0" turns it on |
| locale | string | — | Account language. ⚠️ NOTIFICATION TEXT IS WRITTEN FROM THIS COLUMN and frozen at send time. An inactive code falls back to the default. |
email_taken
no_changes
Deletes the account from inside the app. ⚠️ The username must be typed to confirm. The account closes immediately, sessions are revoked and after 30 days the identity is erased irreversibly; until then support can undo it.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| username | string | có | The account username — intent confirmation |
username_mismatch
deletion_failed
Balance ledger: every movement, its amount and the balance at that moment. Cursor pagination (`before_id`) — no row is skipped when new entries arrive.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| limit | int | — | 1–100, default 50 |
| before_id | int | — | `next_before_id` from the previous response |
Social login
Starts a social login flow and returns the URL to open in a browser.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| provider | string | có | Only `google`. |
| device_id | string | có | Device id |
| handover_challenge | string | có | PKCE S256 (base64url, 43 chars) — binds the handover code to this app |
| native_failure | string | — | Why the on-device account picker failed, if it did; only written to the server log |
bad_request
unavailable
Exchanges the handover code from social login for an access token. Single use, valid 60 seconds.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| code | string | có | Handover code from the deep link |
| handover_verifier | string | có | Plain verifier for the challenge sent to social-start |
| device_id | string | có | Device id |
invalid_grant
account_suspended
Redirects the flow to the provider (302). Opened in a browser; does not return JSON.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| f | string | có | Flow id returned by auth/social-start |
not_found
Google callback. THIS IS THE URL TO PASTE INTO THE GOOGLE CONSOLE. Not called by the app.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| code | string | có | Authorization code from Google |
| state | string | có | CSRF value identifying the flow |
not_found
Missions
Published missions and the user's status on each. ⚠️ When the system is off it returns `enabled: false` and an EMPTY list.
Không nhận tham số nào.
Submits an entry for a mission. ⚠️ The reward lands on the balance when an admin APPROVES it, not on submission.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| mission_id | int | có | Mission id |
| payload | string | có | The requested value (max 2000 chars) |
missions_disabled
not_found
already_submitted
quota_full
payload_too_long
image_required
Submits a SCREENSHOT for a mission (multipart). ⚠️ Only missions with `answer_type = image` accept it. The reward lands on the balance when an admin APPROVES it, not on submission.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| mission_id | int | có | Mission id |
| file | file | có | JPEG or PNG, up to 5 MB. ⚠️ PDF and SVG are refused: both can carry executable code. The image is re-encoded on the server (EXIF/GPS is stripped). |
missions_disabled
not_found
already_submitted
quota_full
text_required
proof_rejected
Support
The user's own support tickets. ⚠️ Message BODIES are not returned, only the header; use `support/thread` for the conversation.
Không nhận tham số nào.
Messages of one ticket. ⚠️ Does NOT mark as read — that is `support/read`. If fetching counted as reading, an app opened and closed on a notification would clear the unread mark unseen.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| ticket_id | int | có | Ticket id |
not_found
Returns the attachment (screenshot) of a message as BYTES; only to the ticket owner. Someone else's, missing or attachment-less messages get the SAME `not_found`. The response is `no-store`: it must not be cached or written to disk.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| message_id | int | có | Message id (`id` in the thread) |
not_found
Opens a new support ticket. ⚠️ LINKS ARE REFUSED in the text (it keeps a phishing address from being opened in the admin panel); a screenshot can be attached with `support/reply-image`.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| topic | string | — | Topic code (see `topics` in the `support` response). Empty means `general`. |
| subject | string | — | Subject (max 120 chars). Empty means the first line of the message. |
| body | string | có | Message (max 2000 chars) |
link_not_allowed
body_too_long
too_many_tickets
too_many_messages
too_fast
Opens a new support ticket WITH A SCREENSHOT (multipart). Same rules as `support/open`; a body is still required.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| body | string | có | Message (max 2000 chars) |
| file | file | có | JPEG or PNG, up to 5 MB. Re-encoded on the server. |
link_not_allowed
body_too_long
image_rejected
too_many_tickets
too_many_messages
too_fast
Replies to an existing ticket. ⚠️ A `solved` ticket REOPENS — otherwise a "no, it did not work" message would fall outside the queue. A `closed` ticket is refused.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| ticket_id | int | có | Ticket id |
| body | string | có | Message (max 2000 chars) |
not_found
ticket_closed
link_not_allowed
body_too_long
too_many_messages
too_fast
Replies to a ticket with a SCREENSHOT (multipart). ⚠️ A body is still REQUIRED: an image-only message does not tell the person in the admin panel what they are looking at.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| ticket_id | int | có | Ticket id |
| body | string | có | Message (max 2000 chars) |
| file | file | có | JPEG or PNG, up to 5 MB. ⚠️ PDF and SVG are refused: both can carry executable code. The image is re-encoded on the server (EXIF/GPS is stripped). |
not_found
ticket_closed
link_not_allowed
body_too_long
image_rejected
too_many_messages
too_fast
Marks admin replies as read.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| ticket_id | int | có | Ticket id |
not_found
Mining
Starts a session. The multiplier is computed now and frozen onto the session; later changes in referral activity do not alter it.
Không nhận tham số nào.
session_already_active
mining_disabled
account_suspended
ad_required
Remaining time and expected reward of the open session.
Không nhận tham số nào.
Credits a finished session. A session is never credited twice.
Không nhận tham số nào.
no_session
session_not_finished
already_claimed
Referrals
People you referred and how many are mining right now. Only active ones count. Cursor pagination (`before_id`), ordered by `id DESC` — `mining_now` is live and stays out of the ordering, otherwise rows would repeat or vanish across pages. `total` and `active` come from their own query, not from the page.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| limit | int | — | Max 100 (default 50) |
| before_id | int | — | `next_before_id` from the previous response |
Sends a reminder notification to someone you referred whose mining session is off. Once per 12 hours per target. Only your own referrals can be reached.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| user_id | int | có | `items[].id` from the `referrals` list. |
not_eligible
rate_limited
Ads
Ads watched in the current slice of the running session (the session is split into `slices` equal parts), ads watched across the whole session (`session_watched`, capped by `daily_total`), remaining quota, when the next slice starts and any live boost. Rewards are NOT granted here — Google verifies server-to-server.
Không nhận tham số nào.
Reports the outcome of a rewarded-ad load attempt. Sessions start with an ad, so fill rate is a direct measure of revenue: every unfilled attempt means a session that started without an ad.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| result | string | có | filled · no_fill · error · consent · offline |
| unit | string | — | primary · fallback · none (defaults to none) |
Notifications
Registers the device FCM token. The app must call this on every <code>onNewToken</code>, independently of the login flow. Safe to call repeatedly for the same device.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| device_id | string | có | Persistent device id (same as in the login request). |
| fcm_token | string | có | Firebase registration token. |
| lang | string | — | Device language. Notification text is picked by this; the default language is used when empty. |
bad_request
In-app notification list. Push is not lossless (device off, permission denied, dead token) — this list is the durable record, and the text is stored already resolved to the language used at send time. `type` values: `announcement`, `mining` (session closed and reward credited), `kyc`, `withdrawal`, `wallet`.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| limit | int | — | Max rows (default 30, max 100). |
Marks a notification read. Without <code>id</code>, marks all of the user's unread notifications.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| id | int | — | Notification id. All when empty. |
Deletes a notification. Without <code>id</code>, deletes the user's READ notifications — unread ones are kept, because destroying an unseen notification in one tap would lose something the user never saw.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| id | int | — | Notification id. All read ones when empty. |
Content
Startup configuration — which sign-in methods are ENABLED. <b>No auth</b>: social buttons are drawn before sign-in, when no token exists yet. ⚠️ Returns only availability; never a key, app id or secret.
Không nhận tham số nào.
unavailable
Languages enabled for the app, and the default.
Không nhận tham số nào.
The app language pack. Returns an `ETag`; send `If-None-Match` and get **304** when unchanged. Editing a string in the panel changes the stamp immediately — no app release needed to fix wording.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| lang | string | — | Language code; default if omitted |
unknown_language
Published announcements.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| lang | string | — | Language code |
Social media accounts. An account left empty or `#` in the panel is OMITTED from the response, so the app never draws a dead button.
Không nhận tham số nào.
Published partners. No pagination by design: the list is entered by hand and is dozens of rows, not thousands. Rows with `is_active = 0` are never returned. Unlike blog, this endpoint DOES fall back to the default language — a partner name is a proper noun and hiding an untranslated row would drop the organisation from the list. `link_url` is raw; the client filters the scheme.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| lang | string | — | Language code |
Frequently asked questions and their categories.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| lang | string | — | Language code |
Legal documents; a single document when `slug` is given.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| lang | string | — | Language code |
| slug | string | — | terms · privacy · cookies · kvkk |
not_found
Protocol whitepaper, section by section.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| lang | string | — | Language code |
Blog
Published blog posts. Pagination uses a TWO-PART cursor: `before_published_at` + `before_id`, ordered by `published_at DESC, id DESC` — an id-only cursor is not enough because publish dates can be scheduled. `featured` is NOT part of the ordering. No language fallback: a post without text in the requested language does not appear at all.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| lang | string | — | Language code; unknown values fall back to the default |
| limit | int | — | 1–50, default 20 |
| before_published_at | string | — | `next_before_published_at` from the previous response — send WITH `before_id` |
| before_id | int | — | `next_before_id` from the previous response |
Full body of one post, addressed by SLUG (slug is per-language and is the post identity in that language). Unpublished posts also return `post_not_found` — saying "exists but draft" would leak draft titles. Body is `blocks` format: newline-separated lines in a markdown subset. The server emits no HTML; parsing is the client's job.
| Tham số | Kiểu | Bắt buộc | Mô tả |
|---|---|---|---|
| lang | string | — | Language code |
| slug | string | có | Post slug in that language |
post_not_found
03Lỗi
Các lỗi dùng mã trạng thái HTTP tiêu chuẩn; trường error.code trong phần thân là dạng máy đọc được và không phụ thuộc vào ngôn ngữ. Client nên rẽ nhánh theo mã, không phải theo thông điệp — thông điệp tuân theo Accept-Language.
Mã lỗi chung
| Mã | HTTP | Ý nghĩa |
|---|---|---|
| bad_request | 400 | Malformed request or missing parameter. |
| unauthorized | 401 | Missing, expired or revoked token. |
| forbidden | 403 | Account suspended. |
| not_found | 404 | No such endpoint. |
| method_not_allowed | 405 | Method not accepted by this endpoint. |
| rate_limited | 429 | Rate limit exceeded. Retry after retry_after seconds. |
| app_outdated | 426 | App version too old, update required. |
| server_error | 500 | Unexpected server error. |
| unavailable | 503 | Service temporarily unavailable. |
04Giới hạn tốc độ
Giới hạn được áp dụng theo từng endpoint và được ghi trên mỗi thẻ. Với các yêu cầu đã xác thực, bộ đếm được tính theo người dùng, với yêu cầu ẩn danh thì theo IP. Vượt quá giới hạn sẽ trả về 429 kèm Retry-After; mọi phản hồi cũng đều có X-RateLimit-Limit, X-RateLimit-Remaining và X-RateLimit-Reset.
Nếu bạn cần hạn mức cao hơn, hãy viết cho chúng tôi qua trang hỗ trợ.
