Accounts, originators and earnings
Sign in, commission an asset as its originator, and read what it has earned over the API.
Signing in is optional. It changes one thing: a made-to-order request made while signed in records you as the originator of whatever is listed, and every paid licence of it credits you a share of the price.
Signing in
Identity is Google Firebase’s. The browser signs in with Google or a phone number and receives an ID token; send it as a bearer token. The server checks the signature against Google’s published keys, the audience and the issuer on every request, and stores no password.
Authorization: Bearer <Firebase ID token>
Commission as an originator
POST /api/bank/request
Authorization: Bearer <token>
{"query": "a falconer holding a hooded hawk", "shape": "landscape"}
-> {"request_id": "req_...", "originator": true, ...}
originator says whether the request was credited. Without a valid token it is
false and the request still runs, anonymously.
Read your statement
GET /api/account/earnings
Authorization: Bearer <token>
-> {"share": 0.2,
"totals": {"licences": 3, "earned_usd": 5.4, "paid_out_usd": 0, "balance_usd": 5.4, "assets": 2},
"assets": [{"asset_id": "a_...", "title": "...", "listed": true, "licences": 3, "earned_usd": 5.4}],
"recent": [{"license_id": "lic_...", "gross_usd": 9.0, "share": 0.2, "amount_usd": 1.8, "note": null}]}
| Route | What it does |
|---|---|
GET /api/account/config | Public. The Firebase web config and the current share. |
GET /api/account/me | Who you are signed in as, and your totals. |
GET /api/account/earnings | Every asset you originated and every licence behind the balance. |
DELETE /api/account/me | Erase your identity. The ledger keeps the amounts, attached to nobody. |
When the amount is zero
note explains every zero: free licence when nothing was paid, and
own asset when the buyer was the originator. A payment reference nothing verified
is not a sale and is credited at zero too.
A licence credits its originator exactly once. The ledger has a unique constraint on the licence, so a retried request cannot pay twice.