Files
pyre/apps/api
RogueWave 6ab0f02d06 feat(prometheus): real providers (Gemini/fal/Pollinations…) + secure key store
- Secure secrets: gitignored ~/pyre/.env (chmod 600) loaded into the API via
  `node --env-file-if-exists`; keys never committed/logged/returned. .env.example
  documents the vars. Free-first default (text=gemini, image=pollinations).
- @pyre/config: provider selection + key fields.
- @pyre/prometheus: real providers via fetch (no SDK deps) — Gemini/Anthropic/
  OpenAI text, Pollinations(free)/fal/DeepInfra/Replicate image, OpenAI moderation;
  `createProviders()` factory selects by config + key presence, falls back to stub.
  29 tests.
- @pyre/api: /api/prometheus/generate builds providers from config; keys never logged.

Live-verified end-to-end: admin-gated generate returned a real Spawn ("Ashen
Golem"/$AGOL) with a Pollinations image on the $0 stub-text+free-image stack;
.env-loaded admin token enforced. typecheck 8/8, 150 tests.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-31 07:23:18 +00:00
..

@pyre/api

PYRE backend HTTP API. Skeleton only — endpoints exist as TODO stubs/route placeholders, NOT real implementations. No Solana transaction or scan/build logic is implemented yet (see CLAUDE.md, §14).

Stack: Node.js + Fastify + TypeScript, with PostgreSQL (@pyre/db), Redis + BullMQ for queueing jobs handled by @pyre/worker.

Responsibilities (§13)

Token scan coordination, classification helpers, route evaluation, AI generation orchestration, metadata preparation, receipt storage, Spawn record storage, public API, admin API.

Endpoints to implement (§14) — TODO

  • POST /api/scan — scan a wallet's token accounts; return summary + accounts.
  • POST /api/build/close-empty — build unsigned close-account tx for empty ATAs.
  • POST /api/build/burn — build unsigned burn tx for selected junk tokens.
  • POST /api/receipt — record/return a cleanup receipt for a confirmed tx.
  • POST /api/prometheus/generate — enqueue a Prometheus Spawn generation job.
  • Admin endpoints — review/approve/reject generated Spawn packages.

Currently only GET /health is wired up.

Backend security rules (§16)

Rate-limit scan endpoints, validate wallet pubkeys, validate token-account ownership, never trust client-submitted classifications (recompute server-side), log all transaction-build requests, protect admin endpoints, use env secrets only.

Scripts

  • devtsx watch src/index.ts
  • buildtsc -p tsconfig.json
  • typechecktsc --noEmit
  • lint / test — placeholders for now