Files
pyre/apps/api/README.md
RogueWave c20094ab56 chore: scaffold PYRE MVP monorepo (structure + docs)
pnpm + TypeScript workspace per design doc §13:
- apps/{web,api,worker} skeletons (Next.js 16, Fastify 5, BullMQ)
- packages/{core,solana,prometheus,db,config} (core has real types/DTOs;
  solana/prometheus are stubs)
- programs/pyre-core placeholder (future Anchor, v1.0)
- docs/: PYRE_MVP_DESIGN (canonical), ARCHITECTURE, SECURITY, TOKEN_CLASSIFICATION
- CLAUDE.md, README, .env.example (no private-key var by design)

Skeleton + docs only — no Solana/business logic yet. All workspaces typecheck clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-31 02:20:55 +00:00

39 lines
1.6 KiB
Markdown

# @pyre/api
PYRE backend HTTP API. **Skeleton only** — endpoints exist as TODO stubs/route
placeholders, NOT real implementations. No Solana transaction or scan/build
logic is implemented yet (see [`CLAUDE.md`](../../CLAUDE.md), §14).
Stack: Node.js + Fastify + TypeScript, with PostgreSQL (`@pyre/db`), Redis +
BullMQ for queueing jobs handled by `@pyre/worker`.
## Responsibilities (§13)
Token scan coordination, classification helpers, route evaluation, AI generation
orchestration, metadata preparation, receipt storage, Spawn record storage,
public API, admin API.
## Endpoints to implement (§14) — TODO
- [ ] `POST /api/scan` — scan a wallet's token accounts; return summary + accounts.
- [ ] `POST /api/build/close-empty` — build unsigned close-account tx for empty ATAs.
- [ ] `POST /api/build/burn` — build unsigned burn tx for selected junk tokens.
- [ ] `POST /api/receipt` — record/return a cleanup receipt for a confirmed tx.
- [ ] `POST /api/prometheus/generate` — enqueue a Prometheus Spawn generation job.
- [ ] Admin endpoints — review/approve/reject generated Spawn packages.
Currently only `GET /health` is wired up.
## Backend security rules (§16)
Rate-limit scan endpoints, validate wallet pubkeys, validate token-account
ownership, never trust client-submitted classifications (recompute server-side),
log all transaction-build requests, protect admin endpoints, use env secrets only.
## Scripts
- `dev``tsx watch src/index.ts`
- `build``tsc -p tsconfig.json`
- `typecheck``tsc --noEmit`
- `lint` / `test` — placeholders for now