> ## Documentation Index
> Fetch the complete documentation index at: https://shield.fi/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Request test tokens

> Start a background request for the configured test token set.



## OpenAPI

````yaml openapi.json POST /airdrop
openapi: 3.1.0
info:
  title: Shield Swap API
  description: >-
    Shield Swap REST API for pools, positions, swaps, routes, quotes, settlement
    status, and transaction input schemas. Transactions target the configured
    shield_swap program and `token_registry.aleo`.


    ## Numeric wire format


    Exact financial values are JSON strings, not JSON numbers. Unsigned decimal
    inputs use ASCII digits and an optional `.` fraction, for example
    `"1234.50"`; base-unit integers use ASCII digits only. Grouping separators,
    localized decimal commas, signs, exponent notation, whitespace, Unicode
    digits, and redundant leading zeros are not accepted for those inputs.
    Signed response metrics may include a leading `-`. Clients should localize
    only for display and convert user input back to this canonical form before
    sending it.


    ## Authentication


    Most endpoints require credentials from an invited wallet. Public routes are
    `/health`, `/ready`, `/metrics`, `/auth/*`, `/protocol/state`,
    `/compliance*`, `GET /tokens*`, `GET /pools`, `GET /pools/stats`, and `GET
    /pools/{key}`.


    Browsers use HTTP-only session cookies issued by `/auth/verify`. Access
    sessions last 15 minutes and are renewed through `/auth/refresh`.
    Programmatic clients use a long-lived token from `POST /api-tokens` as
    `Authorization: Bearer ss_…`. API tokens cover data and trading routes and
    can request WebSocket tickets. Token management, code redemption, and admin
    routes require a browser session.


    ## WebSocket feed


    The live feed runs on the separate websocket gateway at `GET /ws`.


    1. Request a ticket from `GET /auth/ws-ticket` using a browser session or
    API token.

    2. Open the socket and send the `authenticate` frame within 5 seconds.

    3. Subscribe to each required room.

    4. Before the 60-second ticket expires, request a new ticket and send
    another `authenticate` frame.


    The socket accepts WebSocket tickets only. Session JWTs and API tokens are
    rejected.


    ```json

    {"action": "authenticate", "token": "<ticket from /auth/ws-ticket>"}

    {"action": "subscribe", "room": "trades:<pool_key>"}

    {"action": "unsubscribe", "room": "<room>"}

    {"action": "synchronize"}

    ```


    After reconnecting, resend subscriptions and then send `synchronize`. The
    gateway replies `{"control": "synchronized"}` when those subscriptions are
    active. Refetch any REST data that depends on the stream after receiving the
    reply.


    Each connection allows 32 rooms, 240 client frames per minute, and 2 KB per
    frame. A client may subscribe only to the balance room for its ticket
    subject.


    Rooms:

    - `pool_launches`: newly created pools

    - `pool_stats:<pool_key>`: price & liquidity updates

    - `ohlcv:<pool_key>`: candle updates

    - `trades:<pool_key>`: swaps / mints / burns

    - `balances:<address>`: balance-change hints for an address


    - `protocol_config`: revisioned protocol-configuration invalidations


    Server messages are either events (`{"type": <event>, "data": { … }}`) or
    control messages (`{"control": <value>}`). Event types are `PoolLaunch`,
    `PoolStats`, `Ohlcv`, `Trade`, `BalanceChange`, and `ProtocolConfigChanged`.
    Its data contains `revision`, `observed_block`, and the changed
    `scope`/`key` pairs. Financial fields use the numeric format described
    above.


    Treat `ProtocolConfigChanged` as an invalidation, not as the new
    configuration. Fetch `GET /protocol/state?minimum_revision=<revision>`;
    retry a `503 protocol_revision_pending` after the advertised `Retry-After`;
    and discard or requote any `/route` result whose `protocol_revision` is
    older. Subscribe to `pool_stats:<pool_key>` separately when live price and
    liquidity updates matter.


    The gateway currently sends `synchronized` and `resync_required` controls.
    `resync_required` means the stream may have missed updates, so refetch
    affected data over REST. Ignore unknown control values.


    Event delivery is at most once. Treat REST as the source of truth. During a
    deployment the gateway may close the socket with code 1012 (service
    restart); reconnect and restore the subscriptions.
  contact:
    name: Shield Swap
  license:
    name: ''
  version: 0.1.0
servers:
  - url: https://api.swap.shield.fi
    description: Shield Swap mainnet API
security: []
tags:
  - name: schema
    description: On-chain function input schemas for trading / liquidity / token operations
  - name: auth
    description: Wallet sign-in, sessions, logout, and WebSocket tickets
  - name: access
    description: Invite access redemption and administration
  - name: api-tokens
    description: >-
      Long-lived API tokens for programmatic access; send as `Authorization:
      Bearer ss_…` on any gated endpoint
  - name: referral
    description: Referral redemption and administration
  - name: pools
    description: Pool metadata, stats, trades, OHLCV
  - name: positions
    description: LP positions
  - name: swaps
    description: Historical swaps
  - name: tokens
    description: Token registry
  - name: balances
    description: On-chain token balances
  - name: compliance
    description: Token/pair allowlist, pause, and pool-creation gating state
  - name: protocol
    description: Fee tiers and tick spacings
  - name: route
    description: Swap routing
  - name: debug
    description: On-chain introspection helpers
  - name: airdrop
    description: >-
      Faucet: sends ALEO, USDCx, and ETH to a user address as records, once per
      address per 15 min
  - name: unclaimed
    description: Pending swap outputs and position fees
paths:
  /airdrop:
    post:
      tags:
        - airdrop
      summary: Request test tokens
      description: >-
        Delivers configured amounts of ALEO, USDCx, and ETH to the given address
        as

        records via `transfer_public_to_private`, spent from the

        treasury's public balance in each target's underlying program. One claim

        per recipient address per 15 minutes (429 after that).


        Proving each token takes ~15-30s, so this returns immediately with

        `status: "running"` + a `job_id`. The transfers run in a detached worker

        (capped concurrency, per-token timeout); poll `GET /airdrop/{job_id}`
        until

        `status == "complete"` to read per-token results.


        Required env: `DEPLOYER_PRIVATE_KEY` (the treasury key whose public
        balances

        fund every airdrop; `AIRDROP_PRIVATE_KEY` honored as a fallback),

        `RPC_URLS` (first entry used).
      operationId: airdrop
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AirdropRequest'
        required: true
      responses:
        '200':
          description: Airdrop job started
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AirdropStartResponseDoc'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '413':
          description: Request body too large
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '415':
          description: Content-Type must be application/json
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '422':
          description: Request body does not match schema
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '429':
          description: Airdrop already claimed for this address in the last 15 minutes
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '500':
          description: Misconfigured server (missing env vars)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
      security:
        - bearer_auth: []
components:
  schemas:
    AirdropRequest:
      type: object
      required:
        - address
      properties:
        address:
          type: string
          description: Aleo address (`aleo1...`) to receive the airdrop.
    AirdropStartResponseDoc:
      type: object
      required:
        - data
      properties:
        data:
          $ref: '#/components/schemas/AirdropStartResult'
    ErrorResponseDoc:
      type: object
      required:
        - error
      properties:
        error:
          type: string
        ref:
          type:
            - string
            - 'null'
    AirdropStartResult:
      type: object
      description: >-
        Returned by `POST /airdrop`: the airdrop now runs in the background, so
        the

        caller gets a `job_id` to poll `GET /airdrop/{job_id}` with.
      required:
        - job_id
        - status
      properties:
        job_id:
          type: string
        status:
          type: string
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Session JWT (browsers receive it as an httpOnly cookie from `POST
        /auth/verify`; 15 min, silently renewed via `POST /auth/refresh`), or a
        long-lived API token (`ss_…`) minted at `POST /api-tokens`. API tokens
        work on data and trading endpoints and can request WebSocket tickets;
        token management and admin endpoints accept session JWTs only.

````