Who holds what
The API never stores, receives or requests a private key. The API key authenticates the integration but does not sign transactions.
Lifecycle of an operation
Every operation that moves funds (allocation, rebalancing or redemption) goes through five steps: prepare, approve, sign, execute and record.1
Prepare
TESA builds the operation according to the allocation policy and returns a proposal with the calculated movements.
2
Approve
The company approves or rejects it in the dashboard or through the API, with an
admin scope key. Without approval, nothing is executed.3
Sign
The unsigned transactions go to the company’s wallet, in self-custody or with the qualified custodian.
4
Execute
The signed transactions are broadcast. USDC moves through Circle’s CCTP and is allocated to USDY and BUIDL, or returns to the company’s custody on redemption.
5
Record
TESA tracks the confirmation, updates positions and sends webhooks with the hash of each transaction.
Environments
Each environment has its own keys. The URLs above are proposals and are not live yet.
Conventions
- Format: UTF-8 JSON, with
snake_casefields. - Amounts: USDC amounts are decimal strings with two decimal places (
"842110.00"), to avoid loss of precision. - Dates: ISO 8601 in UTC (
2026-09-01T00:00:00Z). - Identifiers: opaque strings with a per-resource prefix, such as
prop_,res_andcart_. - Pagination: lists use a cursor, with the
limiteandaposparameters.
Versioning
The major version is in the path (/v1). Backward-compatible changes, such as new fields or events, ship without a version change, and your integration should ignore fields it does not recognize. Breaking changes create a new major version, with a coexistence period announced in advance. Follow the changelog.