API Documentation

The Digital Real Estate Code (DREC) API allows platforms to issue permanent, verifiable records into the public DREC registry. Once published, creators can reference those records and anyone can independently verify them. Here's how to connect your platform.

What DREC does

DREC lets platforms register proof records — and lets anyone check if a record is real. It records truth — it doesn't give things financial value.

Only records marked as OWNED are accepted. Records made "on behalf of" someone are rejected.

Authentication & Endpoints

Creating a record requires your API key in the request header. Looking up or checking records is open to anyone — no key needed. Use the DREC URLs below with your matching API key.

DREC URL

Send your API requests to these URLs. Pair the Sandbox or Live URL with your matching API key.

POST
Register (Sandbox)
sandbox
https://thedrec.com/functions/sandboxRegisterDREC
POST
Register (Live)
production
https://thedrec.com/functions/registerDREC
POST
Resolve
public
https://thedrec.com/functions/resolveDREC
POST
Verify
public
https://thedrec.com/functions/verifyDREC

Register requests need your API key in the X-API-Key header. Resolve and Verify are public — no key needed.

⚠️ StoopUp — Key Rules

  • • sk_test_stoopup_... — Sandbox only. Safe to use in dev/QA. Returns TEST-DREC- codes.
  • • sk_live_stoopup_... — Production only. Do NOT use for testing. Records are permanent.
  • • Never expose either key client-side. Send API calls from your server.
# Sandbox (testing):
X-API-Key: sk_test_stoopup_t3st4b2c9d1e7f8a0b3c6d9e2f1a4b7c0
Content-Type: application/json

# Production (live go-live only):
X-API-Key: sk_live_stoopup_...   # get from Platform Management
Content-Type: application/json

Environments

SANDBOX

This is your testing environment. Records created here are marked with TEST-DREC- and never appear in the live registry. Safe to use during development.

API Key prefix: sk_test_

PRODUCTION

The live registry. Records you create here are permanent and publicly verifiable — forever. Only use this when you're ready to go live.

API Key prefix: sk_live_

⚠️ Sandbox and production data are fully isolated. Sandbox records do not affect production registry integrity.

Register a DREC

POST
registerDREC

This is how your platform creates a proof record. You tell DREC what happened — an ownership event, a completion, a milestone — and a permanent public code gets created. Only records where someone genuinely owns something are accepted.

Request

curl -X POST https://YOUR_FUNCTION_URL/registerDREC \
  -H "X-API-Key: sk_test_stoopup_xxxxxxxxxxxx" \
  -H "Content-Type: application/json" \
  -d '{
    "asset_type": "goal",
    "external_asset_id": "mqtllxfmhe2x",
    "external_asset_label": "Community Fundraising Goal",
    "ownership_enabled": true,
    "association_type": "OWNED",
    "owner_reference": "stoopup_user_or_org",
    "ledger_reference": "https://stoopup.app/goals/mqtllxfmhe2x"
  }'

Response (201 Created)

{
  "success": true,
  "drec_code": "TEST-DREC-STOOPUP-GOAL-MQTILXFMHE2X",
  "asset_type": "goal",
  "platform_id": "stoopup",
  "status": "registered",
  "environment": "sandbox"
}

Required Fields

FieldTypeNotes
asset_typestringgoal, structure
external_asset_idstringYour platform's internal ID for this asset
ownership_enabledbooleanMust be explicitly true or false
association_typestringMust be "OWNED" — ON_BEHALF is rejected
owner_referencestring(optional) Your platform's owner/user ID
ledger_referencestring(optional) URL to your platform ledger entry

Resolve a DREC

POST
resolveDREC

Use this to look up the full details of any DREC code — who registered it, what type of asset it is, and whether the platform marked it as an ownership-backed record. No API key needed.

Request

curl -X POST https://YOUR_FUNCTION_URL/resolveDREC \
  -H "Content-Type: application/json" \
  -d '{ "drec_code": "TEST-DREC-STOOPUP-GOAL-MQTILXFMHE2X" }'

Response (200)

{
  "drec_code": "TEST-DREC-STOOPUP-GOAL-MQTILXFMHE2X",
  "platform_id": "stoopup",
  "asset_type": "goal",
  "external_asset_id": "mqtllxfmhe2x",
  "owner_reference": "stoopup_user_or_org",
  "ownership_enabled": true,
  "ledger_reference": "https://stoopup.app/goals/mqtllxfmhe2x",
  "association_type": "OWNED",
  "status": "active",
  "environment": "sandbox",
  "created_at": "2026-04-22T14:00:00.000Z",
  "last_verified_at": "2026-04-22T18:30:00.000Z"
}

Verify a DREC

POST
verifyDREC

Use this to check whether a specific code really belongs to a specific asset. It's how apps confirm ownership at the moment it matters — like when a user claims a reward or accesses a feature. Every check is logged, whether it passes or fails.

Request

curl -X POST https://YOUR_FUNCTION_URL/verifyDREC \
  -H "Content-Type: application/json" \
  -d '{
    "drec_code": "TEST-DREC-STOOPUP-GOAL-MQTILXFMHE2X",
    "platform_id": "stoopup",
    "external_asset_id": "mqtllxfmhe2x"
  }'

Response — Valid

{
  "valid": true,
  "drec_code": "TEST-DREC-STOOPUP-GOAL-MQTILXFMHE2X",
  "platform_id": "stoopup",
  "asset_type": "goal",
  "ownership_enabled": true,
  "status": "active",
  "environment": "production",
  "verified_at": "2026-04-22T18:30:00.000Z"
}

Response — Invalid

{
  "valid": false,
  "reason": "DREC code not found in registry"
}

Error Responses

StatusErrorCause
400Missing required fieldsRequest body is missing a required field
400ON_BEHALF assets are not DREC-eligibleassociation_type must be OWNED
401Missing X-API-Key headerNo API key provided
401Invalid API key formatKey does not start with sk_test_ or sk_live_
401Invalid API keyKey not found for any active platform
403Platform is suspendedPlatform account has been suspended
404DREC not foundCode does not exist in registry (resolve endpoint)
500Internal server errorUnexpected server error

StoopUp integration checklist

  • ✅ Use sk_test_stoopup_... for all dev and QA — sandbox records are isolated and prefixed TEST-DREC-
  • ✅ Only switch to sk_live_stoopup_... when you are ready to go live — production records are permanent
  • ✅ Store the drec_code returned by registerDREC alongside your internal asset record
  • ✅ Call verifyDREC at runtime to confirm ownership — all attempts are audit-logged
  • ✅ Call resolveDREC (no API key) to retrieve full metadata for any DREC code
  • ✅ Only OWNED association types are registry-eligible — ON_BEHALF will be rejected at registration