OUTCOME · Create or advance
What changes
Creates or advances only the enable custom token resource described by this contract after authorization, validation, policy, and idempotency gates pass.
v2MPC wallet lifecycle
/api/v2/wallets/custom-assetsPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Call this when a wallet, treasury, custody, or governed agent workflow needs to apply the documented enable custom token transition after re-reading the current authoritative state so it can make a custody decision inside the correct owner, workspace, network, and policy boundary.
OUTCOME · Create or advance
Creates or advances only the enable custom token resource described by this contract after authorization, validation, policy, and idempotency gates pass.
WHY IT MATTERS
ISOLATION + AUTHORITY
The authenticated owner, workspace, network, and wallet policy remain authoritative. A wallet record, policy result, approval, ceremony, or balance never grants another lifecycle stage and cannot substitute for threshold signing or separately owned funding, settlement, publisher, matching, or trading authority.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing wallets:write authority.EXAMPLEBearer hc_live_…
Idempotency-KeyheaderRequiredASCII string · 1–1281-128 ASCII characters; reuse only for a byte-equivalent network-and-contract import retryEXAMPLEpost-api-v2-wallets-custom-assets-request-001
X-Request-IDheaderOptionalstringOptional caller correlation identifier. The gateway emits the effective value on the response.
Content-DigestheaderRequiredstringRFC 9530 sha-256 digest of the exact transmitted request-body bytes.
Signature-InputheaderRequiredstringRFC 9421 sig1 input covering @method, @path, content-digest, content-type, and idempotency-key, with created, expires, nonce, keyid, and alg=ed25519.
SignatureheaderRequiredstringRFC 9421 sig1 Ed25519 signature made by an active key registered to the bearer client.
acknowledge_unapproved_token_riskbodyOptionalbooleanMust be true only when inspection reports the token is outside the reviewed catalog; reviewed assets do not require it.EXAMPLEfalse
contract_addressbodyRequired20-byte hexadecimal EVM addressToken contract on the selected network. The same address on another network is a different asset.EXAMPLE0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48
network_idbodyRequiredCAIP-2 network identifierExact network selected from GET /api/v2/wallets/token-import-networks. It is never inferred from the contract address.EXAMPLEeip155:1
REQUEST
{
"acknowledge_unapproved_token_risk": true,
"contract_address": "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48",
"network_id": "eip155:1"
}RESPONSES
"example-value"{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentialsOPERATIONAL NOTES
This route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗