List wallet ledger entries for the authenticated app
GET /v1/credit-ledger
GET https://api.k-otp.dev/v1/credit-ledgerOverview
Returns an audit projection of wallet mutations: credit top-ups, per-issue debits, and refunds. amountDelta is signed (debits are negative) and balanceAfter is the wallet balance after the entry. Internal billing references, external payment references, and initiator metadata are omitted; issueId is present only for issue-linked entries.
Results are ordered newest first (createdAt descending, ties broken by id) and keyset-paginated. Pass limit (1-100, default 50) and, for subsequent pages, the opaque cursor returned as nextCursor; nextCursor is omitted on the last page. Cursors are bound to the endpoint that issued them and must be sent unchanged. Keep the same filters while paging.
Optional createdFrom/createdTo (RFC 3339 date-time) select the half-open range [createdFrom, createdTo); when both are given createdFrom must be earlier than createdTo. entryType filters by entry type.
Requires an sk_ secret key; pk_ public keys are rejected with 403.
Authentication
| Accepted keys | Required scope | Also accepted |
|---|---|---|
sk_ | otp:ledger:read | otp:dashboard:read, otp:read, * |
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
limit | query | integer | Page size: 1-100 items. Defaults to 50 when omitted. | |
cursor | query | string | nextCursor from the previous page. | |
entryType | query | "clawback" | "credit" | "debit" | "refund" | Filter by entry type. | |
createdFrom | query | string (date-time) | Inclusive lower bound on createdAt. | |
createdTo | query | string (date-time) | Exclusive upper bound on createdAt; must be later than createdFrom. |
Response (200)
One page of ledger entries, newest first.
| Field | Type | Required | Description |
|---|---|---|---|
items | object[] | yes | |
nextCursor | string | Cursor for the next page; absent on the last page. |
Error responses
Every error uses the { defined, code, status, message, data? } envelope. See Errors.
| Status | code | Description |
|---|---|---|
| 400 | BAD_REQUEST | invalid query, limit outside 1-100, malformed cursor, a cursor issued by a different endpoint, or createdFrom not earlier than createdTo. |
| 401 | UNAUTHORIZED | the Authorization: Bearer credential is missing, malformed, inactive, or rejected by introspection. |
| 403 | FORBIDDEN | the credential lacks otp:ledger:read (or an accepted alias), or a pk_ public key was used. Public keys are limited to issue/verify. |
| 409 | CONFLICT | the request conflicts with the current state of the resource. |
| 500 | INTERNAL_SERVER_ERROR | unexpected server failure. Undefined errors (defined: false) use the same envelope. |
| 503 | SERVICE_UNAVAILABLE | credential introspection or a downstream dependency is temporarily unavailable. Retry with backoff. |
Example request
curl "https://api.k-otp.dev/v1/credit-ledger" \
-H "Authorization: Bearer $KOTP_SECRET_KEY"