Identity & users
- Applicant — The KYC applicant record created when a user starts identity verification. KYC guide
- KYC — Know Your Customer. The identity-verification process that feeds attestation claims onto a PINT JWT. KYC and attestation
- Onboarding step — A single stage in the user onboarding state machine (for example,
kyc_verification,card_setup). Onboarding state machine - Partner — An integrator using Sumvin, addressed via their SIS API key and their SIS Dashboard organisation.
- SRI — Sumvin Resource Identifier. URI-style identifier for users, resources, and capabilities. SRI reference
Signing, keys & wallets
- EIP-712 — The Ethereum typed-data signing standard used for Purchase Intents. EIP-712 & Purchase Intents
- EIP-1271 — The contract-based signature verification standard used by Safe smart accounts. Safes and identity
- EOA — Externally owned account. A single-keypair Ethereum address, distinct from a Safe smart account. Wallets guide
- Safe — The user’s smart-account wallet, deployed per chain, acting as the on-chain identity anchor. Safes and identity
- Sei — The L1 blockchain Sumvin defaults to (chain ID
1329). Wallets guide - Signing Services — The signing-enclave surface that holds per-user P-256 agent keys and signs PINTs on behalf of agents. Signing Services
Purchase intents & authorisation
- IPA — Intelligent Purchase Authorisation. An ongoing, scope-bound authorisation for an agent to execute purchases across a time window. IPA guide
- Nonce — The monotonically increasing per-wallet counter on a PINT, used for replay prevention. Nonces
- PINT — Purchase Intent. An EIP-712 signed message authorising specific scopes and actions. Purchase Intents
- Revocation — Invalidating a PINT and every JWT issued against it before their natural expiry. Revocation
- Scope — An SRI-format capability string carried on a signed PINT. Scopes reference
- x402 — The HTTP 402 Payment Required pattern for machine-to-machine PINT settlement. Payment Links and x402
JWTs & verification
- Audience — The
audJWT claim identifying the intended verifier. A verifier must match its registered identifier against this claim. Verify a JWT - Claim — A named field on a JWT payload (for example,
kyc_status,age_over_18,scopes). JWT reference - Enhanced Tier — A verification tier requiring both JWT validation and verification of the original PINT’s EIP-712 signature. Triggered by
sr:us:pint:spend:execute. Verification tiers - JWKS — JSON Web Key Set. The public-key document a verifier uses to validate PINT JWTs. JWKS
- JWT — JSON Web Token. The SIS-issued credential a verifier receives on inbound requests. JWT reference
- KID — The
kididentifier on a JWK or JWT header. Tells the verifier which JWKS key signed a given JWT. JWKS - Standard Tier — A verification tier requiring only JWT validation. Applies to every scope except
sr:us:pint:spend:execute. Verification tiers - Subject — The
subJWT claim. Carries the user’s SRI. JWT reference - Verification tier — The level of verification a verifier must perform on a PINT credential. Either Standard or Enhanced. Scopes and verification tiers
- Verifier — Any service receiving a Sumvin PINT JWT on an inbound request. Verifier Guide overview
Platform & SIS dashboard
- CORS origin — The browser origin allow-list tying an environment to the domains that may present credentials to SIS. CORS origins
- Environment — An isolated namespace inside an organisation, with its own auth provider and SDK credentials. Environments
- Organisation — A partner tenant in the SIS Dashboard, containing one or more environments. Organisations
- SIS — Sumvin Identity Service. The B2B API surface that exchanges signed PINTs for JWTs and exposes user data by SRI. Platform API vs SIS
Cards, ramps & banking
- Funding wallet — The Safe on a card’s chain that the card draws balance from. Funding wallets
- Meld — On/off-ramp partner handling buy, sell, and bank linking flows through a hosted widget. Meld overview
- PAN — Primary account number. The card’s full number, never exposed through standard card management endpoints. Card management API
- Processor token — A Plaid-side token produced during bank linking and used to initiate movement through a downstream processor.
- Ramp session — A Meld-backed session moving value between fiat and crypto. Ramp sessions
API conventions
- HAL — Hypermedia Application Language. The link format (
_links) Sumvin uses on every response. API conventions - RFC 7807 — The Problem Details spec Sumvin uses for every error response. Error handling
- Webhook — An inbound HTTP callback. Sumvin consumes KYC, Meld, and Plaid webhooks internally; partner-facing webhooks are roadmap.