> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tozzecard.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent wallet holdings vs targets, with market data, plus the card's USD1

> Exists only when the server runs with AGENT_MODE=dry|live (404 otherwise). 502 with code SESSION_EXPIRED / NOT_LOGGED_IN means the Agentic Wallet needs a sign-in in the Binance App. Runs baw: a few seconds per call.



## OpenAPI

````yaml https://api.tozzecard.xyz/openapi.json get /portfolio
openapi: 3.1.0
info:
  title: Tozzecard API
  version: 1.0.0
  description: >-
    Backend for the Tozzecard app: card sign-in, card face and statement, agent
    strategy, portfolio, agent feed, market hours and the demo B402 merchant.


    **Sign in with the card key** (the EOA the browser unlocks with the
    passkey):

    1. `POST /auth/challenge {address}` → `{message}`

    2. `account.signMessage({ message })` (viem)

    3. `POST /auth/verify {message, signature}` → `{token, address, kyc, card}`.

    4. Send `Authorization: Bearer <token>` on `/me*`, `/kyc/session` and `PUT
    /strategy`. Tokens last 30 days.


    **Activating the card** (identity check with Didit): while `kyc` is not
    `approved`, `card` is null. `POST /kyc/session {returnUrl?}` → `{url}`; open
    it; Didit sends the user back to `returnUrl`; poll `GET /me` while `kyc` is
    `pending`. On approval the card is issued with the holder name from the
    document.


    **Paying a merchant order** (B402 / x402 v2): `GET
    /merchant/orders/{id}/pay` → 402 with `accepts[0]`; build and sign with
    `@tozzecard/binance/eip3009` (`transferAuthorization`, `signTypedData`,
    `paymentHeader`); `POST` the same URL with header `PAYMENT-SIGNATURE`. The
    receipt comes back in `PAYMENT-RESPONSE`.


    Errors are `{error, code?}`. Amounts in USD are numbers; on-chain amounts
    are decimal strings.
servers:
  - url: https://api.tozzecard.xyz
    description: VPS (BSC mainnet)
  - url: http://localhost:8787
    description: Local
security: []
tags:
  - name: Card
    description: Sign-in and the card itself
  - name: Agent
    description: Strategy, portfolio and the agent's decisions
  - name: Market
    description: US market hours and tokenized stock prices
  - name: Merchant
    description: Demo merchant accepting USD1 through B402
  - name: System
paths:
  /portfolio:
    get:
      tags:
        - Agent
      summary: Agent wallet holdings vs targets, with market data, plus the card's USD1
      description: >-
        Exists only when the server runs with AGENT_MODE=dry|live (404
        otherwise). 502 with code SESSION_EXPIRED / NOT_LOGGED_IN means the
        Agentic Wallet needs a sign-in in the Binance App. Runs baw: a few
        seconds per call.
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Portfolio'
        '502':
          description: Agentic Wallet error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Portfolio:
      type: object
      properties:
        card:
          type: object
          properties:
            address:
              type: string
            usd1:
              type: number
        totalUsd:
          type: number
        holdings:
          type: array
          items:
            type: object
            properties:
              symbol:
                type: string
              address:
                type: string
              balance:
                type: string
                description: token units
              valueUsd:
                type: number
              weight:
                type: number
                description: share of totalUsd, 0–1
              target:
                type: number
                description: strategy weight, 0–1
              market:
                anyOf:
                  - type: object
                    properties:
                      ticker:
                        type: string
                      platform:
                        type: string
                      status:
                        $ref: '#/components/schemas/MarketStatus'
                      tokenPrice:
                        type: number
                      closeRef:
                        anyOf:
                          - type: object
                          - type: 'null'
                      spreadVsClose:
                        anyOf:
                          - type: number
                          - type: 'null'
                  - type: 'null'
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: string
        code:
          type: string
    MarketStatus:
      type: object
      properties:
        openState:
          type: boolean
        marketStatus:
          anyOf:
            - enum:
                - premarket
                - regular
                - postmarket
                - overnight
                - closed
                - offhours
                - pause
                - paused
            - type: 'null'
        reasonCode:
          anyOf:
            - type: string
            - type: 'null'
        nextOpenTime:
          anyOf:
            - type: number
            - type: 'null'
          description: ms since epoch
        nextCloseTime:
          anyOf:
            - type: number
            - type: 'null'
          description: ms since epoch

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.