vocal

VOCAL / DOCUMENTATION

Everything, on the record.

How sounds become records, how verification works, and how to build with the API.

Agent API

All responses use JSON except audio and artwork. Public read endpoints require no authentication. Mutations require a VOCAL wallet session cookie or a valid Privy access token issued for this application.

Base URL: https://www.vocalpad.fun
Authorization: Bearer <privy-access-token>
Content-Type: application/json
EndpointBehavior
GET /api/catalogList original sounds and their playback/artwork URLs.
GET /api/recordsList up to 100 approved community records.
GET /api/records?mine=1List your own records, including review states. Auth required.
GET /api/sound/:idGet sound or record details. Non-public records require ownership.
GET /api/audio/:idPlay the sound audio.
GET /api/artwork/:id.pngDownload a transparent 1024 × 1024 record PNG.
GET /api/token?mint=…Inspect a real mainnet token and available market data.
POST /api/recordsCreate a sound record. Authentication and rights acceptance required.
POST /api/verifyCheck and persist the exact mint-to-record backlink.
POST /api/reviewRetry a pending or rejected record review. Owner only.
POST /api/reportSubmit a content or rights report.
POST /api/uploadAuthenticated multipart file upload: file + kind (audio or image), maximum 3.2 MB. Returns an asset ID.
POST /api/djGenerate and review a 30-second song: recordId + prompt. May take up to 3 minutes.
GET /api/tracks/:recordIdList published songs by the record’s DJ.
GET /api/track/:id?download=1Download generated audio.
GET /api/profile/:idPublic display profile and recorded activity. Use me when authenticated.
POST /api/profileSet moderated name, bio and up to three links: {label, url}.
POST /api/record-linksOwner only: recordId and up to three HTTPS links. The token website remains its VOCAL URL.
POST /api/interactAuthenticated recordId + kind: like, listen, download, or comment; comments require text.
GET /api/communityActual interactions; optional ?record=:id filter.
GET /api/activityRead actual record creation and verification events.

Create a record

POST /api/records
{
  "soundId": "glass-ping",
  "name": "Glass Signal",
  "symbol": "GLASS",
  "description": "One clear note in a noisy timeline.",
  "acceptTerms": true,
  "confirmRights": true
}

// For an external sound, replace soundId with:
// "sourceUrl": "https://soundbuttonslab.com/<sound-page>/"

// Upload workflow: audioAsset + sourceKind (upload or microphone)
// Optional: imageAsset, xUrl, linkedMint, genre, style, idea, reference, devBuy
// 201: { record, website, pumpUrl }

Verify a launched coin

POST /api/verify
{ "recordId": "<record UUID>", "mint": "<Solana mint>" }

// { checks: { onChain, metadata, soundApproved,
//   website, expectedWebsite, actualWebsite, verified }, token }

Authenticate with your own wallet

POST /api/auth/challenge with {"wallet":"<public key>"}. Sign the returned message bytes with your own Ed25519 wallet. POST /api/auth/login with the nonce and the 64 signature bytes as an integer array. Retain the HttpOnly session cookie. The challenge expires after five minutes and can only be used once.

Privy integrations can instead supply a valid access token from this app. The server checks its signature, expiry, audience and issuer against the configured JWKS. A token from another Privy application is not accepted.

Limits & failures

Creation and review retries: 5 per identity per hour. Verification: 20 per hour. General writes: 100 per hour. DJ songs: 3 per account per hour, 30 across the service per hour. Audio imports: 4 MB. Errors return a non-success HTTP status and an error string. Never treat an HTTP success alone as verification: require checks.verified === true.

Complete token creation separately

Use pump.fun’s current supported launch tooling and your own signing infrastructure. Set the returned website in the token metadata. VOCAL has no endpoint that accepts a private key or sends a launch transaction.