developers
[ public api ]
Bonfire is a social network you actually own. Posts, photos and comments live on IPFS, authorship is stamped on the TEXITcoin chain, and identity is a wallet — not an email address. These endpoints let you embed, read and verify any of it from anywhere. No keys, no signups. Just HTTP.
01 · the CID is the truth
Every photo, video, story and comment body on Bonfire is identified by its IPFS CID — a cryptographic hash of the bytes. Same bytes → same CID. Different bytes → different CID. Always.
That makes the CID the only identifier that actually matters. Our database row, our gateway URL, our chain stamp, and any third-party IPFS pinner in the world all point at the exact same content via the exact same string. If Bonfire goes dark, re-pin the CID anywhere and the content still resolves.
# A CID looks like this:
bafybeigsqgnxogzyi7fdyogldjvia3juqkxnjv...
# Anyone can fetch it from any IPFS gateway:
curl -L https://ipfs.io/ipfs/{cid} -o media.bin
curl -L https://gateway.pinata.cloud/ipfs/{cid} -o media.bin
curl -L https://bonfire.honest.money/api/stream/{cid} -o media.binA post is a small JSON manifest (also pinned, also a CID) that lists its media CIDs, author wallet, tags and body text. The /p/{postId} page is just a friendly wrapper around that manifest.
02 · on-chain proof & OP_RETURN
When a post is published, when a comment lands, when hosting is paid or released, Bonfire broadcasts a tiny TEXITcoin transaction whose OP_RETURN output carries an ≤80-byte tag naming the event and the content CID. The chain proves when something was published and by which wallet — IPFS proves what was published.
event tags broadcast in OP_RETURN C claim — content first lands on the network P payment — hosting payment received R renewal — hosting prepaid for another period T takedown — author unpinned it (chain record survives) D moderation — moderator pulled it M metadata — profile / post metadata update X comment — IPFS CID of a new comment body TXCV1G recovery countdown started (account continuity) TXCV1N succession completed to a new identity address
Unpinning frees storage but never erases history: the OP_RETURN record is permanent even after our gateway stops serving the bytes. Anyone can decode the payloads on an author's derived addresses and rebuild their timeline without trusting us.
03 · wallet identity & xpub linking
Bonfire has no usernames or passwords. An account is a TXC address, optionally decorated with an @handle and always addressable by its 6-character asset ID (#ABC123).
Linking a wallet hands Bonfire an account-level xpub — never a seed, never a private key. Bonfire derives a fresh address per post from it, so your whole social history is self-verifiable from your own wallet. The link protocol is hm-link-xpubs, and it is what Beekeeper and HME Wallet speak.
# 1 — wallet scans the QR and reads the consent manifest
GET https://bonfire.honest.money/api/public/v1/wallet-link?token={single-use-token}
# 2 — wallet posts back a signed envelope
POST https://bonfire.honest.money/api/public/v1/wallet-link
{
"version": 1,
"type": "hm-link-xpubs",
"identity_address": "T9...",
"xpub": "xpub6...",
"xpub_path": "m/44'/696969'/1101'",
"signature": "H4r...==",
"token": "{single-use-token}"
}Tokens are single-use and short-lived, and the signed message includes the server-issued challenge — a replayed envelope from another app cannot be accepted. Derivation path for Bonfire social activity is m/44'/696969'/1101'/{post index}.
04 · QR wallet sign-in
The browser mints a short-lived challenge, renders it as a QR code, and polls. The wallet fetches the exact message from the callback, signs it, and posts the signature back. Nothing but an address and a signature ever leaves the device — no transaction, no spend.
# 1 — mint a challenge (5 min TTL) → returns QR payload + deep link
curl -X POST https://bonfire.honest.money/api/public/auth/wallet-challenge
# 2 — poll while the user scans (every 2s)
curl "https://bonfire.honest.money/api/public/auth/wallet-status?id={challengeId}"
# 3 — the wallet fetches the exact message, signs, and posts back
curl -X POST https://bonfire.honest.money/api/public/auth/wallet-callback \
-H "content-type: application/json" \
-d '{"id":"{challengeId}","address":"T9...","signature":"H4r...=="}'
# 4 — browser burns the one-time token for a session
curl -X POST https://bonfire.honest.money/api/public/auth/wallet-exchange \
-H "content-type: application/json" \
-d '{"token":"{oneTimeToken}"}'The QR is an hm-login JSON envelope (version, origin, nonce, callback URL, expiry, chain txc, and an explicit non-payment statement), with a payhme://login deep link for same-device mobile. Messages are signed with the TEXITcoin Signed Message: prefix. Verification is exposed standalone in §09.
05 · embed a post
/embed/p/{postId}A self-contained Bonfire post card — media, author, body, tags, like and comment counts — sized for any page. Add ?theme=light for light surfaces; the default is the dark ember theme.
<iframe src="https://bonfire.honest.money/embed/p/FB277B" width="550" height="520" frameborder="0" allow="fullscreen; picture-in-picture" title="Bonfire post" ></iframe>
Every post page also carries canonical, Open Graph, Twitter and SocialMediaPosting JSON-LD tags, so pasting a /p/{postId} link into any chat app unfurls correctly with no extra work.
06 · oEmbed discovery
/api/public/oembed?url={postUrl}Standard oEmbed rich provider for Bonfire posts. WordPress, Notion, Discourse, Ghost and anything else that speaks oEmbed can auto-embed a pasted post link. Optional maxwidth (200–1200) and maxheight (200–2000).
curl "https://bonfire.honest.money/api/public/oembed?url=https://bonfire.honest.money/p/FB277B" | jq
# → {
# "type": "rich", "version": "1.0",
# "provider_name": "Bonfire",
# "title": "…", "author_name": "@handle",
# "html": "<iframe src=\"https://bonfire.honest.money/embed/p/…\" …></iframe>",
# "width": 550, "height": 520
# }07 · stream media by CID
/api/stream/{cid}Serves any pinned Bonfire media — post photos, video files, HLS segments — from our dedicated IPFS gateway. Supports HTTP Range requests, so it works as a drop-in <img> or <video src> for any browser, native app, or player.
curl -L https://bonfire.honest.money/api/stream/bafybeigsqgnxogzyi7fdyogldjvia3juqkxnjvexampleexampleexample -o media.mp4
HTML use: <video src="https://bonfire.honest.money/api/stream/{cid}" controls />
08 · embed a video player
/embed/{cid}A bare-bones Bonfire video player for long-form uploads and livestream archives. Optional query params: autoplay=1, muted=1, t=30 (start seconds). Live channels embed as /embed/live/{streamId} or /embed/live/by-wallet/{wallet}.
<iframe
src="https://bonfire.honest.money/embed/{cid}?autoplay=1&muted=1"
width="640" height="360"
frameborder="0"
allow="autoplay; fullscreen; picture-in-picture"
allowfullscreen
></iframe>09 · verify a TXC signed message
/api/public/txc-verify-messageCryptographically verifies a message signed by a TEXITcoin wallet. Useful for wallet-gated content, comment attribution, or proving ownership against any TXC address — not just Bonfire ones.
curl -X POST https://bonfire.honest.money/api/public/txc-verify-message \
-H "content-type: application/json" \
-d '{
"address": "txc1q...",
"signature": "H4r...==",
"message": "I own this wallet"
}'
# → { "valid": true }10 · TXC node health
/api/public/txc-healthLive status of the TEXITcoin node behind Bonfire's stamping: tip block height, chain info, hot-wallet balance, and the public top-up address. Handy for monitoring or status dashboards.
curl https://bonfire.honest.money/api/public/txc-health | jq
Every account, post and comment on Bonfire has a derived TXC address. Its whole lifecycle — publish, payment, renewal, takedown, succession — is published as on-chain transactions to that address. Audit any of it on the public explorer:
https://mempool.texitcoin.org/address/{address}12 · post IDs & lookup
Every post has a short, six-character ID taken from the post's own derived TEXITcoin address — so the ID you share points straight at the on-chain record. Long database IDs still work forever, so old links never break.
https://bonfire.honest.money/p/FB277B # short, shareable https://bonfire.honest.money/p/efb277b9-8908-4617-98f6-ffb3ab1330c8 # original long id, still valid
look up a post and its proof
/api/public/post/{id}Accepts a short ID or a long ID. Returns the post, its author, its IPFS manifest CID, its own chain address and derivation path, and the OP_RETURN transaction that stamped it.
curl "https://bonfire.honest.money/api/public/post/FB277B" | jq
# → {
# "post": { "shortId": "FB277B", "kind": "story", "body": "…", "tags": [] },
# "author": { "wallet": "txc1…", "handle": "…" },
# "proof": { "metadataCid": "bafy…", "ownerAddress": "txc1…",
# "derivationPath": "m/44'/696969'/1101'/0/7",
# "txHash": "…", "opReturn": "TXCV1P|bafy…|B" },
# "links": { "page": "…", "embed": "…", "oembed": "…" }
# }12 · [ ground rules ]
- · Reading is free and key-less. Writing — posting, commenting, boosting — costs a little TXC from your Bonfire balance. That's the anti-troll toll, not a subscription.
- · Be reasonable. There's no hard rate limit, but bots that hammer the gateway get throttled at the edge.
- · Content whose hosting isn't paid gets unpinned after the grace window — CIDs survive on IPFS but may not be served from our gateway.
- · Want to publish? Use the /feed composer or /upload for video — they handle pinning, wallet derivation, OP_RETURN stamping and fees in one shot.
Built something on top of Bonfire? Stamp it on the chain — your tx shows up in that address's history forever. learn more about TEXITcoin