API docs
The two read-only endpoints a collection's own contracts point at, what they answer, and how often they may be read.
The two endpoints
A collection whose on-chain base URI points at /api/metadata/<collection>/ answers two documents here: each of its tokens' metadata at /api/metadata/<collection>/<tokenId>, and the collection's own at /api/metadata/<collection>/contract — the document EIP-7572 calls contractURI. The platform writes that base URI when it creates a collection; a token minted with a URI of its own keeps it instead, because the per-token value takes precedence.
A collection is named by its numeric id or by its slug, and both work in either URL. Everything else under /api belongs to a session, to an operator or to the cron scheduler — none of it is addressed by a contract, so none of it is promised here.
A token's metadata
The answer is the JSON an ERC-721 client expects: a name, an image and the token's attributes. A token id has to be a plain non-negative integer; anything else is a 400, and a collection or a token that does not exist is a 404.
The values are read per request rather than frozen at the mint. The name and the token's own metadata come from the row the platform holds; the attributes are assembled from the parameters the drop defines and the values this token carries — from the database when the mint went through this site, and from the chain when it did not. The outputs of data rules, which are what a drop binds to a live feed, are read through on every request too, so a rule that moves reaches a marketplace within the cache window below.
The image falls back in order: a file pinned for this token's state, then the token's own artwork, then the collection's cover, then the cover of the single release that points at the collection. When two releases share one collection — an auction series does — neither cover is guessed at, and a token with no image is the better answer.
A collection's metadata
The collection's document carries its name, its description, an image by the same fallback, the royalty in basis points and the artist's confirmed wallet where there is one. A collection answers its own contractURI from the moment it is created: the field is written as the token base plus the word contract.
How often they may be read
- 600 requests per minute for one IP address. Past that the answer is 429 with a Retry-After header, in seconds.
- Cache-Control: public, max-age=60, s-maxage=60, stale-while-revalidate=300 — a minute of freshness so a change propagates, and not zero, so that a popular drop cannot turn every marketplace refresh into a database read.