NDX developer docs

NDX (getndx.com) is a trading card collection product. This page is the public developer entry point: how to find the OpenAPI specification, which endpoints are reachable without a user session, and how authenticated collector APIs work.

When to call NDX

Call these APIs when you need to:

Do not call NDX to scrape the full trading-card catalog, to place marketplace orders, or to impersonate a collector. Catalog identification and most collection writes require a signed-in NDX user.

Discoverability

Public endpoints

These do not require a collector session.

Waitlist — POST https://getndx.com/api/waitlist

Adds an email to the NDX launch waitlist. Idempotent: repeating the same email still returns success.

POST /api/waitlist HTTP/1.1
Host: getndx.com
Content-Type: application/json

{"email":"collector@example.com"}
{"ok":true}

A hidden website field is a honeypot. Bots that fill it still receive {"ok":true} and are not stored.

Health — GET https://api.getndx.com/healthz

Liveness. Returns {"status":"ok"} without touching the database.

Readiness — GET https://api.getndx.com/health

Readiness. Pings Postgres. Use this to decide whether the consumer API can serve traffic.

Public library views — GET https://api.getndx.com/v1/public/u/{userId}/views

Lists a collector's published library views. {userId} is the collector's NDX user UUID. Unauthenticated.

Public view query — GET https://api.getndx.com/v1/public/u/{userId}/views/{slug}/query

Returns the cards in one published view. Optional limit (1–100) and cursor query parameters.

Authentication

Collector APIs under https://api.getndx.com/v1/ expect:

Authorization: Bearer <ndx-session-token>

Mint a session by posting a provider identity token to POST /v1/auth/apple or POST /v1/auth/google. The response includes a short-lived NDX access token and a refresh token (POST /v1/auth/refresh). There is no public API key for catalog-wide access.

GET /v1/me HTTP/1.1
Host: api.getndx.com
Authorization: Bearer <ndx-session-token>

GET /v1/me/portfolio returns collection value. GET /v1/release-calendar/ returns upcoming releases. Both require the bearer token.

Spec quality

Every operation in openapi.json has a unique operationId, a description, typed parameters, and response schemas so agents can register the endpoints as tools.

Policies

Using the API is subject to the Terms of Use and Acceptable Use Policy. Privacy details: Privacy Policy. Questions: contact.