API migration record, September 2026¶
Historical record
Nothing on this page is served. Every path in a Removed spelling column answers the
ordinary 404 for an authenticated call, like any other path the API does not serve. The
current API is the endpoint reference, and the policy is on
Deprecations. This page exists only to help you port an integration
written against the old paths.
In September 2026 four sets of operations moved to their final spellings, and the canonical-only release removed every old spelling:
- Session-scoped paths
- EVM and SVM split
- Custom-method actions
- Product namespaces
- The session-tag header
The operations themselves did not change: request and response bodies, ids and
Idempotency-Key rules are the same under the new path.
Session-scoped paths¶
Operations that act on your fork session used to live at flat paths. They moved under the
session they act on, sessions/{uid}/…. The operation, body and response are unchanged. Use your
session id from X-Resource-Id, or current.
| Method | Removed spelling | Use instead |
|---|---|---|
POST |
/api/v1/bevm/transactions |
/api/v1/bevm/sessions/{uid}/transactions |
POST |
/api/v1/bevm/transactions:replay |
/api/v1/bevm/sessions/{uid}/transactions:replay |
POST |
/api/v1/bevm/transactions:resolve |
/api/v1/bevm/sessions/{uid}/transactions:resolve |
POST |
/api/v1/bevm/snapshots |
/api/v1/bevm/sessions/{uid}/snapshots |
POST |
/api/v1/bevm/snapshots:restore |
/api/v1/bevm/sessions/{uid}/snapshots:restore |
GET |
/api/v1/bevm/balances/{address} |
/api/v1/bevm/sessions/{uid}/balances/{address} |
POST |
/api/v1/bevm/balances:batchGet |
/api/v1/bevm/sessions/{uid}/balances:batchGet |
POST |
/api/v1/bevm/logs:query |
/api/v1/bevm/sessions/{uid}/logs:query |
POST |
/api/v1/bevm/facets:resolve |
/api/v1/bevm/sessions/{uid}/facets:resolve |
POST |
/api/v1/bevm/fundings:apply |
/api/v1/bevm/sessions/{uid}/fundings:apply |
POST, GET |
/api/v1/bevm/differentials |
/api/v1/bevm/sessions/{uid}/differentials |
GET |
/api/v1/bevm/provenance-seals/current |
/api/v1/bevm/sessions/{uid}/provenance-seals |
POST |
/api/v1/bevm/deployments |
/api/v1/bevm/sessions/{uid}/deployments |
POST |
/api/v1/bevm/contracts:call |
/api/v1/bevm/sessions/{uid}/contracts:call |
POST |
/api/v1/bevm/storage-traces |
/api/v1/bevm/sessions/{uid}/storage-traces |
POST |
/api/v1/bevm/storage-slots:read |
/api/v1/bevm/sessions/{uid}/storage-slots:read |
POST |
/api/v1/bevm/storage-slots:write |
/api/v1/bevm/sessions/{uid}/storage-slots:write |
POST |
/api/v1/bevm/blocks |
/api/v1/bevm/sessions/{uid}/blocks |
POST |
/api/v1/bevm/introspections |
/api/v1/bevm/sessions/{uid}/introspections |
POST |
/api/v1/bevm/transient-analyses |
/api/v1/bevm/sessions/{uid}/transient-analyses |
POST |
/api/v1/bevm/gas-fuzz-traces |
/api/v1/bevm/sessions/{uid}/gas-fuzz-traces |
GET |
/api/v1/bevm/engagement-exports |
/api/v1/bevm/sessions/{uid}/engagement-exports |
EVM and SVM split¶
Solana (SVM) operations used to live under the EVM product, at …/svm/… inside
/api/v1/bevm/*. They now have their own product prefix, /api/v1/bsvm/*. EVM is bevm, SVM is
bsvm.
| Method | Removed spelling | Use instead |
|---|---|---|
GET |
/api/v1/bevm/targets/{uid}/svm/blocks |
/api/v1/bsvm/targets/{uid}/blocks |
GET |
/api/v1/bevm/targets/{uid}/svm/blocks/{pc} |
/api/v1/bsvm/targets/{uid}/blocks/{pc} |
GET |
/api/v1/bevm/targets/{uid}/svm/heap |
/api/v1/bsvm/targets/{uid}/heap |
GET |
/api/v1/bevm/targets/{uid}/svm/cfg |
/api/v1/bsvm/targets/{uid}/cfg |
GET |
/api/v1/bevm/targets/{uid}/svm/functions |
/api/v1/bsvm/targets/{uid}/functions |
GET |
/api/v1/bevm/targets/{uid}/svm/trace |
/api/v1/bsvm/targets/{uid}/trace |
GET |
/api/v1/bevm/targets/{uid}/svm/access-map |
/api/v1/bsvm/targets/{uid}/access-map |
POST |
/api/v1/bevm/sessions/{uid}/svm/transactions |
/api/v1/bsvm/sessions/{uid}/transactions |
POST |
/api/v1/bevm/sessions/{uid}/svm/transactions:simulate |
/api/v1/bsvm/sessions/{uid}/transactions:simulate |
POST |
/api/v1/bevm/sessions/{uid}/svm/airdrops |
/api/v1/bsvm/sessions/{uid}/airdrops |
GET |
/api/v1/bevm/sessions/{uid}/svm/latest-blockhash |
/api/v1/bsvm/sessions/{uid}/latest-blockhash |
Solana sessions are opened with POST /api/v1/bsvm/sessions; the EVM product opens EVM
sessions only.
Custom-method actions¶
A few actions were spelled as a path segment (…/{id}/release) or as a bare POST that meant
"do something". They now use custom methods: the action follows a
colon on the resource it acts on.
| Method | Removed spelling | Use instead |
|---|---|---|
POST |
/api/v1/bevm/audit-legal-holds/{hold_id}/release |
/api/v1/workbench/audit-legal-holds/{hold_id}:release |
POST |
/api/v1/bevm/audit-destinations/{dest_id}/enable |
/api/v1/workbench/audit-destinations/{dest_id}:enable |
POST |
/api/v1/bevm/audit-destinations/{dest_id}/disable |
/api/v1/workbench/audit-destinations/{dest_id}:disable |
POST |
/api/v1/bevm/library/presets (build a preset) |
/api/v1/bevm/library/presets:build |
POST |
/api/v1/bevm/library/presets/{preset_id} (apply a preset) |
/api/v1/bevm/library/presets/{preset_id}:apply |
Reading presets was unchanged. Legal holds and SIEM destinations then moved to the workbench namespace (next section), so the three evidence-plane rows above give their final spelling.
Product namespaces¶
Every endpoint now lives under the one product it belongs to:
| Namespace | Product |
|---|---|
/api/v1/bevm/ |
EVM workbench: sessions, targets, scans, Composer, the contract sandbox |
/api/v1/bsvm/ |
SVM (Solana) workbench |
/api/v1/workbench/ |
what both workbenches share: the audit evidence plane, long-running operations, artifacts, your IDE view |
/api/v1/radar/ |
chain intelligence: contract code search today |
/api/v1/workspaces/ |
workspaces, projects, activity, the contract and audit indexes, invitations, notes |
Nothing else about these operations changed: same bodies, same ids, same Idempotency-Key rules.
Radar moved off the generic /api/v1/code/ prefix onto its product:
| Method | Removed spelling | Use instead |
|---|---|---|
POST |
/api/v1/code/search |
/api/v1/radar/code/search |
POST |
/api/v1/code/search:count |
/api/v1/radar/code/search:count |
GET |
/api/v1/code/{code_id} |
/api/v1/radar/code/{code_id} |
Workspaces: the plane's top-level collections moved under /api/v1/workspaces/. Paths that
were already under it, such as /api/v1/workspaces/{workspace_id}/projects, are unchanged.
| Method | Removed spelling | Use instead |
|---|---|---|
GET |
/api/v1/projects |
/api/v1/workspaces/projects |
GET, PATCH, DELETE |
/api/v1/projects/{project_id} |
/api/v1/workspaces/projects/{project_id} |
GET, POST |
/api/v1/projects/{project_id}/audit-logs |
/api/v1/workspaces/projects/{project_id}/audit-logs |
GET |
/api/v1/projects/{project_id}/overview |
/api/v1/workspaces/projects/{project_id}/overview |
GET, POST |
/api/v1/projects/{project_id}/members |
/api/v1/workspaces/projects/{project_id}/members |
DELETE |
/api/v1/projects/{project_id}/members/{member_id} |
/api/v1/workspaces/projects/{project_id}/members/{member_id} |
GET, POST |
/api/v1/projects/{project_id}/invitations |
/api/v1/workspaces/projects/{project_id}/invitations |
DELETE |
/api/v1/projects/{project_id}/invitations/{invitation_id} |
/api/v1/workspaces/projects/{project_id}/invitations/{invitation_id} |
GET |
/api/v1/activity |
/api/v1/workspaces/activity |
GET |
/api/v1/contracts |
/api/v1/workspaces/contracts |
GET |
/api/v1/contracts/inventory |
/api/v1/workspaces/contracts/inventory |
GET |
/api/v1/audits |
/api/v1/workspaces/audits |
GET |
/api/v1/audits/publications |
/api/v1/workspaces/audits/publications |
POST |
/api/v1/invitations/accept |
/api/v1/workspaces/invitations:accept |
| all | /api/v1/notes/… |
/api/v1/workspaces/notes/… |
Workbench: the capabilities both VM workbenches share moved off the EVM prefix, so a
Solana-only team never has to call /api/v1/bevm/:
| Method | Removed spelling | Use instead |
|---|---|---|
GET, PUT, PATCH, DELETE |
/api/v1/bevm/audit-views/me |
/api/v1/workbench/audit-views/me |
GET |
/api/v1/bevm/audit-events |
/api/v1/workbench/audit-events |
GET |
/api/v1/bevm/audit-events/{event_id} |
/api/v1/workbench/audit-events/{event_id} |
GET |
/api/v1/bevm/audit-checkpoints |
/api/v1/workbench/audit-checkpoints |
GET, POST |
/api/v1/bevm/audit-exports |
/api/v1/workbench/audit-exports |
GET |
/api/v1/bevm/audit-exports/{export_id} |
/api/v1/workbench/audit-exports/{export_id} |
GET |
/api/v1/bevm/audit-exports/{export_id}/content |
/api/v1/workbench/audit-exports/{export_id}/content |
GET, PUT |
/api/v1/bevm/audit-retention-policy |
/api/v1/workbench/audit-retention-policy |
GET, POST |
/api/v1/bevm/audit-legal-holds |
/api/v1/workbench/audit-legal-holds |
POST |
/api/v1/bevm/audit-legal-holds/{hold_id}:release |
/api/v1/workbench/audit-legal-holds/{hold_id}:release |
GET |
/api/v1/bevm/audit-tombstones |
/api/v1/workbench/audit-tombstones |
GET, POST |
/api/v1/bevm/audit-destinations |
/api/v1/workbench/audit-destinations |
DELETE |
/api/v1/bevm/audit-destinations/{dest_id} |
/api/v1/workbench/audit-destinations/{dest_id} |
POST |
/api/v1/bevm/audit-destinations/{dest_id}:enable |
/api/v1/workbench/audit-destinations/{dest_id}:enable |
POST |
/api/v1/bevm/audit-destinations/{dest_id}:disable |
/api/v1/workbench/audit-destinations/{dest_id}:disable |
GET, PUT |
/api/v1/bevm/audit-residency |
/api/v1/workbench/audit-residency |
GET |
/api/v1/bevm/operations |
/api/v1/workbench/operations |
GET |
/api/v1/bevm/operations/{op_id} |
/api/v1/workbench/operations/{op_id} |
GET |
/api/v1/bevm/operations/{op_id}/events |
/api/v1/workbench/operations/{op_id}/events |
POST |
/api/v1/bevm/operations/{op_id}:cancel |
/api/v1/workbench/operations/{op_id}:cancel |
POST |
/api/v1/bevm/operations/{op_id}:pause |
/api/v1/workbench/operations/{op_id}:pause |
POST |
/api/v1/bevm/operations/{op_id}:resume |
/api/v1/workbench/operations/{op_id}:resume |
GET |
/api/v1/bevm/artifacts/{artifact_id} |
/api/v1/workbench/artifacts/{artifact_id} |
GET |
/api/v1/bevm/artifacts/{artifact_id}/content |
/api/v1/workbench/artifacts/{artifact_id}/content |
Jobs, analysis jobs, history, executions, the preset library and recipe hints stay on
/api/v1/bevm/: what they return is EVM-specific (wei amounts, EVM storage slots, EVM opcode
traces), so they belong to the EVM product.
The session-tag header¶
The request header that selects one of your concurrent sessions was renamed. Only the new name is read; a request carrying only the old one addresses your default session.
| Removed header | Use instead |
|---|---|
x-bevm-session-tag |
trilocore-session-tag |