SolFund by The Galactic Center
API
Version 1 is a public HTTP API for the same reclaim flow as the website. It returns closable accounts and unsigned transactions. You sign those transactions in your own wallet. The server does not accept private keys.
This deployment is on Devnet with a service fee of 0%. The machine-readable spec is /api/v1/openapi.json.
Authentication
If SOLFUND_API_KEY is unset, requests are public. If it is set, send the key as Authorization: Bearer or the x-api-key header. A missing or wrong key returns 401.
Rate limit and CORS
Each IP address is limited to SOLFUND_RATE_LIMIT_PER_MINUTE requests per minute, default 60. The limit is tracked in this server process, so it is a basic guard, not a global quota. Responses include X-RateLimit-Limit and X-RateLimit-Remaining. A 429 includes Retry-After.
Browser origins are controlled by SOLFUND_CORS_ORIGINS. The default is *. Set a comma-separated list of origins to restrict it.
GET /api/v1/scan/{wallet}
Reads classic Token and Token-2022 accounts for a public address. Closable empty accounts, fungible tokens, and standard NFTs are returned with the lamports each close would reclaim. Programmable NFTs and other accounts that cannot be closed safely are returned under unsupported with a reason. Compressed NFTs are not token accounts and are omitted. The quote is the fee math for closing every closable account.
curl "$ORIGIN/api/v1/scan/YOUR_WALLET_ADDRESS"
POST /api/v1/build-transactions
Body is JSON with the owner's public address and the token account addresses to close. The server scans again and uses chain balances. It ignores any amount you might try to send. The response contains unsigned legacy transactions, base64-encoded, plus the recent blockhash and an instruction summary.
Each transaction may contain only closeAccount, burn (for a listed balance), one SystemProgram.transfer of the disclosed fee, and compute budget instructions. Rent is paid to the owner. Review the transaction before you sign. Burning is permanent.
curl -X POST "$ORIGIN/api/v1/build-transactions" \
-H "content-type: application/json" \
-d '{"wallet":"YOUR_WALLET_ADDRESS","accounts":["TOKEN_ACCOUNT"]}'Deserialize with Transaction.from from @solana/web3.js, then sign with the wallet that owns the accounts. Do not send the signed transaction back to this API.
GET /api/v1/stats
Returns the fee, whether a treasury and buyback wallet are configured, and null network totals. A public indexer is not connected, so those figures are not invented. The response also includes scan and build counts for this server process. They reset when the process restarts.
curl "$ORIGIN/api/v1/stats"
What not to send
Do not send a seed phrase, a secret key, a keypair file, or a private key in any field or path. Those requests are rejected. Lamport amounts in responses are decimal strings so large values are not rounded.
More detail on the fee and the treasury is on the transparency page.