Roadmap
What is built, what is still an interface, and what comes next
Use this page to decide what to integrate against now. Anything marked 🟡 is not live. Don't build a production dependency on it yet.
What your key gets today#
Float is pre-launch. Live keys don't work for underwriting or KYB yet. See Environments and access.
Test keys (fk_test_) | Live keys (fk_live_) | |
|---|---|---|
| Underwriting | Full sandbox behavior with mock results | 503. No real provider is configured yet |
| KYB | Full sandbox behavior with mock results | 503. No real provider is configured yet |
| Chain observation | Solana devnet | Not enabled |
| Document uploads | 503. No object storage is configured yet | 503. No object storage is configured yet |
| Attestations | Created, but stay pending (no anchor) | Created, but stay pending (no anchor) |
What is real vs stubbed#
| Area | 🟢 Real now | 🟡 Interface / not yet built |
|---|---|---|
| Auth | Partner API keys (HMAC-hashed, scoped, test/live, revocable), service keys | OAuth client credentials |
| HTTP conventions | Envelope, error registry, request IDs, validation, idempotency, rate limit, security headers | Published API Reference, on hold while the API is finalized |
| Businesses | Create/link, masked identifiers (AES-GCM + blind index), ed25519 wallet proofs, wallet-based identity | KYB. Test keys use a sandbox; live keys return 503, and businesses stay unverified |
| Underwriting | Async lifecycle, dispatch with retries, SLA sweeper, information push, result ingestion, taxonomy validation | Real engine. Sandbox is test-only. Live keys return 503 until a real provider is connected |
| Assessments | Stored, band resolved from versioned taxonomy, expiry flag | Final band taxonomy (draft-1 is a placeholder) |
| Events & webhooks | Outbox, GET /v1/events, signed webhooks (retries, auto-disable, secret rotation, SSRF guard with connect-time IP check) | Self-serve endpoint management (operator-managed for now) |
| Attestations | Fingerprints, batching, proofs, private detail for the owning partner, and a public verification endpoint. See Verifiable assessments | On-chain anchoring is not live. Every attestation sits at pending with no anchor. Revocation isn't wired up yet |
| Documents | Encrypted upload, forwarding, retention + deletion sweep | Uploads return 503: no object storage is configured yet. Production retention policy is also undecided |
| Obligations & repayments | Registration, reported accounting + status machine, overdue sweeper, repayment references, verification pipeline, OutcomePolicy (chain_observed v0), real Solana observer per environment | Discovery of unreported invoice repayments (only partner-supplied tx signatures are verified) |
| Credit lines | kind: credit_line, Float-wide ceilings with per-provider shares, facilities, usage, live limit, settlements, chain observer for Subscriptions & Allowances delegations, CreditOutcomePolicy (chain_observed_credit v0) | Stream/webhook indexer for scale (polling today) |
| Reputation | Consent-gated cross-partner read from Float-verified evidence only; evidence_only policy | Band policy (band is always null) |
The chain observer is real but off by default, enabled per environment. Where it is off: repayments report float_verification.status: "not_configured", obligations report verified.chain_observability: "not_configured", and reputation returns evidence_status: "chain_verification_not_configured" with empty counts. Today it is on for test keys (Solana devnet) and not enabled for live keys.
Next increments#
Agreed scope, not built yet. Roughly in order.
Publish batch values on Solana, and revoke when an assessment is withdrawn.
S3/GCS/R2 adapter, malware scanning, retention for information payloads and invoices.
Delivery logs in the dashboard and a manual redeliver command.
Find unreported repayments via repayment_reference (source chain_observed).
Replace polling with a webhook/stream indexer (Helius / Geyser). Pick a mainnet RPC provider.
Confirm against a real failed CPI pull (none in the mainnet sample yet).
Grace window, revocation with outstanding usage, scaling by amounts.
Replace the open 0.1 schema with fields agreed with the underwriting developer.
Decide bands and which cross-partner evidence to expose.
Recovered after default, disputes, restructuring.
Generated from the API itself, once the API is finalized.
Deferred by decision#
| Item | Status today |
|---|---|
| Double-financing detection | Invoice fingerprint is written; detection logic later |
| Production document retention | Legal/compliance decision; policy is configurable once decided |
| Real information schema | Open schema 0.1 until the field set is agreed |
| Real band taxonomy | invoice_risk/draft-1 is a placeholder |
| KYB | identity_status stays unverified until an identity provider is integrated |
Later#
API surface
POST /v1/underwriting_requests/{id}/cancel(thecanceledstate already exists)- List endpoints for underwriting requests and obligations, if partners ask (
GET /v1/eventscovers reconciliation today) PATCH /v1/businesses/{id}
Self-serve & auth
- Self-serve API keys and webhooks (with the dashboard)
- OAuth client credentials
- Wallet-signed consent grants instead of partner-attested consent
Operations
- Metrics export and alert routing
- A worker health endpoint