> This page is for Taurus PROTECT, version v3.48.
> For other versions, use one of these documentation indexes:
> - v3.58 (default): https://taurushq.ferndocs.com/protect-capital/v3.58/llms.txt
> - v3.56: https://taurushq.ferndocs.com/protect-capital/v3.56/llms.txt
> - v3.54: https://taurushq.ferndocs.com/protect-capital/v3.54/llms.txt
> - v3.52: https://taurushq.ferndocs.com/protect-capital/v3.52/llms.txt
> - v3.50: https://taurushq.ferndocs.com/protect-capital/v3.50/llms.txt
> - v3.48: https://taurushq.ferndocs.com/protect-capital/v3.48/llms.txt
> - v3.46: https://taurushq.ferndocs.com/protect-capital/v3.46/llms.txt
> - v3.44: https://taurushq.ferndocs.com/protect-capital/v3.44/llms.txt
> - v3.42: https://taurushq.ferndocs.com/protect-capital/v3.42/llms.txt
> - v3.40: https://taurushq.ferndocs.com/protect-capital/v3.40/llms.txt
> - v3.38: https://taurushq.ferndocs.com/protect-capital/v3.38/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://taurushq.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://taurushq.ferndocs.com/_mcp/server.

# Create whitelisted contracts

POST https://your-protect-instance.example.com/api/rest/v1/whitelists/contracts
Content-Type: application/json

This endpoint creates a new whitelisted contracts.
For ETH, `tokenId` is left empty
For XTZ, `tokenId` is left empty for FA1.2 tokens and must have a value for FA2 tokens
For ALGO, we either need a tokenId which is the `assetId` for algorand, or we need a `contractAddress` (creator address) and a `symbol` (unit name), which will be used to identify the asset.
For XLM,  we need a valid `contractAddress` (Stellar address) and `tokenId` (Stellar asset code).For ICP, we need a valid `contractAddress` (valid ICP principal).Required role: **WhitelistedAddressCreator**.

Reference: https://taurushq.ferndocs.com/protect-capital/reference/contract-whitelisting/create

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Request

### Body (application/json)

This endpoint expects a tgvalidatordCreateWhitelistedContractAddressRequest.

- `blockchain` (string, required) — Symbol of the blockchain on which to whitelist a contract. Examples: `BTC`, `ADA`, `SOL` ...
- `symbol` (string, required) — Symbol of the token. For ALGO it is the unit name of the standard asset.
- `contractAddress` (string, optional) — Address of the smart contract. For ALGO standard assets, this is the address of the creator of the asset. For XLM, this is the Stellar address. For ICP, this is the ICP principal.
- `name` (string, optional) — Name for the contract.
- `decimals` (string, optional) — Number of decimal places to consider as minimum unit of transfer.
- `tokenId` (string, optional) — Unused for ETH and Polygon. For XTZ, this is used to create a FA2 token. For ALGO standard assets, this is the globally unique asset id.
- `kind` (string, optional) — Examples: `""` (default), `"NFT_AUTO"`, `"NFT_XTZ_FA2"`, `"NFT_EVM_ERC721"`, `"NFT_EVM_ERC1155"`, `"SOL_TOKEN"`, `"SOL_TOKEN2022"`, `"NFT_EVM_CRYPTOPUNKS"`
- `network` (string, optional) — Name of the blockchain network, eg. `mainnet`, `testnet`, or `sepolia`.

## Response

### 200

A successful response.

- `result` (tgvalidatordIDResult, optional)

## Errors

### 400 Bad Request Error

Bad Request: indicates that the server cannot or will not process the request due to something that is perceived to be a client error (for example, malformed request syntax, invalid request message framing, or deceptive request routing)

- `any`

### 401 Unauthorized Error

Unauthorized: indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource

- `any`

### 403 Forbidden Error

Forbidden: indicates that the server understands the request but refuses to authorize it

- `any`

### 404 Not Found Error

Not Found: indicates that the server cannot find the requested resource

- `any`

### 500 Internal Server Error

Internal Server Error: indicates that the server encountered an unexpected condition that prevented it from fulfilling the request

- `any`

### 503 Service Unavailable Error

Service Unavailable: indicates that the server is not ready to handle the request.

- `any`

## Types

### tgvalidatordIDResult

- `id` (string, optional)

## Examples

**Request**

```json
{
  "blockchain": "string",
  "symbol": "string"
}
```

**Response**

```json
{
  "result": {
    "id": "1322"
  }
}
```

**SDK Code**

```python
import requests

url = "https://your-protect-instance.example.com/api/rest/v1/whitelists/contracts"

payload = {
    "blockchain": "string",
    "symbol": "string"
}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://your-protect-instance.example.com/api/rest/v1/whitelists/contracts';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"blockchain":"string","symbol":"string"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://your-protect-instance.example.com/api/rest/v1/whitelists/contracts"

	payload := strings.NewReader("{\n  \"blockchain\": \"string\",\n  \"symbol\": \"string\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://your-protect-instance.example.com/api/rest/v1/whitelists/contracts")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"blockchain\": \"string\",\n  \"symbol\": \"string\"\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://your-protect-instance.example.com/api/rest/v1/whitelists/contracts")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"blockchain\": \"string\",\n  \"symbol\": \"string\"\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://your-protect-instance.example.com/api/rest/v1/whitelists/contracts', [
  'body' => '{
  "blockchain": "string",
  "symbol": "string"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://your-protect-instance.example.com/api/rest/v1/whitelists/contracts");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"blockchain\": \"string\",\n  \"symbol\": \"string\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "blockchain": "string",
  "symbol": "string"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://your-protect-instance.example.com/api/rest/v1/whitelists/contracts")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```