Skip to main content
POST
Authorise a session key

Authorizations

X-Auth-Apikey
string
header
required

HMAC-signed API key. Send X-Auth-Apikey, X-Auth-Nonce and X-Auth-Signature.

Body

application/json
x
string
required

P-256 public key X coordinate of the browser-held key.

Example:

"0x2f9a…"

y
string
required

P-256 public key Y coordinate.

Example:

"0x8c41…"

expires_at
number

Requested expiry, Unix seconds. Clamped DOWN to policy — asking for longer returns the ceiling rather than an error.

Example:

1797600000

Response

calls
object[]
required

Sign and relay these to authorise the key.

expires_at
number
required

The granted expiry, clamped DOWN to product policy.

Example:

1797600000

handler_installed
boolean
required
Example:

true

safe
string
required
Example:

"0x0DECE7d83f8D47CD8dD8278c0F22c361C58577BD"