> ## Documentation Index
> Fetch the complete documentation index at: https://docs.calibri.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authorise a session key

> Returns the Safe calls that authorise a browser-held P-256 key to sign orders. Nothing is authorised until you sign and relay them. `expires_at` is clamped DOWN to policy. The key is never a Safe owner, so withdraw and redeem stay passkey-only.



## OpenAPI

````yaml /api-reference/openapi/calibri.yaml post /api/v2/atlas/account/wallet/session-key
openapi: 3.1.0
info:
  title: Calibri API
  version: 1.0.0
  description: >-
    The Calibri API. Discover markets, read live books, place signed orders, and
    manage positions and account data.

    Routed by path prefix to the service that answers it — which is an
    implementation detail, not something a caller has to reason about.
servers:
  - description: Production
    url: https://calibri.io
security: []
tags:
  - name: Health
    description: Service liveness.
    x-displayName: Health
  - name: Events
    description: Discover events and their metadata.
    x-displayName: Events
  - name: Markets
    description: List markets and load market detail for trading.
    x-displayName: Markets
  - name: Series
    description: Recurring event series.
    x-displayName: Series
  - name: Tags
    description: Editorial shelves used to browse the catalogue.
    x-displayName: Tags
  - name: Market Data
    description: Order book, depth, trade tape, tickers, and candles.
    x-displayName: Market Data
  - name: Assets
    description: Underlying asset price history for price-feed markets.
    x-displayName: Assets
  - name: Community
    description: Leaderboard and platform activity.
    x-displayName: Community
  - name: Currencies
    description: Currency registry.
    x-displayName: Currencies
  - name: Trade
    description: Place, list, and cancel orders.
    x-displayName: Trade
  - name: Positions
    description: Your matched contracts.
    x-displayName: Positions
  - name: Wallet
    description: Self-custody Safe, passkey, session keys, and relay.
    x-displayName: Wallet
  - name: Rewards
    description: Maker rebates and referral earnings.
    x-displayName: Rewards
  - name: Account
    description: Balances, ledger, PnL, limits, preferences, and profile.
    x-displayName: Account
  - name: Categories
    description: Categories
    x-displayName: Categories
  - name: Other
    description: Other
    x-displayName: Other
externalDocs:
  description: ''
  url: ''
paths:
  /api/v2/atlas/account/wallet/session-key:
    post:
      tags:
        - Wallet
      summary: Authorise a session key
      description: >-
        Returns the Safe calls that authorise a browser-held P-256 key to sign
        orders. Nothing is authorised until you sign and relay them.
        `expires_at` is clamped DOWN to policy. The key is never a Safe owner,
        so withdraw and redeem stay passkey-only.
      parameters: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SessionKeyPrepareRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SessionKeyPrepareEntity'
          description: ''
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEntity'
          description: ''
      security:
        - apiKey: []
components:
  schemas:
    SessionKeyPrepareRequest:
      properties:
        expires_at:
          description: >-
            Requested expiry, Unix seconds. Clamped DOWN to policy — asking for
            longer returns the ceiling rather than an error.
          example: 1797600000
          type: number
        x:
          description: P-256 public key X coordinate of the browser-held key.
          example: 0x2f9a…
          type: string
        'y':
          description: P-256 public key Y coordinate.
          example: 0x8c41…
          type: string
      required:
        - x
        - 'y'
      type: object
    SessionKeyPrepareEntity:
      properties:
        calls:
          description: Sign and relay these to authorise the key.
          items:
            $ref: '#/components/schemas/SafeSetupCallEntity'
          type: array
        expires_at:
          description: The granted expiry, clamped DOWN to product policy.
          example: 1797600000
          type: number
        handler_installed:
          example: true
          type: boolean
        safe:
          example: '0x0DECE7d83f8D47CD8dD8278c0F22c361C58577BD'
          type: string
      required:
        - safe
        - handler_installed
        - expires_at
        - calls
      type: object
    ErrorEntity:
      properties:
        errors:
          description: Match on the code, not the HTTP status or the human text.
          example:
            - account.custody.deposits_disabled
          items:
            type: string
          type: array
      required:
        - errors
      type: object
    SafeSetupCallEntity:
      properties:
        data:
          description: ABI-encoded calldata.
          example: 0x095ea7b3…
          type: string
        hash:
          description: The SafeTx hash to sign.
          example: 0x9ab1…
          type: string
        nonce:
          description: The Safe's nonce for this call. Relay in order.
          example: 4
          type: number
        operation:
          description: '`0` = CALL, `1` = DELEGATECALL (a MultiSend batch).'
          example: 0
          type: number
        to:
          description: Target contract.
          example: '0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359'
          type: string
      required:
        - to
        - data
        - operation
        - nonce
        - hash
      type: object
  securitySchemes:
    apiKey:
      description: >-
        HMAC-signed API key. Send X-Auth-Apikey, X-Auth-Nonce and
        X-Auth-Signature.
      in: header
      name: X-Auth-Apikey
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.