> ## Documentation Index
> Fetch the complete documentation index at: https://docs.simpuru.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Finish signing in

> Send the `{ key, signature }` from `signData`. On the first sign-in the account and its Simpuru wallet are created (limits 10 tADA per purchase, 30 tADA a day). The session lasts 7 days.



## OpenAPI

````yaml https://api.simpuru.xyz/openapi.json post /auth/verify
openapi: 3.1.0
info:
  title: Simpuru API
  version: 0.1.0
  summary: Buyer protection for AI agents paying with x402 on Cardano (preprod).
  description: >-
    Sellers list design prompts; each listing commits to the SHA-256 of its
    content.

    Buyers (people or agents) pay over **x402** on Cardano preprod, either
    **instant** (pay the seller)

    or **protected** (lock into our `vested_pay` escrow, released only if
    delivery checks out).


    Consumers: the web app (`apps/web`), the buyer agent and protection watcher
    (`apps/agent`), the MCP

    server (`apps/mcp`, hosted at `/mcp`), and the arbiter service
    (`apps/arbiter`, internal).


    Every on-chain claim can be checked on
    `https://preprod.cardanoscan.io/transaction/<hash>`.
  license:
    name: MIT
    identifier: MIT
servers:
  - url: https://api.simpuru.xyz
    description: Production (Cardano preprod)
  - url: http://localhost:4021
    description: Local `bun run dev` in apps/api
security: []
tags:
  - name: Account
    description: >-
      Sign in with a Cardano wallet (CIP-30 `signData`), then use the session as
      `Authorization: Bearer <token>`. Every account has a Simpuru wallet: a
      preprod wallet the platform holds for the owner, funded with tADA, that
      web purchases and the owner's agents spend from.
  - name: Catalogue
    description: Free listing data.
  - name: Paid content
    description: 'The x402 paywall: instant or escrow-protected.'
  - name: Purchases
    description: Purchase timelines, derived from chain by the seller agent.
  - name: MCP
    description: Model Context Protocol endpoint for agents (Claude Code, Cursor, ...).
  - name: Arbiter (internal)
    description: Dispute settlement service, `apps/arbiter`, port 4023. Not public.
  - name: System
    description: Health.
paths:
  /auth/verify:
    post:
      tags:
        - Account
      summary: Finish signing in
      description: >-
        Send the `{ key, signature }` from `signData`. On the first sign-in the
        account and its Simpuru wallet are created (limits 10 tADA per purchase,
        30 tADA a day). The session lasts 7 days.
      operationId: authVerify
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                owner:
                  type: string
                key:
                  type: string
                  description: COSE_Key hex from signData.
                signature:
                  type: string
                  description: COSE_Sign1 hex from signData.
              required:
                - owner
                - key
                - signature
      responses:
        '200':
          description: Signed in
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
                    description: 'Send as `Authorization: Bearer <token>`.'
                  expiresAt:
                    type: integer
                    description: Unix ms.
                  account:
                    type: object
                    properties:
                      owner:
                        type: string
                      walletAddress:
                        type: string
                        description: The Simpuru wallet; send tADA here to shop.
                    required:
                      - owner
                      - walletAddress
                required:
                  - token
                  - expiresAt
                  - account
        '400':
          description: Missing owner
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Bad signature, or no live challenge for this address
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.