> ## Documentation Index
> Fetch the complete documentation index at: https://docs.simpuru.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Start signing in

> Returns the digest the wallet signs. Pass the address CIP-30 gives you (`getChangeAddress()` / `getUsedAddresses()[0]`, hex) or a bech32 `addr_test1…`. The challenge expires in 5 minutes.



## OpenAPI

````yaml https://api.simpuru.xyz/openapi.json post /auth/challenge
openapi: 3.1.0
info:
  title: Simpuru API
  version: 0.1.0
  summary: Buyer protection for AI agents paying with x402 on Cardano (preprod).
  description: >-
    Sellers list design prompts; each listing commits to the SHA-256 of its
    content.

    Buyers (people or agents) pay over **x402** on Cardano preprod, either
    **instant** (pay the seller)

    or **protected** (lock into our `vested_pay` escrow, released only if
    delivery checks out).


    Consumers: the web app (`apps/web`), the buyer agent and protection watcher
    (`apps/agent`), the MCP

    server (`apps/mcp`, hosted at `/mcp`), and the arbiter service
    (`apps/arbiter`, internal).


    Every on-chain claim can be checked on
    `https://preprod.cardanoscan.io/transaction/<hash>`.
  license:
    name: MIT
    identifier: MIT
servers:
  - url: https://api.simpuru.xyz
    description: Production (Cardano preprod)
  - url: http://localhost:4021
    description: Local `bun run dev` in apps/api
security: []
tags:
  - name: Account
    description: >-
      Sign in with a Cardano wallet (CIP-30 `signData`), then use the session as
      `Authorization: Bearer <token>`. Every account has a Simpuru wallet: a
      preprod wallet the platform holds for the owner, funded with tADA, that
      web purchases and the owner's agents spend from.
  - name: Catalogue
    description: Free listing data.
  - name: Paid content
    description: 'The x402 paywall: instant or escrow-protected.'
  - name: Purchases
    description: Purchase timelines, derived from chain by the seller agent.
  - name: MCP
    description: Model Context Protocol endpoint for agents (Claude Code, Cursor, ...).
  - name: Arbiter (internal)
    description: Dispute settlement service, `apps/arbiter`, port 4023. Not public.
  - name: System
    description: Health.
paths:
  /auth/challenge:
    post:
      tags:
        - Account
      summary: Start signing in
      description: >-
        Returns the digest the wallet signs. Pass the address CIP-30 gives you
        (`getChangeAddress()` / `getUsedAddresses()[0]`, hex) or a bech32
        `addr_test1…`. The challenge expires in 5 minutes.
      operationId: authChallenge
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                address:
                  type: string
                  description: Hex (CIP-30) or bech32 preprod address.
              required:
                - address
      responses:
        '200':
          description: Sign `digest` with `api.signData(address, digest)`
          content:
            application/json:
              schema:
                type: object
                properties:
                  owner:
                    type: string
                    description: The address as bech32; send it back to /auth/verify.
                  digest:
                    type: string
                    pattern: ^[0-9a-f]{64}$
                    description: Lowercase hex SHA-256.
                  expiresAt:
                    type: integer
                    description: Unix ms.
                required:
                  - owner
                  - digest
                  - expiresAt
        '400':
          description: Not a preprod address
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.