/me…) and creating a listing need a session. A session comes from a Cardano wallet signing a one-time challenge (CIP-30 signData, checked as a CIP-8 signature).
Sign in
owneris the bech32 address (addr_test1…) the account belongs to.- The challenge is valid for 5 minutes and can be used once.
- The wallet signs
sha256("simpuru:signin:v1\n" + owner + "\n" + nonce); the API hands you that digest. account.walletAddressis the account’s Simpuru wallet.
Use the session
Send it as a Bearer token:POST /auth/logout ends it. Any 401 means the session is gone: sign in again.
Signed requests without a session
Scripts that hold a wallet key can sign a single request instead, in anX-Simpuru-Proof header: base64 JSON { address, timestamp, key, signature }, at most 5 minutes old. Two requests accept it:
The hosted MCP server has its own OAuth 2.1 sign-in, also approved with a wallet. See MCP.