Skip to main content
Account routes (/me…) and creating a listing need a session. A session comes from a Cardano wallet signing a one-time challenge (CIP-30 signData, checked as a CIP-8 signature).

Sign in

  • owner is the bech32 address (addr_test1…) the account belongs to.
  • The challenge is valid for 5 minutes and can be used once.
  • The wallet signs sha256("simpuru:signin:v1\n" + owner + "\n" + nonce); the API hands you that digest.
  • account.walletAddress is the account’s Simpuru wallet.

Use the session

Send it as a Bearer token:
A session lasts 7 days. POST /auth/logout ends it. Any 401 means the session is gone: sign in again.

Signed requests without a session

Scripts that hold a wallet key can sign a single request instead, in an X-Simpuru-Proof header: base64 JSON { address, timestamp, key, signature }, at most 5 minutes old. Two requests accept it: The hosted MCP server has its own OAuth 2.1 sign-in, also approved with a wallet. See MCP.