Skip to content
LogoLogo

Authentication

All protected MPP endpoints (/agent/*) use wallet-based authentication. No API keys or OAuth tokens - you sign a message with your EVM private key.

Auth Headers

Every request to a protected endpoint must include these headers:

HeaderDescription
X-Wallet-AddressYour EVM wallet address (0x...)
X-SignatureEIP-191 signature of the message below
X-TimestampUnix timestamp in milliseconds
X-NonceA unique UUID per request

Message Format

The signed message is a colon-separated string:

{wallet}:{timestamp}:{nonce}

Example:

0x5B6C...a3F2:1711500000000:550e8400-e29b-41d4-a716-446655440000

Generating Auth Headers

Using viem:

import { privateKeyToAccount } from "viem/accounts";
import { randomUUID } from "crypto";
 
const account = privateKeyToAccount("0xYOUR_PRIVATE_KEY");
 
const getAuthHeaders = async () => {
  const nonce = randomUUID();
  const timestamp = String(Date.now());
  const message = `${account.address}:${timestamp}:${nonce}`;
  const signature = await account.signMessage({ message });
 
  return {
    "X-Wallet-Address": account.address,
    "X-Signature": signature,
    "X-Timestamp": timestamp,
    "X-Nonce": nonce,
  };
};

Validation Rules

  • Timestamp must be within 60 seconds of the server's clock
  • Nonce must be unique - each nonce can only be used once
  • Signature is verified using EIP-191 personal_sign via the wallet address

If any check fails, the endpoint returns 401.

Public Endpoints

These endpoints do not require authentication:

EndpointDescription
GET /agent/balance/:addressCheck token balances on-chain
GET /agent/chainsList supported chains & tokens
GET /healthGateway health check