Signed Partner API
Every request to/v1/partner/* uses the merchant Ed25519 key pair. This
includes end-user KYC and all payment operations, including signed reads.
Sign the exact raw JSON bytes you send. Do not serialize again after signing.
The canonical request is:
pathAndQuery includes the leading slash and query string, if any. The body
hash is lowercase hexadecimal SHA-256. A GET with no body uses the hash of an
empty byte string.
Merchant portal JWT
The portal API is separate. Exchange provisioned credentials at:access_token, token_type: "Bearer", expires_at,
and merchant_partner_id. Send it as:
401,
log in again rather than retrying a stale token.
