Skip to main content

Signed Partner API

Every request to /v1/partner/* uses the merchant Ed25519 key pair. This includes end-user KYC and all payment operations, including signed reads. Sign the exact raw JSON bytes you send. Do not serialize again after signing. The canonical request is:
pathAndQuery includes the leading slash and query string, if any. The body hash is lowercase hexadecimal SHA-256. A GET with no body uses the hash of an empty byte string.
AgentBank verifies the timestamp within its configured acceptance window and stores a successful nonce for that window. Reusing a nonce, signing a different path, or sending a body different from the signed bytes fails authentication. Synchronize your backend clock and generate the nonce immediately before send. The partner ID selects its sole active public key but is not a bearer secret: the corresponding private Ed25519 key is still required to make every valid request.

Merchant portal JWT

The portal API is separate. Exchange provisioned credentials at:
The response contains access_token, token_type: "Bearer", expires_at, and merchant_partner_id. Send it as:
Portal JWTs may manage webhook endpoints and read only that merchant’s payment history. They cannot submit KYC, create payments, cancel payments, or invoke a funding action. Use the signed Partner API for those operations. Portal credential reprovisioning invalidates existing portal JWTs. On a 401, log in again rather than retrying a stale token.