> ## Documentation Index
> Fetch the complete documentation index at: https://shield.fi/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify a wallet signature

> Verify the signed challenge and establish the browser session cookies.



## OpenAPI

````yaml openapi.json POST /auth/verify
openapi: 3.1.0
info:
  title: Shield Swap API
  description: >-
    Shield Swap REST API for pools, positions, swaps, routes, quotes, settlement
    status, and transaction input schemas. Transactions target the configured
    shield_swap program and `token_registry.aleo`.


    ## Numeric wire format


    Exact financial values are JSON strings, not JSON numbers. Unsigned decimal
    inputs use ASCII digits and an optional `.` fraction, for example
    `"1234.50"`; base-unit integers use ASCII digits only. Grouping separators,
    localized decimal commas, signs, exponent notation, whitespace, Unicode
    digits, and redundant leading zeros are not accepted for those inputs.
    Signed response metrics may include a leading `-`. Clients should localize
    only for display and convert user input back to this canonical form before
    sending it.


    ## Authentication


    Most endpoints require credentials from an invited wallet. Public routes are
    `/health`, `/ready`, `/metrics`, `/auth/*`, `/protocol/state`,
    `/compliance*`, `GET /tokens*`, `GET /pools`, `GET /pools/stats`, and `GET
    /pools/{key}`.


    Browsers use HTTP-only session cookies issued by `/auth/verify`. Access
    sessions last 15 minutes and are renewed through `/auth/refresh`.
    Programmatic clients use a long-lived token from `POST /api-tokens` as
    `Authorization: Bearer ss_…`. API tokens cover data and trading routes and
    can request WebSocket tickets. Token management, code redemption, and admin
    routes require a browser session.


    ## WebSocket feed


    The live feed runs on the separate websocket gateway at `GET /ws`.


    1. Request a ticket from `GET /auth/ws-ticket` using a browser session or
    API token.

    2. Open the socket and send the `authenticate` frame within 5 seconds.

    3. Subscribe to each required room.

    4. Before the 60-second ticket expires, request a new ticket and send
    another `authenticate` frame.


    The socket accepts WebSocket tickets only. Session JWTs and API tokens are
    rejected.


    ```json

    {"action": "authenticate", "token": "<ticket from /auth/ws-ticket>"}

    {"action": "subscribe", "room": "trades:<pool_key>"}

    {"action": "unsubscribe", "room": "<room>"}

    {"action": "synchronize"}

    ```


    After reconnecting, resend subscriptions and then send `synchronize`. The
    gateway replies `{"control": "synchronized"}` when those subscriptions are
    active. Refetch any REST data that depends on the stream after receiving the
    reply.


    Each connection allows 32 rooms, 240 client frames per minute, and 2 KB per
    frame. A client may subscribe only to the balance room for its ticket
    subject.


    Rooms:

    - `pool_launches`: newly created pools

    - `pool_stats:<pool_key>`: price & liquidity updates

    - `ohlcv:<pool_key>`: candle updates

    - `trades:<pool_key>`: swaps / mints / burns

    - `balances:<address>`: balance-change hints for an address


    - `protocol_config`: revisioned protocol-configuration invalidations


    Server messages are either events (`{"type": <event>, "data": { … }}`) or
    control messages (`{"control": <value>}`). Event types are `PoolLaunch`,
    `PoolStats`, `Ohlcv`, `Trade`, `BalanceChange`, and `ProtocolConfigChanged`.
    Its data contains `revision`, `observed_block`, and the changed
    `scope`/`key` pairs. Financial fields use the numeric format described
    above.


    Treat `ProtocolConfigChanged` as an invalidation, not as the new
    configuration. Fetch `GET /protocol/state?minimum_revision=<revision>`;
    retry a `503 protocol_revision_pending` after the advertised `Retry-After`;
    and discard or requote any `/route` result whose `protocol_revision` is
    older. Subscribe to `pool_stats:<pool_key>` separately when live price and
    liquidity updates matter.


    The gateway currently sends `synchronized` and `resync_required` controls.
    `resync_required` means the stream may have missed updates, so refetch
    affected data over REST. Ignore unknown control values.


    Event delivery is at most once. Treat REST as the source of truth. During a
    deployment the gateway may close the socket with code 1012 (service
    restart); reconnect and restore the subscriptions.
  contact:
    name: Shield Swap
  license:
    name: ''
  version: 0.1.0
servers:
  - url: https://api.swap.shield.fi
    description: Shield Swap mainnet API
security: []
tags:
  - name: schema
    description: On-chain function input schemas for trading / liquidity / token operations
  - name: auth
    description: Wallet sign-in, sessions, logout, and WebSocket tickets
  - name: access
    description: Invite access redemption and administration
  - name: api-tokens
    description: >-
      Long-lived API tokens for programmatic access; send as `Authorization:
      Bearer ss_…` on any gated endpoint
  - name: referral
    description: Referral redemption and administration
  - name: pools
    description: Pool metadata, stats, trades, OHLCV
  - name: positions
    description: LP positions
  - name: swaps
    description: Historical swaps
  - name: tokens
    description: Token registry
  - name: balances
    description: On-chain token balances
  - name: compliance
    description: Token/pair allowlist, pause, and pool-creation gating state
  - name: protocol
    description: Fee tiers and tick spacings
  - name: route
    description: Swap routing
  - name: debug
    description: On-chain introspection helpers
  - name: airdrop
    description: >-
      Faucet: sends ALEO, USDCx, and ETH to a user address as records, once per
      address per 15 min
  - name: unclaimed
    description: Pending swap outputs and position fees
paths:
  /auth/verify:
    post:
      tags:
        - auth
      summary: Verify a wallet signature
      operationId: verify
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/VerifyRequestDoc'
        required: true
      responses:
        '200':
          description: >-
            Session established via httpOnly cookies; body carries the CSRF
            token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SessionResponseDoc'
        '400':
          description: Malformed JSON
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '401':
          description: Invalid / expired signature
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '409':
          description: Session state changed during verification
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '413':
          description: Request body too large
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '415':
          description: JSON content type required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '422':
          description: Request body schema mismatch
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '429':
          description: Rate limit exceeded
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
        '500':
          description: Internal error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDoc'
components:
  schemas:
    VerifyRequestDoc:
      type: object
      required:
        - address
        - signature
        - challenge_id
      properties:
        address:
          type: string
        challenge_id:
          type: string
        signature:
          type: string
    SessionResponseDoc:
      type: object
      required:
        - data
      properties:
        data:
          $ref: '#/components/schemas/SessionPayload'
    ErrorResponseDoc:
      type: object
      required:
        - error
      properties:
        error:
          type: string
        ref:
          type:
            - string
            - 'null'
    SessionPayload:
      type: object
      description: >-
        Session identity returned on verify/refresh/session. The access +
        refresh

        tokens are set as httpOnly cookies (not in the body); `csrf_token` is
        held in

        memory by the SPA and echoed in the `X-CSRF-Token` header.
      required:
        - address
        - expires_at
        - csrf_token
        - session_version
      properties:
        address:
          type: string
        csrf_token:
          type: string
        expires_at:
          type: integer
          format: int64
        session_id:
          type:
            - string
            - 'null'
          format: uuid
        session_version:
          type: integer
          format: int64

````