Skip to main content
Every signed route takes this header:
Message

Rules

  • The first signed call creates the user.
  • Keep the header until until, then sign again. With Mera’s signing session, this needs no prompt.
  • An expired, future-dated beyond 7 days, or mismatched session answers 401 session expired or similar: sign again.
  • Sessions ride in a header, never a cookie, so CORS allows any origin.

Verified routes

Top-ups and sends also need the account to be verified onchain (isVerified on the credit line), which GET /me returns as verified. Otherwise they answer 400 verify your identity first. See KYC integration.