Message
Rules
- The first signed call creates the user.
- Keep the header until
until, then sign again. With Mera’s signing session, this needs no prompt. - An expired, future-dated beyond 7 days, or mismatched session answers 401
session expiredor similar: sign again. - Sessions ride in a header, never a cookie, so CORS allows any origin.
Verified routes
Top-ups and sends also need the account to be verified onchain (isVerified on the credit line), which GET /me returns as verified. Otherwise they answer 400 verify your identity first. See KYC integration.
