Skip to main content
POST
Verify signed challenge and receive tokens

Authorizations

x-api-key
string
header
required

Body

application/json
type
enum<string>
required
Available options:
message
walletPubkey
string
required
signature
string
required

Base58-encoded signature

authMode
enum<string>
default:access_only

Token model. Defaults to the deprecated access_only when omitted. Send access_refresh for refresh tokens.

Available options:
access_only,
access_refresh

Response

Tokens for the requested auth mode. The access_only variant is returned with Deprecation (an RFC 8594 HTTP-date, e.g. Tue, 21 Jul 2026 00:00:00 GMT) and Link (rel="successor-version" naming the absolute refresh URL https://api.jup.ag/trigger/v2/auth/refresh) response headers.

Access token plus rotating refresh token, returned identically by access_refresh verify and by refresh.

authMode
enum<string>
required
Available options:
access_refresh
accessToken
string
required

JWT to send in the Authorization Bearer header. Expires 15 minutes after issue.

refreshToken
string
required

Opaque token used to obtain a new access token. Rotates on every /auth/refresh call.

expiresAt
string<date-time>
required

ISO 8601 timestamp when accessToken expires.

tokenType
enum<string>
required
Available options:
Bearer