A valid request URL is required to generate request examples{
"accessToken": "<jwt>",
"user": {
"id": "018f9a2b-7c3d-7e10-9a4b-2c1d5e6f7a8b",
"abstractAccountAddress": "0x…"
}
}{
"code": "INVALID_PARAMETER",
"message": "scope is required"
}{
"code": "INVALID_TOKEN",
"message": "Unknown agent API key"
}{
"code": "AGENT_KEYS_DISABLED",
"message": "Agent keys are not enabled for this partner"
}Create an agent session
Issues a 15-minute access token (type=agent) with no refresh token.
Create one per operation.
Identify the agent with exactly one of the x-agent-api-key header or
the body signedMessage. API-key-only agents must use the header.
signedMessage requires a public key stored at bind time.
The requested scope must be a subset of the bound key’s scopes; omit it
to receive the full bound set. Tokens issued before a key rotation fail.
A valid request URL is required to generate request examples{
"accessToken": "<jwt>",
"user": {
"id": "018f9a2b-7c3d-7e10-9a4b-2c1d5e6f7a8b",
"abstractAccountAddress": "0x…"
}
}{
"code": "INVALID_PARAMETER",
"message": "scope is required"
}{
"code": "INVALID_TOKEN",
"message": "Unknown agent API key"
}{
"code": "AGENT_KEYS_DISABLED",
"message": "Agent keys are not enabled for this partner"
}Headers
Your Partner ID (UUID) from the Developer Dashboard.
Opaque API key returned once at bind or rotate. Mutually exclusive with body
signedMessage. Required for API-key-only agents.
"air_ag_…"
Body
Space-delimited scopes for the agent JWT. Must be a subset of the bound key's scopes. Omit to use the full bound set.
"openid credentials.read credentials.verify"
Mutually exclusive with x-agent-api-key. The bound key must have a
stored public key.
Show child attributes
Show child attributes
Was this page helpful?