> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agg.market/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> To integrate AGG, start with Quickstart: REST (https://docs.agg.market/quickstart/rest), then Order lifecycle & statuses (https://docs.agg.market/concepts/order-lifecycle).
> Track every trade until it reaches a terminal status. Before retrying a failed or timed-out call, read Errors, retries & idempotency (https://docs.agg.market/concepts/errors).
> The API reference is generated from https://docs.agg.market/openapi/openapi.json.

# Verify sign-in

> Proves identity and returns an access + refresh token pair directly. The body is a union on `kind`:

- **wallet** (default when `kind` is omitted) — verifies a signed SIWE/SIWS `message` and `signature`.
- **`kind: "privy"`** — verifies a Privy-issued ES256 access token against the app's Privy JWKS. Available only when the app's wallet provider is Privy with credentials saved; the token must be issued by that same Privy app. Otherwise, or when the token is expired or invalid, the request is rejected with 401.

Everything after identity is proven is shared across both: principal creation, the early-access gate, user creation, and token issuing.

## Integration guide

* **Before you call:** [Set up your app and request headers](/environments).
* **Workflow:** [Choose a sign-in provider](/recipes/authentication).
* **Next:** [Fund an account and track withdrawals](/concepts/funding).


## OpenAPI

````yaml /openapi/openapi.json post /auth/verify
openapi: 3.0.2
info:
  title: AGG API
  version: 1.0.0
  description: >-
    Prediction market aggregator REST API — authentication, users, venue events,
    venue markets, orderbooks, charts, and execution workflows.
servers:
  - url: https://api.agg.market
    description: Production
security: []
tags:
  - name: Authentication
    description: Sign users in and manage their session tokens.
  - name: Markets
    description: Find events, markets and outcomes to trade.
  - name: Market Data
    description: Live orderbooks, prices, charts and scores for those markets.
  - name: Trading
    description: Quote, place, sign, track and cancel orders.
  - name: Portfolio
    description: A user's orders, positions, balances and activity.
  - name: Funding
    description: Deposit addresses, withdrawals, balance refills and fiat on-ramp.
  - name: Users
    description: The signed-in user's profile, linked accounts, KYC and venue keys.
  - name: Hosted Venue Accounts
    description: Provision, fund and withdraw from venue accounts hosted for the user.
  - name: Webhooks
    description: Configure and operate webhook delivery to your server.
  - name: Partner Admin
    description: Server-side reads across your app's users, orders and analytics.
  - name: Paper Trading
    description: Simulated accounts and orders for testing without real funds.
  - name: News
    description: News feeds linked to markets.
  - name: Correlated Markets
    description: Markets related to a given market and the effect of its resolution.
paths:
  /auth/verify:
    post:
      tags:
        - Authentication
      summary: Verify sign-in
      description: >-
        Proves identity and returns an access + refresh token pair directly. The
        body is a union on `kind`:


        - **wallet** (default when `kind` is omitted) — verifies a signed
        SIWE/SIWS `message` and `signature`.

        - **`kind: "privy"`** — verifies a Privy-issued ES256 access token
        against the app's Privy JWKS. Available only when the app's wallet
        provider is Privy with credentials saved; the token must be issued by
        that same Privy app. Otherwise, or when the token is expired or invalid,
        the request is rejected with 401.


        Everything after identity is proven is shared across both: principal
        creation, the early-access gate, user creation, and token issuing.
      operationId: verify
      requestBody:
        required: true
        content:
          application/json:
            schema:
              anyOf:
                - type: object
                  required:
                    - message
                    - signature
                  properties:
                    kind:
                      type: string
                      enum:
                        - wallet
                    message:
                      type: string
                    signature:
                      type: string
                    earlyAccessCode:
                      type: string
                - type: object
                  required:
                    - kind
                    - privyToken
                  properties:
                    kind:
                      type: string
                      enum:
                        - privy
                    privyToken:
                      minLength: 1
                      type: string
                    earlyAccessCode:
                      type: string
      responses:
        '200':
          description: '200'
          content:
            application/json:
              schema:
                type: object
                required:
                  - accessToken
                  - user
                properties:
                  accessToken:
                    type: string
                  refreshToken:
                    type: string
                  user:
                    type: object
                    required:
                      - id
                    properties:
                      id:
                        type: string
        '400':
          description: '400'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
        '401':
          description: '401'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
        '403':
          description: '403'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
      security:
        - appId: []
components:
  schemas:
    ErrorMessage:
      type: object
      required:
        - message
      properties:
        message:
          type: string
  securitySchemes:
    appId:
      type: apiKey
      in: header
      name: x-app-id
      description: >-
        Your application ID. Required on app-tier and user-tier routes. Omitted
        on routes that authenticate with x-app-api-key only.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.