> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agg.market/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> To integrate AGG, start with Quickstart: REST (https://docs.agg.market/quickstart/rest), then Order lifecycle & statuses (https://docs.agg.market/concepts/order-lifecycle).
> Track every trade until it reaches a terminal status. Before retrying a failed or timed-out call, read Errors, retries & idempotency (https://docs.agg.market/concepts/errors).
> The API reference is generated from https://docs.agg.market/openapi/openapi.json.

# Verify Turnstile token

> Verifies a Cloudflare Turnstile token against the app's linked widget. Intended to be called from **your backend**, not the browser — API keys are secrets and must never ship to the client. Both `x-app-id` and `x-app-api-key` are required; the server rejects the request with `401` if `x-app-id` does not match the app embedded in the API key. Create a key via `POST /apps/:appId/api-keys` (admin JWT required). Returns `{ success: true }` on a valid token or `403` if verification fails. Tokens are single-use (replay-protected).



## OpenAPI

````yaml /openapi/openapi.json post /bot-protection/verify
openapi: 3.0.2
info:
  title: AGG API
  version: 1.0.0
  description: >-
    Prediction market aggregator REST API — authentication, users, venue events,
    venue markets, orderbooks, charts, and execution workflows.
servers:
  - url: https://api.agg.market
    description: Production
security: []
tags:
  - name: Authentication
    description: Sign users in and manage their session tokens.
  - name: Markets
    description: Find events, markets and outcomes to trade.
  - name: Market Data
    description: Live orderbooks, prices, charts and scores for those markets.
  - name: Trading
    description: Quote, place, sign, track and cancel orders.
  - name: Portfolio
    description: A user's orders, positions, balances and activity.
  - name: Funding
    description: Deposit addresses, withdrawals, balance refills and fiat on-ramp.
  - name: Users
    description: The signed-in user's profile, linked accounts, KYC and venue keys.
  - name: Hosted Venue Accounts
    description: Provision, fund and withdraw from venue accounts hosted for the user.
  - name: Webhooks
    description: Configure and operate webhook delivery to your server.
  - name: Partner Admin
    description: Server-side reads across your app's users, orders and analytics.
  - name: Paper Trading
    description: Simulated accounts and orders for testing without real funds.
  - name: News
    description: News feeds linked to markets.
  - name: Correlated Markets
    description: Markets related to a given market and the effect of its resolution.
paths:
  /bot-protection/verify:
    post:
      tags:
        - Authentication
      summary: Verify Turnstile token
      description: >-
        Verifies a Cloudflare Turnstile token against the app's linked widget.
        Intended to be called from **your backend**, not the browser — API keys
        are secrets and must never ship to the client. Both `x-app-id` and
        `x-app-api-key` are required; the server rejects the request with `401`
        if `x-app-id` does not match the app embedded in the API key. Create a
        key via `POST /apps/:appId/api-keys` (admin JWT required). Returns `{
        success: true }` on a valid token or `403` if verification fails. Tokens
        are single-use (replay-protected).
      operationId: botProtectionVerify
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - turnstileToken
              properties:
                turnstileToken:
                  minLength: 1
                  maxLength: 2048
                  type: string
      responses:
        '200':
          description: '200'
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                properties:
                  success:
                    type: boolean
        '400':
          description: '400'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
        '401':
          description: '401'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
        '403':
          description: '403'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
        '429':
          description: '429'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
      security:
        - appApiKey: []
components:
  schemas:
    ErrorMessage:
      type: object
      required:
        - message
      properties:
        message:
          type: string
  securitySchemes:
    appApiKey:
      type: apiKey
      in: header
      name: x-app-api-key
      description: App-scoped API key for programmatic app management.

````