> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agg.market/llms.txt
> Use this file to discover all available pages before exploring further.

# Link partner external user ID (HMAC-verified)

> Verifies a partner-signed external user ID assertion and stores the linked external ID on the current user.



## OpenAPI

````yaml /openapi/openapi.json post /users/me/external-id
openapi: 3.0.2
info:
  title: AGG API
  version: 1.0.0
  description: >-
    Prediction market aggregator REST API — authentication, users, venue events,
    venue markets, orderbooks, charts, and execution workflows.
servers:
  - url: https://api.agg.market
    description: Production
  - url: https://api.staging.agg.market
    description: Staging
security: []
paths:
  /users/me/external-id:
    post:
      tags:
        - Users
      summary: Link partner external user ID (HMAC-verified)
      description: >-
        Verifies a partner-signed external user ID assertion and stores the
        linked external ID on the current user.
      operationId: linkExternalId
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - externalId
                - timestamp
                - hmac
              properties:
                externalId:
                  minLength: 1
                  maxLength: 255
                  type: string
                timestamp:
                  minimum: 1
                  type: integer
                hmac:
                  pattern: ^[a-fA-F0-9]{64}$
                  type: string
      responses:
        '200':
          description: '200'
          content:
            application/json:
              schema:
                type: object
                required:
                  - id
                  - username
                  - avatarUrl
                  - externalId
                  - isLocationBlocked
                  - accounts
                  - wallets
                  - venueAccounts
                properties:
                  id:
                    type: string
                  username:
                    type: string
                    nullable: true
                  avatarUrl:
                    type: string
                    nullable: true
                  externalId:
                    type: string
                    nullable: true
                  isLocationBlocked:
                    type: boolean
                  accounts:
                    type: array
                    items:
                      type: object
                      required:
                        - type
                        - provider
                        - providerAccountId
                      properties:
                        type:
                          type: string
                          enum:
                            - oauth
                            - siwe
                            - siws
                            - email
                        provider:
                          type: string
                          enum:
                            - wallet
                            - solana_wallet
                            - google
                            - twitter
                            - apple
                            - email
                        providerAccountId:
                          type: string
                  wallets:
                    type: array
                    items:
                      type: object
                      required:
                        - chain
                        - address
                      properties:
                        chain:
                          type: string
                          enum:
                            - evm
                            - svm
                        address:
                          type: string
                  venueAccounts:
                    type: array
                    items:
                      type: object
                      required:
                        - id
                        - venue
                        - status
                        - kycStatus
                      properties:
                        id:
                          type: string
                        venue:
                          type: string
                          enum:
                            - kalshi
                            - polymarket
                            - limitless
                            - opinion
                            - predict
                            - probable
                            - myriad
                            - hyperliquid
                        status:
                          type: string
                        kycStatus:
                          type: string
                    nullable: true
        '400':
          description: '400'
          content:
            application/json:
              schema:
                type: object
                required:
                  - message
                properties:
                  message:
                    type: string
        '401':
          description: '401'
          content:
            application/json:
              schema:
                type: object
                required:
                  - message
                properties:
                  message:
                    type: string
        '409':
          description: '409'
          content:
            application/json:
              schema:
                type: object
                required:
                  - message
                properties:
                  message:
                    type: string
      security:
        - appId: []
          bearerAuth: []
components:
  securitySchemes:
    appId:
      type: apiKey
      in: header
      name: x-app-id
      description: Your application ID. Required for all app-tier and user-tier routes.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        JWT access token returned by POST /auth/verify. Required for user-tier
        routes.

````