Authentication
WickPlay uses Sign-In with Ethereum. The sign-in signature proves wallet control and does not submit a transaction.
1. Request a challenge
POST /api/auth/wallet/challenge
Content-Type: application/json
Origin: https://wickplay.com{
"address": "0xWALLET_ADDRESS",
"chainId": 1
}Use the chain ID on which the wallet will validate the signature. The response contains the exact SIWE message:
{
"challengeId": "CHALLENGE_TOKEN",
"message": "wickplay.com wants you to sign in..."
}The challenge expires after five minutes.
2. Sign the message
Ask the wallet to sign the returned message exactly. Do not reconstruct or edit it.
3. Verify the signature
POST /api/auth/wallet/verify
Content-Type: application/json
Origin: https://wickplay.com{
"challengeId": "CHALLENGE_TOKEN",
"message": "EXACT_MESSAGE_FROM_CHALLENGE",
"signature": "0xSIGNATURE"
}The response sets an HTTP-only wickplay_session cookie and returns the root wallet and WickPlay
account:
{
"session": true,
"user": {
"createdAt": 0,
"id": "wallet:0x...",
"smartAccount": "0xWICKPLAY_ACCOUNT",
"wallet": "0xROOT_WALLET"
}
}Retain the cookie for later authenticated requests. The session lasts up to 24 hours.
Read or end the session
GET /api/auth/sessionThe response includes accountDeployed, session, and user. A missing or expired session returns
401 with {"session": false}.
DELETE /api/auth/session
Origin: https://wickplay.comCheck private beta access
Check access after sign-in:
GET /api/beta/access
Cookie: wickplay_session=...The response includes the SIWE smart-account address. Cache it only for that account. If an invite
link contains a signed grant, use POST to verify it:
POST /api/beta/access
Content-Type: application/json
Origin: https://wickplay.com
Cookie: wickplay_session=...
{"inviteGrant":"SIGNED_INVITE_GRANT"}An approved response has the account, allowed: true, and a method of invite, referral, or
wickpass. A denied response has the same account, allowed: false, code
BETA_ACCESS_REQUIRED, and a user-facing message.
For a referral code in the form WICK-XXXXXXXX, submit the code through the
Points API, then check access again.
Do not request the one-click trading authorization until access returns allowed: true. This keeps
the wallet flow to one SIWE signature for users who do not yet have access.