Skip to content
Logo

Authentication

WickPlay uses Sign-In with Ethereum. The sign-in signature proves wallet control and does not submit a transaction.

1. Request a challenge

POST /api/auth/wallet/challenge
Content-Type: application/json
Origin: https://wickplay.com
{
  "address": "0xWALLET_ADDRESS",
  "chainId": 1
}

Use the chain ID on which the wallet will validate the signature. The response contains the exact SIWE message:

{
  "challengeId": "CHALLENGE_TOKEN",
  "message": "wickplay.com wants you to sign in..."
}

The challenge expires after five minutes.

2. Sign the message

Ask the wallet to sign the returned message exactly. Do not reconstruct or edit it.

3. Verify the signature

POST /api/auth/wallet/verify
Content-Type: application/json
Origin: https://wickplay.com
{
  "challengeId": "CHALLENGE_TOKEN",
  "message": "EXACT_MESSAGE_FROM_CHALLENGE",
  "signature": "0xSIGNATURE"
}

The response sets an HTTP-only wickplay_session cookie and returns the root wallet and WickPlay account:

{
  "session": true,
  "user": {
    "createdAt": 0,
    "id": "wallet:0x...",
    "smartAccount": "0xWICKPLAY_ACCOUNT",
    "wallet": "0xROOT_WALLET"
  }
}

Retain the cookie for later authenticated requests. The session lasts up to 24 hours.

Read or end the session

GET /api/auth/session

The response includes accountDeployed, session, and user. A missing or expired session returns 401 with {"session": false}.

DELETE /api/auth/session
Origin: https://wickplay.com

Check private beta access

Check access after sign-in:

GET /api/beta/access
Cookie: wickplay_session=...

The response includes the SIWE smart-account address. Cache it only for that account. If an invite link contains a signed grant, use POST to verify it:

POST /api/beta/access
Content-Type: application/json
Origin: https://wickplay.com
Cookie: wickplay_session=...
 
{"inviteGrant":"SIGNED_INVITE_GRANT"}

An approved response has the account, allowed: true, and a method of invite, referral, or wickpass. A denied response has the same account, allowed: false, code BETA_ACCESS_REQUIRED, and a user-facing message.

For a referral code in the form WICK-XXXXXXXX, submit the code through the Points API, then check access again.

Do not request the one-click trading authorization until access returns allowed: true. This keeps the wallet flow to one SIWE signature for users who do not yet have access.