Skip to main content

Authentication

Fiatsend uses wallet-based login (Privy) and issues a session (JWT) for API access.

Flow

  1. User connects wallet
  2. Privy verifies signature and returns session
  3. Backend establishes JWT session (httpOnly)

Headers

  • Authorization: Bearer <token>

Session best practices

  • Short-lived tokens, refresh on activity
  • Use httpOnly, Secure, SameSite cookies