Authenticate with a Privy bearer token
Gated routes take Authorization: Bearer plus a Privy token; public reads take no header.
Gated routes take Authorization: Bearer <privy-token>. Public routes take no header at all. The token is a Privy access token from a signed-in Monvera session, checked server-side by verifyRequest(). Missing, malformed, or expired, it returns 401 {"error":"Please sign in to continue."}.
There is no API key, no client secret, and no way to mint a token outside a real signed-in account. Every gated route acts for the user that token belongs to.
Get a token
Section titled “Get a token”Sign in at https://monvera.best with email or a social login, then read the access token from the Privy client SDK:
import { usePrivy } from "@privy-io/react-auth";
const { getAccessToken } = usePrivy();const privyToken = await getAccessToken();Send it on every gated request:
curl -X POST "https://monvera.best/api/allocate" \ -H "Authorization: Bearer $PRIVY_TOKEN" \ -H "Content-Type: application/json" \ -d '{"goal":"grow my money steadily for five years","amountUsdg":"250"}'Tokens expire. Refresh through the SDK and resend rather than caching one for a long-running job.
Public routes
Section titled “Public routes”No Authorization header. Rate limited per client IP.
| Route | Method | Notes |
|---|---|---|
/api/market |
GET | Catalog of 95 assets; ?symbol= and ?range= |
/api/prices |
GET | Current and historical prices |
/api/screener |
GET | The catalog ranked by four price-history metrics |
/api/strategies |
GET | Open rule-based strategies with backtests |
/api/themes |
GET | One deterministic basket per investing theme |
/api/backtest |
POST | Walk-forward backtest for a strategy rule |
/api/portfolio |
GET | Positions and value; read by ?address= |
/api/transactions |
GET | Settled on-chain trades; read by ?address= |
/api/activity |
GET | Activity feed; read by ?address= |
/api/vera-record |
GET | Vera’s signed on-chain record; read by ?user= |
/.well-known/agent-card.json |
GET | Vera’s discovery document |
portfolio, transactions, and activity are public reads keyed by ?address=, so any account address can be inspected without a token — the chain is public either way. backtest is a public POST.
Token-gated routes
Section titled “Token-gated routes”Require Authorization: Bearer <privy-token>. Rate limited per user id.
| Route | Method | Notes |
|---|---|---|
/api/quote |
POST | Firm router quote; taker in the body |
/api/allocate |
POST | Goal plus amount into a named draft plan |
/api/commit-plan |
POST | Executes the plan and records the risk assessment |
/api/pimlico |
POST | Gas-sponsorship relay for the ERC-4337 user operation |
/api/watchlist |
GET / POST | The account’s saved assets |
/api/alerts |
GET / POST / DELETE | The account’s price alerts |
/api/notifications |
GET / POST | The account’s notification feed |
/api/autopilot |
GET / POST / DELETE | Create, read, and revoke Autopilot |
/api/autopilot/run |
POST | One Autopilot run within existing bounds |
/api/autopilot/runs |
GET | History of Autopilot runs |
What a token cannot do
Section titled “What a token cannot do”A bearer token authenticates a caller; it does not authorize a spend. The account is a non-custodial Privy embedded wallet the user owns, and moving funds needs their signature on the user operation and token permits. A stolen token can read an account and draft plans. It cannot buy, sell, or withdraw on its own, and no response on any route ever returns a private key, a seed phrase, or a session-signer secret.
Routes you cannot call
Section titled “Routes you cannot call”/api/cron/autopilot and /api/cron/alerts are gated by an internal cron secret and invoked by Cloudflare Cron. A Privy token will not reach them. Do not build against them.
Requests from restricted regions are blocked in middleware before any account exists, and gated API paths return 451. The exact body and the affected paths are in conventions; the policy itself is in before you invest.
© 2026 Aibora · Documentation interface. Original Monvera materials retain their upstream attribution andMIT license.