Skip to content

Authenticate with a Privy bearer token

Gated routes take Authorization: Bearer plus a Privy token; public reads take no header.

Gated routes take Authorization: Bearer <privy-token>. Public routes take no header at all. The token is a Privy access token from a signed-in Monvera session, checked server-side by verifyRequest(). Missing, malformed, or expired, it returns 401 {"error":"Please sign in to continue."}.

There is no API key, no client secret, and no way to mint a token outside a real signed-in account. Every gated route acts for the user that token belongs to.

Sign in at https://monvera.best with email or a social login, then read the access token from the Privy client SDK:

import { usePrivy } from "@privy-io/react-auth";
const { getAccessToken } = usePrivy();
const privyToken = await getAccessToken();

Send it on every gated request:

Terminal window
curl -X POST "https://monvera.best/api/allocate" \
-H "Authorization: Bearer $PRIVY_TOKEN" \
-H "Content-Type: application/json" \
-d '{"goal":"grow my money steadily for five years","amountUsdg":"250"}'

Tokens expire. Refresh through the SDK and resend rather than caching one for a long-running job.

No Authorization header. Rate limited per client IP.

Route Method Notes
/api/market GET Catalog of 95 assets; ?symbol= and ?range=
/api/prices GET Current and historical prices
/api/screener GET The catalog ranked by four price-history metrics
/api/strategies GET Open rule-based strategies with backtests
/api/themes GET One deterministic basket per investing theme
/api/backtest POST Walk-forward backtest for a strategy rule
/api/portfolio GET Positions and value; read by ?address=
/api/transactions GET Settled on-chain trades; read by ?address=
/api/activity GET Activity feed; read by ?address=
/api/vera-record GET Vera’s signed on-chain record; read by ?user=
/.well-known/agent-card.json GET Vera’s discovery document

portfolio, transactions, and activity are public reads keyed by ?address=, so any account address can be inspected without a token — the chain is public either way. backtest is a public POST.

Require Authorization: Bearer <privy-token>. Rate limited per user id.

Route Method Notes
/api/quote POST Firm router quote; taker in the body
/api/allocate POST Goal plus amount into a named draft plan
/api/commit-plan POST Executes the plan and records the risk assessment
/api/pimlico POST Gas-sponsorship relay for the ERC-4337 user operation
/api/watchlist GET / POST The account’s saved assets
/api/alerts GET / POST / DELETE The account’s price alerts
/api/notifications GET / POST The account’s notification feed
/api/autopilot GET / POST / DELETE Create, read, and revoke Autopilot
/api/autopilot/run POST One Autopilot run within existing bounds
/api/autopilot/runs GET History of Autopilot runs

A bearer token authenticates a caller; it does not authorize a spend. The account is a non-custodial Privy embedded wallet the user owns, and moving funds needs their signature on the user operation and token permits. A stolen token can read an account and draft plans. It cannot buy, sell, or withdraw on its own, and no response on any route ever returns a private key, a seed phrase, or a session-signer secret.

/api/cron/autopilot and /api/cron/alerts are gated by an internal cron secret and invoked by Cloudflare Cron. A Privy token will not reach them. Do not build against them.

Requests from restricted regions are blocked in middleware before any account exists, and gated API paths return 451. The exact body and the affected paths are in conventions; the policy itself is in before you invest.

© 2026 Aibora · Documentation interface. Original Monvera materials retain their upstream attribution andMIT license.