---
title: "Authenticate wallet session"
method: POST
path: "/v1/wallets/authenticate"
tags: ["Wallets"]
---

# Authenticate wallet session

`POST /v1/wallets/authenticate`

Exchange a user JWT for a session key authorized to act on the user's wallets. Returns the encrypted authorization key and the list of wallets it can access.

## Headers

- `privy-app-id` string, required — ID of your Privy app.

## Request body

- WalletAuthenticateRequestBody — Request body for wallet authentication with HPKE-encrypted response.
  - `encryption_type` 'HPKE', required — The encryption type for the authentication response. Currently only supports HPKE.
  - `recipient_public_key` string, required — The public key of your ECDH keypair, in base64-encoded, SPKI-format, whose private key will be able to decrypt the session key.
  - `user_jwt` string, required — The user's JWT, to be used to authenticate the user.

## Response `200`

Object with authorization key and wallet IDs.

- union — The response from authenticating a wallet, containing an authorization key and wallet data.
  - object — The response from authenticating a wallet with HPKE encryption, containing an encrypted authorization key and wallet data.
    - `encrypted_authorization_key` EncryptedAuthorizationKey, required — HPKE-encrypted authorization key with encapsulated key and ciphertext.
      - `ciphertext` string, required — The encrypted authorization key corresponding to the user's current authentication session.
      - `encapsulated_key` string, required — Base64-encoded ephemeral public key used in the HPKE encryption process. Required for decryption.
      - `encryption_type` 'HPKE', required — The encryption type used. Currently only supports HPKE.
    - `expires_at` number, required — The expiration time of the authorization key in milliseconds since the epoch.
    - `wallets` Wallet[], required
      - `additional_signers` WalletAdditionalSignerItem[], required — Additional signers for the wallet.
        - `override_policy_ids` string[] — An optional list of up to one policy ID to enforce on the wallet.
        - `signer_id` string, cuid2, required — A unique identifier for a key quorum.
      - `address` string, required — Address of the wallet.
      - `archived_at` number, nullable — Unix timestamp of when the wallet was archived in milliseconds, or null if the wallet is active.
      - `authorization_threshold` number — The number of keys that must sign for an action to be valid.
      - `chain_type` 'ethereum' | 'solana' | 'cosmos' | 'stellar' | 'sui' | 'aptos' | 'movement' | 'tron' | 'bitcoin-segwit' | 'bitcoin-taproot' | 'pearl' | 'near' | 'ton' | 'starknet' | 'spark', required — The wallet chain types.
      - `created_at` number, required — Unix timestamp of when the wallet was created in milliseconds.
      - `custody` WalletCustodian — Information about the custodian managing this wallet.
        - `provider` string, required — The custodian responsible for the wallet.
        - `provider_user_id` string, required — The resource ID of the beneficiary of the custodial wallet.
      - `display_name` string — A human-readable label for the wallet.
      - `exported_at` number, nullable, required — Unix timestamp of when the wallet was exported in milliseconds, if the wallet was exported.
      - `external_id` string — A customer-provided identifier for mapping to external systems. Write-once, set only at creation.
      - `id` string, required — Unique ID of the wallet. This will be the primary identifier when using the wallet in the future.
      - `imported_at` number, nullable, required — Unix timestamp of when the wallet was imported in milliseconds, if the wallet was imported.
      - `owner_id` string, cuid2, nullable, required — The key quorum ID of the owner of the wallet.
      - `policy_ids` string[], required — List of policy IDs for policies that are enforced on the wallet.
      - `public_key` string — The compressed, raw public key for the wallet along the chain cryptographic curve.
  - object — The response from authenticating a wallet without encryption, containing a raw authorization key and wallet data.
    - `authorization_key` string, required — The raw authorization key data.
    - `expires_at` number, required — The expiration time of the authorization key in milliseconds since the epoch.
    - `wallets` Wallet[], required
      - `additional_signers` WalletAdditionalSignerItem[], required — Additional signers for the wallet.
        - `override_policy_ids` string[] — An optional list of up to one policy ID to enforce on the wallet.
        - `signer_id` string, cuid2, required — A unique identifier for a key quorum.
      - `address` string, required — Address of the wallet.
      - `archived_at` number, nullable — Unix timestamp of when the wallet was archived in milliseconds, or null if the wallet is active.
      - `authorization_threshold` number — The number of keys that must sign for an action to be valid.
      - `chain_type` 'ethereum' | 'solana' | 'cosmos' | 'stellar' | 'sui' | 'aptos' | 'movement' | 'tron' | 'bitcoin-segwit' | 'bitcoin-taproot' | 'pearl' | 'near' | 'ton' | 'starknet' | 'spark', required — The wallet chain types.
      - `created_at` number, required — Unix timestamp of when the wallet was created in milliseconds.
      - `custody` WalletCustodian — Information about the custodian managing this wallet.
        - `provider` string, required — The custodian responsible for the wallet.
        - `provider_user_id` string, required — The resource ID of the beneficiary of the custodial wallet.
      - `display_name` string — A human-readable label for the wallet.
      - `exported_at` number, nullable, required — Unix timestamp of when the wallet was exported in milliseconds, if the wallet was exported.
      - `external_id` string — A customer-provided identifier for mapping to external systems. Write-once, set only at creation.
      - `id` string, required — Unique ID of the wallet. This will be the primary identifier when using the wallet in the future.
      - `imported_at` number, nullable, required — Unix timestamp of when the wallet was imported in milliseconds, if the wallet was imported.
      - `owner_id` string, cuid2, nullable, required — The key quorum ID of the owner of the wallet.
      - `policy_ids` string[], required — List of policy IDs for policies that are enforced on the wallet.
      - `public_key` string — The compressed, raw public key for the wallet along the chain cryptographic curve.

---

[API](https://skmtc.net/privy-io/apis/privy-api.md) · [All operations](https://skmtc.net/privy-io/apis/privy-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/privy-io/privy-api/revisions/bb2eb34156cc/schema)
