Skip to main content
POST
private/set_session_key_debug

Body

application/json

Request parameters for registering a scoped session key. Address fields are 0x-prefixed hex strings.

expiry_sec
integer<uint64>
required
Required range: x >= 0
nonce
string
required
offchain_scopes
string[]
required

Off-chain scopes which are validated in backend only

protocol_scopes
string[]
required

Scopes granted to the session key, validated by the protocol. Each is a string like "trade:orderbook:all".

public_session_key
string
required

Session key address being authorized.

signature
string
required

0x-prefixed hex, 65-byte r||s||v.

signature_expiry_sec
integer<uint64>
required
Required range: x >= 0
signer
string
required
wallet
string
required

Wallet the session key is being registered for.

ip_whitelist
string[] | null
label
string | null
subaccount_ids
integer<uint64>[] | null
Required range: x >= 0

Response

Success

Debug-route payload for one rebuilt action: the EIP-712 hashes plus the action input fields.

action_hash
string
required

EIP-712 struct hash of the Action: keccak256(abi.encode(action_typehash, …, encoded_data_hashed, …)).

action_typehash
string
required

ACTION_TYPEHASH — keccak of the Action struct type string; invariant across deployments.

domain_separator
string
required

EIP-712 domain separator of the Matching contract for this deployment.

encoded_data
string
required

ABI-encoded, module-specific action payload (the data bytes), 0x-hex.

encoded_data_hashed
string
required

keccak256(encoded_data) — the value packed into the struct hash.

expected_signer
string
required

The signer the signature is checked against.

input_data
object
required

The rebuilt Action envelope and its decoded module-specific data.

module
string
required

Per-action module contract address bound into the signed struct.

owner
string
required

Wallet that owns the subaccount the action applies to.

typed_data_hash
string
required

Final EIP-712 digest the client signs: keccak256(0x1901 || domain_separator || action_hash).

recovered_signer
string | null

null on the debug routes (no signature is checked there); on a signature-mismatch error this is the address actually recovered.