> ## Documentation Index
> Fetch the complete documentation index at: https://docs.derive.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# private/set_session_key_debug

> Takes the same params as private/set_session_key and rebuilds the session-key Action without executing anything, returning the EIP-712 encoded_data, encoded_data_hashed, action_hash, typed_data_hash, domain_separator, action_typehash, module, owner and expected_signer, plus the decoded session key, expiry, protocol scopes and subaccounts. Byte-compare these against your local computation to find why a signature is rejected. Requires a logged-in session.



## OpenAPI

````yaml /openapi.json post /private/set_session_key_debug
openapi: 3.1.0
info:
  title: Derive v3 API
  version: 0.2.0
  description: JSON-RPC 2.0 methods, served over WebSocket and HTTP POST.
servers:
  - url: https://api.derive.xyz/v3
    description: Production (HTTP POST base)
  - url: https://testnet.api.derive.xyz/v3
    description: Testnet (HTTP POST base)
security: []
tags:
  - name: Subaccounts
    description: >-
      List, inspect, and label subaccounts, portfolios, positions, and
      collateral.
  - name: Session Keys
    description: Register, edit, and list delegated signing keys.
  - name: Account
    description: Wallet-level account information and settings.
  - name: Orderbook
    description: Place, replace, cancel, and query orders, trigger orders, and algos.
  - name: RFQ
    description: 'Request-for-quote: send RFQs, quote, and execute block trades.'
  - name: Liquidations
    description: >-
      Open a Dutch auction against a breaching subaccount, quote the auctions
      running right now, bid on them, and review past ones.
  - name: Vault Shareholders
    description: >-
      Deposit into and withdraw from vaults, and track shares, requests, and
      performance.
  - name: Vault Curators
    description: >-
      Create and operate curated vaults: settle deposit and withdrawal requests,
      and manage vault metadata.
  - name: History
    description: >-
      Per-account historical records: orders, trades, transfers, and
      settlements.
  - name: Market Maker Protection
    description: Configure, read, and reset market-maker protection.
  - name: Transfers & Withdrawals
    description: Move collateral between subaccounts, to other wallets, and on-chain.
  - name: Onchain Actions
    description: >-
      L1 onchain actions submitted via OnchainActionManager: register deposit
      addresses, list pending deposits, and inspect onchain action history.
  - name: System
    description: Rate limits and transaction lookups.
  - name: Market Data
    description: Instruments, currencies, tickers, and market-wide feeds.
  - name: Maker Scoring
    description: Maker programs, score breakdowns, and detailed scoring snapshots.
  - name: Referrals
    description: Referral codes and program performance.
  - name: Other
    description: Uncategorized.
paths:
  /private/set_session_key_debug:
    post:
      tags:
        - Session Keys
      summary: private/set_session_key_debug
      description: >-
        Takes the same params as private/set_session_key and rebuilds the
        session-key Action without executing anything, returning the EIP-712
        encoded_data, encoded_data_hashed, action_hash, typed_data_hash,
        domain_separator, action_typehash, module, owner and expected_signer,
        plus the decoded session key, expiry, protocol scopes and subaccounts.
        Byte-compare these against your local computation to find why a
        signature is rejected. Requires a logged-in session.
      operationId: private_set_session_key_debug
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SetSessionKeyRequest'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SetSessionKeyDebugResponse'
        default:
          description: JSON-RPC error (see Error Codes)
components:
  schemas:
    SetSessionKeyRequest:
      description: >-
        Request parameters for registering a scoped session key. Address fields
        are 0x-prefixed hex strings.
      type: object
      required:
        - expiry_sec
        - nonce
        - offchain_scopes
        - protocol_scopes
        - public_session_key
        - signature
        - signature_expiry_sec
        - signer
        - wallet
      properties:
        expiry_sec:
          type: integer
          format: uint64
          minimum: 0
        ip_whitelist:
          type:
            - array
            - 'null'
          items:
            type: string
        label:
          type:
            - string
            - 'null'
        nonce:
          type: string
        offchain_scopes:
          description: Off-chain scopes which are validated in backend only
          type: array
          items:
            type: string
        protocol_scopes:
          description: >-
            Scopes granted to the session key, validated by the protocol. Each
            is a string like `"trade:orderbook:all"`.
          type: array
          items:
            type: string
        public_session_key:
          description: Session key address being authorized.
          type: string
        signature:
          description: 0x-prefixed hex, 65-byte r||s||v.
          type: string
        signature_expiry_sec:
          type: integer
          format: uint64
          minimum: 0
        signer:
          type: string
        subaccount_ids:
          type:
            - array
            - 'null'
          items:
            type: integer
            format: uint64
            minimum: 0
        wallet:
          description: Wallet the session key is being registered for.
          type: string
    SetSessionKeyDebugResponse:
      description: >-
        Debug-route payload for one rebuilt action: the EIP-712 hashes plus the
        action input fields.
      type: object
      required:
        - action_hash
        - action_typehash
        - domain_separator
        - encoded_data
        - encoded_data_hashed
        - expected_signer
        - input_data
        - module
        - owner
        - typed_data_hash
      properties:
        action_hash:
          description: >-
            EIP-712 struct hash of the `Action`:
            `keccak256(abi.encode(action_typehash, …, encoded_data_hashed, …))`.
          type: string
        action_typehash:
          description: >-
            `ACTION_TYPEHASH` — keccak of the `Action` struct type string;
            invariant across deployments.
          type: string
        domain_separator:
          description: >-
            EIP-712 domain separator of the Matching contract for this
            deployment.
          type: string
        encoded_data:
          description: >-
            ABI-encoded, module-specific action payload (the `data` bytes),
            0x-hex.
          type: string
        encoded_data_hashed:
          description: '`keccak256(encoded_data)` — the value packed into the struct hash.'
          type: string
        expected_signer:
          description: The signer the signature is checked against.
          type: string
        input_data:
          $ref: '#/components/schemas/SetSessionKeyActionInputData'
          description: >-
            The rebuilt `Action` envelope and its decoded module-specific
            `data`.
        module:
          description: Per-action module contract address bound into the signed struct.
          type: string
        owner:
          description: Wallet that owns the subaccount the action applies to.
          type: string
        recovered_signer:
          description: >-
            null on the debug routes (no signature is checked there); on a
            signature-mismatch error this is the address actually recovered.
          type:
            - string
            - 'null'
        typed_data_hash:
          description: >-
            Final EIP-712 digest the client signs: `keccak256(0x1901 ||
            domain_separator || action_hash)`.
          type: string
    SetSessionKeyActionInputData:
      description: >-
        The `Action` envelope a debug route rebuilt from the request inputs,
        plus its decoded action data — i.e. what the signature commits to.
      type: object
      required:
        - data
        - expiry
        - module
        - nonce
        - owner
        - signer
        - subaccount_id
      properties:
        data:
          $ref: '#/components/schemas/SetSessionKeyActionDataResponse'
        expiry:
          type: integer
          format: uint64
          minimum: 0
        module:
          type: string
        nonce:
          type: string
        owner:
          type: string
        signer:
          type: string
        subaccount_id:
          type: integer
          format: uint64
          minimum: 0
    SetSessionKeyActionDataResponse:
      type: object
      required:
        - expiry_sec
        - scopes
        - session_key
        - subaccounts
      properties:
        expiry_sec:
          type: integer
          format: uint64
          minimum: 0
        scopes:
          description: Protocol scope wire strings (e.g. `"trade:orderbook:all"`).
          type: array
          items:
            type: string
        session_key:
          type: string
        subaccounts:
          type: array
          items:
            type: integer
            format: uint64
            minimum: 0

````

## Related topics

- [Changelog](/changelog.md)
- [private/set_session_key](/api-reference/session-keys/privateset_session_key.md)
- [private/edit_session_key](/api-reference/session-keys/privateedit_session_key.md)
