> ## Documentation Index
> Fetch the complete documentation index at: https://hevninc.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> HEVN has two products and they authorize money differently. Self-serve (the General tab): the person who owns the email holds the only key and signs for themselves. Whitelabel (the Whitelabel and REST API tabs): the integrator's backend holds a developer key, signs on behalf of client accounts it created, and HEVN co-signs. Never mix the two models in an answer.
> Use HEVN's terms exactly. A rail is a bank route a client can request. A virtual account (bnk_) is an opened rail. Account details are what a payer needs in order to wire money, and arrive in a field named requisites. A client is an account the integrator created; the business behind it is the integrator's customer. A contact is a saved destination; a beneficiary is the party at the far end of a fiat payout. Every departure of money is a payout, to a bank account or to a wallet alike.
> Never name a banking partner. Say 'a licensed banking partner'.
> There are no published fee rates, spreads or minimums. Prices come from a quote on a specific payment; direct pricing questions to HEVN rather than inventing numbers.
> The whitelabel API is at /dapi/v1 and takes a developer-key session plus an X-Hevn-Account header. The CLI uses an app API key in X-Api-Key. They are different credentials and neither works on the other surface.

# Exchange a signed login challenge for a session

> Exchange a signed, unexpired challenge for an access token and refresh token. A challenge is consumed once; replay, a different key or a different account is refused.



## OpenAPI

````yaml /openapi.json post /auth/token
openapi: 3.1.0
info:
  title: HEVN Platform API
  description: >-
    HEVN's account, verification and money-movement API. Verification follows a
    submission workflow: save applicant info and documents, inspect outstanding
    requirements, then explicitly complete the submission to send an immutable
    snapshot for review. Completing a submission is separate from editing it.
  version: 1.0.0
servers: []
security: []
tags:
  - name: auth
    description: Authenticate an integration and issue short-lived account sessions.
  - name: accounts
    description: Create and manage business or individual customer accounts.
  - name: verification
    description: >-
      Collect business-applicant and related-individual information, inspect
      requirements, and complete a verification submission for review.
  - name: documents
    description: Upload verification and payment evidence for later reference by id.
  - name: virtual accounts
    description: Discover payment methods and create persistent receiving account details.
  - name: transfers
    description: Quote, create, authorize and track incoming or outgoing transfers.
  - name: contacts
    description: Create saved contacts and inspect their available payment channels.
  - name: transactions
    description: Read and export the account ledger.
  - name: escrow
    description: Create, authorize and reconcile on-chain escrow agreements.
  - name: sandbox
    description: Emulate funding and lifecycle events in the sandbox environment.
paths:
  /auth/token:
    post:
      tags:
        - auth
      summary: Exchange a signed login challenge for a session
      description: >-
        Exchange a signed, unexpired challenge for an access token and refresh
        token. A challenge is consumed once; replay, a different key or a
        different account is refused.
      operationId: mint_token_auth_token_post
      parameters:
        - name: device-id
          in: header
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: Device-Id
        - name: x-api-key
          in: header
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: X-Api-Key
        - name: user-agent
          in: header
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: User-Agent
      requestBody:
        required: true
        content:
          application/json:
            schema:
              anyOf:
                - $ref: '#/components/schemas/ChallengeTokenRequest'
                - $ref: '#/components/schemas/ProofTokenRequest'
              title: Data
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TokenResponse'
        '422':
          description: Request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformErrorResponse'
      security:
        - HTTPBearer: []
components:
  schemas:
    ChallengeTokenRequest:
      properties:
        challengeId:
          type: string
          format: uuid
          title: Challengeid
          description: >-
            Single-use challenge identifier returned by POST
            /dapi/v1/auth/challenge.
        signature:
          type: string
          title: Signature
          description: Signature over the decoded payload returned for this challenge.
        publicKey:
          anyOf:
            - type: string
            - type: 'null'
          title: Publickey
          description: >-
            Registered P-256 public key; omit when the signature uniquely
            identifies the key.
      additionalProperties: false
      type: object
      required:
        - challengeId
        - signature
      title: ChallengeTokenRequest
    ProofTokenRequest:
      properties:
        email:
          type: string
          format: email
          title: Email
          description: Email address of the account that owns the registered developer key.
        publicKey:
          type: string
          title: Publickey
          description: >-
            Base64 DER SubjectPublicKeyInfo for the registered P-256 developer
            key.
        nonce:
          type: integer
          title: Nonce
          description: >-
            Caller-generated single-use number included in the signed
            authentication proof.
        requestExpiry:
          type: integer
          title: Requestexpiry
          description: Unix time in milliseconds after which the signed request is refused.
        signature:
          type: string
          title: Signature
          description: >-
            Base64 DER ECDSA P-256/SHA-256 signature over the login proof
            message.
      additionalProperties: false
      type: object
      required:
        - email
        - publicKey
        - nonce
        - requestExpiry
        - signature
      title: ProofTokenRequest
    TokenResponse:
      properties:
        accessToken:
          type: string
          title: Accesstoken
          description: Short-lived bearer token used to authorize API requests.
        refreshToken:
          type: string
          title: Refreshtoken
          description: >-
            Long-lived device-bound token used only at POST
            /dapi/v1/auth/refresh.
        expiresIn:
          type: integer
          title: Expiresin
          description: Number of seconds until the access token expires.
        userId:
          type: string
          pattern: ^(?:cl_)?[A-Za-z0-9._:\-]{1,216}$
          title: Userid
          description: Account selected for the issued session.
          examples:
            - cl_9f2c1ab84d7e4f1fa3c65b0e7d9a2c41
      type: object
      required:
        - accessToken
        - refreshToken
        - expiresIn
        - userId
      title: TokenResponse
    PlatformErrorResponse:
      properties:
        error:
          $ref: '#/components/schemas/PlatformErrorBody'
          description: Public error body.
      type: object
      required:
        - error
      title: PlatformErrorResponse
    PlatformErrorBody:
      properties:
        code:
          $ref: '#/components/schemas/PlatformErrorCode'
          description: Stable machine-readable error code.
        message:
          type: string
          title: Message
          description: Human-readable explanation safe to show to an end user.
        details:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Details
          description: Structured context for this error, when available.
      type: object
      required:
        - code
        - message
      title: PlatformErrorBody
    PlatformErrorCode:
      type: string
      enum:
        - invalid_request
        - validation_failed
        - invalid_cursor
        - invalid_id
        - idempotency_key_invalid
        - idempotency_key_reused
        - unauthenticated
        - token_expired
        - forbidden
        - not_found
        - method_not_allowed
        - conflict
        - gone
        - payload_too_large
        - rate_limited
        - provider_unavailable
        - database_unavailable
        - internal_error
        - invalid_credentials
        - request_expired
        - challenge_not_found
        - challenge_consumed
        - challenge_expired
        - signature_invalid
        - key_not_registered
        - signer_not_attached
        - wallet_not_linked
        - approval_consumed
        - approval_expired
        - approval_mismatch
        - signing_policy_refused
        - login_unavailable
        - login_mode_unavailable
        - developer_key_not_found
        - developer_key_already_exists
        - account_header_invalid
        - account_scope_conflict
        - account_not_found
        - account_forbidden
        - account_read_only
        - account_not_controlled
        - contact_not_found
        - quote_not_submitted
        - quote_not_fundable
        - funding_mode_unsupported
        - funding_token_unsupported
        - insufficient_funds
        - smart_wallet_not_deployed
        - wallet_owner_unverified
        - already_funded
        - payment_slot_consumed
        - funding_in_progress
        - funding_attempt_expired
        - contact_changed
        - user_operation_rejected
        - user_operation_unavailable
        - integrator_inactive
        - client_creation_not_enabled
        - email_in_use
        - name_in_use
        - client_request_conflict
        - client_not_found
        - profile_locked
        - contact_not_payable
        - contact_chain_unsupported
        - contact_token_unsupported
        - contact_payment_details_invalid
        - amount_below_minimum
        - amount_above_maximum
        - amount_precision_unsupported
        - payout_not_found
        - payout_not_fundable
        - quote_expired
        - bundler_rejected
        - bundler_unavailable
        - contact_details_invalid
        - contact_in_use
        - kyb_incomplete
        - kyb_roster_conflict
        - kyb_subject_conflict
        - document_fields_missing
        - document_not_found
        - document_type_unsupported
        - invalid_enum_value
        - entity_not_found
        - escrow_not_found
        - escrow_action_not_found
        - escrow_not_operated_by_you
        - escrow_state_changed
        - action_in_flight
        - simulation_failed
        - stale_nonce
        - amount_out_of_range
        - amount_not_allowed
        - window_closed
        - token_not_supported
        - receiver_not_a_client
        - rail_not_found
        - rail_not_available
        - rail_requirements_unmet
        - phone_required
        - payin_not_available
        - payin_expired
        - payin_not_found
        - transaction_not_found
      title: PlatformErrorCode
  securitySchemes:
    HTTPBearer:
      type: http
      scheme: bearer

````