Skip to main content
The consumer session endpoint is the wallet-first entry point for the FlareHQ consumer product. There is no email or password — a wallet address is the account. POST with an empty body creates a brand-new Circle-managed wallet and account; POST with a walletAddress connects an existing external wallet. Either way the response issues a signed JWT in a consumer_token cookie that lasts 30 days. The same path also hosts GET (session check) and DELETE (sign out).

Endpoint

Request

Headers

No authentication is required to create a session — this endpoint is the onboarding step.

POST Body Parameters

string
Connect an existing external wallet. Must be a valid EVM 0x... address. When omitted, FlareHQ provisions a brand-new Circle-managed wallet instead.

Response

boolean
true on a successful session creation.
object
The consumer account behind the session.
The response also sets the consumer_token cookie (HttpOnly, SameSite=Lax, 30-day expiry). Browsers store and resend it automatically; protected consumer endpoints (balance, activity) require it.

GET — Session check

Returns the account decoded from the consumer_token cookie, for page-load session checks. Response body mirrors the POST body:

DELETE — Sign out

Clears the consumer_token cookie and returns:

Examples

Success Response

Error Responses

Notes

Sessions last 30 days so consumers do not have to re-onboard often. If a consumer’s cookie expires, simply call POST again with their existing walletAddress to refresh the session — existing external-wallet accounts are reused, and their lastSeenAt is updated.
Real fund custody lives in Circle for CIRCLE-type wallets, while EXTERNAL wallets are non-custodial by nature. The session mechanism itself is identical either way.
Calling POST with an empty body always provisions a new Circle wallet. To resume an existing account, always pass the walletAddress.