POST with an empty body creates a brand-new Circle-managed wallet and account; POST with a walletAddress connects an existing external wallet. Either way the response issues a signed JWT in a consumer_token cookie that lasts 30 days. The same path also hosts GET (session check) and DELETE (sign out).
Endpoint
Request
Headers
No authentication is required to create a session — this endpoint is the onboarding step.
POST Body Parameters
string
Connect an existing external wallet. Must be a valid EVM
0x... address. When omitted, FlareHQ provisions a brand-new Circle-managed wallet instead.Response
boolean
true on a successful session creation.object
The consumer account behind the session.
consumer_token cookie (HttpOnly, SameSite=Lax, 30-day expiry). Browsers store and resend it automatically; protected consumer endpoints (balance, activity) require it.
GET — Session check
Returns the account decoded from theconsumer_token cookie, for page-load session checks. Response body mirrors the POST body:
DELETE — Sign out
Clears theconsumer_token cookie and returns:
Examples
Success Response
Error Responses
Notes
Sessions last 30 days so consumers do not have to re-onboard often. If a consumer’s cookie expires, simply call
POST again with their existing walletAddress to refresh the session — existing external-wallet accounts are reused, and their lastSeenAt is updated.
