POST /api/merchant/verify before you can log in or receive an API key.
Endpoint
Request
Headers
No authentication is required. Anyone with a valid email can sign up.
Body Parameters
string
required
The merchant’s email address. Must be unique — if a verified account already exists for this email, the request fails with
HTTP 409.string
required
The merchant’s display name. This is the name shown to payers on hosted checkout pages and used to match payments in the dashboard.
string
required
Account password, hashed with bcrypt before storage. Must be at least 8 characters.
string
Accepted for backward compatibility but ignored. Every merchant starts on a Circle-managed wallet (
"CIRCLE"), which is provisioned at verification time. Connecting an external wallet (MetaMask, WalletConnect, Coinbase) must be done after login via the SIWE flow at GET/POST /api/merchant/wallet/connect.string
Accepted for backward compatibility but ignored. A raw, unverified external address is no longer accepted at signup — ownership can only be proven through the authenticated SIWE connect flow.
Response
boolean
true on a successful signup.string
Human-readable confirmation —
"Verification code sent. Check your email."string
The email address the verification code was sent to, mirroring the request body.
Examples
Success Response
Error Responses
Notes
The verification code expires 10 minutes after signup. If it expires, sign up again with the same email — the existing unverified record is reused and a fresh code is issued.

