All API endpoints (except /health and /auth/token) require a JWT bearer token.
Obtaining a Token
Request a token from your participant backend:
Response
Using the Token
Include the token in the Authorization header on all subsequent requests:
JWT Claims
The token contains these claims:
Token Lifecycle
- Tokens expire after 3600 seconds (1 hour) by default
- Request a new token before the current one expires
- Expired tokens return
401 Unauthorized
The /auth/token endpoint is a development convenience. In production, tokens will be issued by an external identity provider (e.g., Keycloak, Auth0) integrated with your organization’s SSO.
Verifying Your Identity
Use the /api/v1/whoami endpoint to confirm your backend’s party identity, participant id, and schema version:
The schema_version field is pinned at "v2" — clients MUST gate on this value so any future breaking shape change is detectable, not silent. participant_id is the Canton participant id discovered from the Ledger API at boot; it is the empty string "" in sandbox / localnet mode (no MUSUBI_LEDGER_API_JWT).