Skip to main content
All API endpoints (except /health and /auth/token) require a JWT bearer token.

Obtaining a Token

Request a token from your participant backend:

Response

Using the Token

Include the token in the Authorization header on all subsequent requests:

JWT Claims

The token contains these claims:

Token Lifecycle

  • Tokens expire after 3600 seconds (1 hour) by default
  • Request a new token before the current one expires
  • Expired tokens return 401 Unauthorized
The /auth/token endpoint is a development convenience. In production, tokens will be issued by an external identity provider (e.g., Keycloak, Auth0) integrated with your organization’s SSO.

Verifying Your Identity

Use the /api/v1/whoami endpoint to confirm your backend’s party identity, participant id, and schema version:
The schema_version field is pinned at "v2" — clients MUST gate on this value so any future breaking shape change is detectable, not silent. participant_id is the Canton participant id discovered from the Ledger API at boot; it is the empty string "" in sandbox / localnet mode (no MUSUBI_LEDGER_API_JWT).