Documentation
Authentication
RunLayer supports wallet-signed sessions for the console and long-lived API keys for integrators.
Wallet sign-in (console)
The orchestrator issues a nonce; you sign a fixed message with your wallet; the server verifies and returns a JWT scoped to your workspace.
Sign-in flow
# 1) Nonce
GET https://runlayer-y9kc.onrender.com/v1/auth/nonce?address=0xYOUR_WALLET
# 2) Sign `message` in wallet, then:
POST https://runlayer-y9kc.onrender.com/v1/auth/sign-in
{
"address": "0xYOUR_WALLET",
"nonce": "...",
"signature": "0x..."
}
# 404 no_workspace → complete POST /v1/onboarding firstOnboarding (new workspace)
POST /v1/onboarding
POST https://runlayer-y9kc.onrender.com/v1/onboarding
{
"name": "Acme agents",
"slug": "acme-agents",
"address": "0xYOUR_WALLET",
"nonce": "...",
"signature": "0x..."
}
→ { "token": "...", "workspaceId": "...", "slug": "..." }Session JWT
Pass Authorization: Bearer <jwt> on workspace routes (runs, agents, billing). Invalid sessions return 401; the console drops to guest mode without redirecting to onboarding.
Workspace profile
GET https://runlayer-y9kc.onrender.com/v1/workspaces/me
Authorization: Bearer <jwt>API keys
Keys are prefixed with rl_sk_ and map to the same workspace as the creator. Use them for server-side dispatch and CI.
| Header | Value |
|---|---|
| Authorization | Bearer rl_sk_… |
| Content-Type | application/json |
Lookup before sign-in
GET /v1/auth/lookup?address=0x…— returns whether a workspace exists for that wallet.