Documentation

Authentication

RunLayer supports wallet-signed sessions for the console and long-lived API keys for integrators.

Wallet sign-in (console)

The orchestrator issues a nonce; you sign a fixed message with your wallet; the server verifies and returns a JWT scoped to your workspace.

Sign-in flow
# 1) Nonce
GET https://runlayer-y9kc.onrender.com/v1/auth/nonce?address=0xYOUR_WALLET

# 2) Sign `message` in wallet, then:
POST https://runlayer-y9kc.onrender.com/v1/auth/sign-in
{
  "address": "0xYOUR_WALLET",
  "nonce": "...",
  "signature": "0x..."
}

# 404 no_workspace → complete POST /v1/onboarding first

Onboarding (new workspace)

POST /v1/onboarding
POST https://runlayer-y9kc.onrender.com/v1/onboarding
{
  "name": "Acme agents",
  "slug": "acme-agents",
  "address": "0xYOUR_WALLET",
  "nonce": "...",
  "signature": "0x..."
}

→ { "token": "...", "workspaceId": "...", "slug": "..." }

Session JWT

Pass Authorization: Bearer <jwt> on workspace routes (runs, agents, billing). Invalid sessions return 401; the console drops to guest mode without redirecting to onboarding.

Workspace profile
GET https://runlayer-y9kc.onrender.com/v1/workspaces/me
Authorization: Bearer <jwt>

API keys

Keys are prefixed with rl_sk_ and map to the same workspace as the creator. Use them for server-side dispatch and CI.

HeaderValue
AuthorizationBearer rl_sk_…
Content-Typeapplication/json

Lookup before sign-in

  • GET /v1/auth/lookup?address=0x… — returns whether a workspace exists for that wallet.