Hilt Auth API

The auth API from Hilt — 8 operation(s) for auth.

Operations 8

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

POST /v1/auth/register Register a new merchant account · Register #
Ask an LLM
“How do I sign up for a free Hilt merchant account?”
“Can I use a referral code when I register?”
Tell an agent
Register a merchant account for {email} with password {password}.
Sign up {email} using referral code {referral_code} and password {password}.
POST /v1/auth/login Log in with email and password · Login #
Ask an LLM
“How do I get a JWT by logging in with my email and password?”
“Does the login token include my plan entitlements?”
Tell an agent
Log in as {email} with password {password}.
Sign me in with {email} and get a token.
POST /v1/auth/wallet Sign in with a Phantom wallet · Wallet Auth #
Ask an LLM
“Can I sign in with my Phantom wallet instead of an email?”
“What do I need to send to authenticate with a signed wallet nonce?”
Tell an agent
Authenticate wallet {wallet_address} with signed message {signed_message} for nonce {message_nonce}.
Log in with Phantom wallet {wallet_address}.
GET /v1/auth/oauth/providers List available OAuth sign-in providers · Oauth Provider Status #
Ask an LLM
“Which social OAuth providers can I sign in with?”
“Is OAuth login currently enabled for each provider?”
Tell an agent
List the OAuth sign-in providers and their status.
Show which OAuth logins are available.
GET /v1/auth/oauth/{provider}/start Start an OAuth sign-in flow · Oauth Start #
Ask an LLM
“How do I begin signing in through an OAuth provider?”
“Can I choose where to redirect after the OAuth login finishes?”
Tell an agent
Start OAuth sign-in with {provider}.
Begin an OAuth login with {provider} and return to {next} afterward.
GET /v1/auth/oauth/{provider}/callback Handle an OAuth provider callback · Oauth Callback #
Ask an LLM
“What endpoint receives the authorization code when the OAuth provider redirects back?”
“How is an OAuth error returned from the provider handled on callback?”
Tell an agent
Complete the {provider} OAuth callback with code {code} and state {state}.
Process the {provider} callback that returned error {error}.
POST /v1/auth/logout Log out of the current session · Logout #
Ask an LLM
“How do I log out of my session?”
“Does logging out invalidate my JWT on the server?”
Tell an agent
Log me out.
End my current session.
POST /v1/auth/refresh Refresh a session token · Refresh Token #
Ask an LLM
“Can I renew my JWT before it expires?”
“Will a refreshed token pick up my new subscription plan?”
Tell an agent
Refresh token {token}.
Get a fresh JWT from {token} with updated entitlements.

Documentation

Specifications

Other Resources

🔗
OAuthScopes
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/scopes/hilt-so-scopes.yml
🔗
Conventions
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/conventions/hilt-so-conventions.yml
🔗
Idempotency
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/conventions/hilt-so-conventions.yml
🔗
ErrorCatalog
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/errors/hilt-so-problem-types.yml
🔗
Conformance
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/conformance/hilt-so-conformance.yml
🔗
Lifecycle
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/lifecycle/hilt-so-lifecycle.yml
🔗
Sandbox
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/sandbox/hilt-so-sandbox.yml
🔗
DataModel
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/data-model/hilt-so-data-model.yml
🔗
Webhooks
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/asyncapi/hilt-so-webhooks-asyncapi.yml
🔗
Webhooks
https://docs.hilt.so/developers/webhooks
🔗
Plans
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/plans/hilt-so-plans-pricing.yml
🔗
ChangeLog
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/changelog/hilt-so-changelog.yml
🔗
Postman
https://www.hilt.so/downloads/hilt-postman-collection-latest.json
🔗
Postman
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/postman/hilt-so-postman-collection.json
🔗
Packages
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/packages/hilt-so-packages.yml
🔗
SDKs
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/packages/hilt-so-packages.yml
🔗
CLI
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/cli/hilt-so-cli.yml
🔗
Components
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/components/hilt-so-components.yml
🔗
ToolCrosswalk
https://raw.githubusercontent.com/api-evangelist/hilt-so/refs/heads/main/mcp/hilt-so-tool-crosswalk.yml

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/hilt-so:hilt-so-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

hilt-so-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Hilt Auth API
  description: Hilt Pay Workspace and Hilt Pay API routes for zero-custody Solana checkout, MPP metered payment channels, receipts, memberships, entitlements, native subscriptions, webhooks, and support context.
  version: 1.0.0
  contact:
    name: Hilt
    url: https://www.hilt.so
    email: hello@hilt.so
  x-guidance: Start with POST /v1/access/agent-bootstrap. An agent can purchase 30 days of Starter, Growth, or Scale through the matching x402 V2 activation endpoint paid in Solana USDC. For metered integrations, settle PAYMENT-SIGNATURE through POST /v1/access/x402/settle and atomically consume through POST /v1/access/entitlements/consume before serving. Never send private keys, seed phrases, or wallet secrets.
servers:
- url: https://api.hilt.so
tags:
- name: Auth
paths:
  /v1/auth/register:
    post:
      tags:
      - Auth
      summary: Register
      description: Creates a new Hilt merchant account on the free plan.
      operationId: register_v1_auth_register_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RegisterRequest'
        required: true
      responses:
        '201':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
  /v1/auth/login:
    post:
      tags:
      - Auth
      summary: Login
      description: Password-based login. Returns JWT on success with full entitlement claims.
      operationId: login_v1_auth_login_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LoginRequest'
        required: true
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
  /v1/auth/wallet:
    post:
      tags:
      - Auth
      summary: Wallet Auth
      description: 'Phantom wallet-based authentication.

        Verifies the signed nonce, creates or retrieves the user account.

        Wallet-only accounts have no email so is_staff is always False.'
      operationId: wallet_auth_v1_auth_wallet_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WalletAuthRequest'
        required: true
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
  /v1/auth/oauth/providers:
    get:
      tags:
      - Auth
      summary: Oauth Provider Status
      operationId: oauth_provider_status_v1_auth_oauth_providers_get
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthProviderStatusResponse'
  /v1/auth/oauth/{provider}/start:
    get:
      tags:
      - Auth
      summary: Oauth Start
      operationId: oauth_start_v1_auth_oauth__provider__start_get
      parameters:
      - name: provider
        in: path
        required: true
        schema:
          type: string
          title: Provider
      - name: mode
        in: query
        required: false
        schema:
          type: string
          default: login
          title: Mode
      - name: next
        in: query
        required: false
        schema:
          anyOf:
          - type: string
          - type: 'null'
          title: Next
      - name: surface
        in: query
        required: false
        schema:
          anyOf:
          - type: string
          - type: 'null'
          title: Surface
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthStartResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
  /v1/auth/oauth/{provider}/callback:
    get:
      tags:
      - Auth
      summary: Oauth Callback
      operationId: oauth_callback_v1_auth_oauth__provider__callback_get
      parameters:
      - name: provider
        in: path
        required: true
        schema:
          type: string
          title: Provider
      - name: code
        in: query
        required: false
        schema:
          anyOf:
          - type: string
          - type: 'null'
          title: Code
      - name: state
        in: query
        required: false
        schema:
          anyOf:
          - type: string
          - type: 'null'
          title: State
      - name: error
        in: query
        required: false
        schema:
          anyOf:
          - type: string
          - type: 'null'
          title: Error
      - name: error_description
        in: query
        required: false
        schema:
          anyOf:
          - type: string
          - type: 'null'
          title: Error Description
      responses:
        '302':
          description: Redirect to the Hilt application after OAuth.
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
  /v1/auth/logout:
    post:
      tags:
      - Auth
      summary: Logout
      description: 'Logs out the current session.

        For stateless JWTs this is a no-op server-side.

        Clients should discard the token locally.'
      operationId: logout_v1_auth_logout_post
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DetailResponse'
  /v1/auth/refresh:
    post:
      tags:
      - Auth
      summary: Refresh Token
      description: 'Refreshes a JWT that is still valid.

        Issues a new token with a fresh TTL and re-derives entitlement claims

        from the database so subscription changes are reflected immediately.'
      operationId: refresh_token_v1_auth_refresh_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RefreshRequest'
        required: true
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    LoginRequest:
      properties:
        email:
          type: string
          format: email
          title: Email
        password:
          type: string
          title: Password
      type: object
      required:
      - email
      - password
      title: LoginRequest
    AuthResponse:
      properties:
        token:
          type: string
          title: Token
        user_id:
          type: string
          title: User Id
        tier:
          type: string
          title: Tier
        email:
          anyOf:
          - type: string
          - type: 'null'
          title: Email
        claims:
          $ref: '#/components/schemas/EntitlementClaims'
      type: object
      required:
      - token
      - user_id
      - tier
      - email
      - claims
      title: AuthResponse
    OAuthProviderStatusResponse:
      properties:
        google:
          $ref: '#/components/schemas/OAuthProviderInfo'
        github:
          $ref: '#/components/schemas/OAuthProviderInfo'
        x:
          $ref: '#/components/schemas/OAuthProviderInfo'
      type: object
      required:
      - google
      - github
      - x
      title: OAuthProviderStatusResponse
    OAuthStartResponse:
      properties:
        provider:
          type: string
          title: Provider
        callback_url:
          type: string
          title: Callback Url
        authorization_url:
          type: string
          title: Authorization Url
      type: object
      required:
      - provider
      - callback_url
      - authorization_url
      title: OAuthStartResponse
    OAuthProviderInfo:
      properties:
        enabled:
          type: boolean
          title: Enabled
        callback_url:
          type: string
          title: Callback Url
        app_base_url:
          type: string
          title: App Base Url
        uses_app_secret_fallback:
          type: boolean
          title: Uses App Secret Fallback
          default: false
        missing:
          items:
            type: string
          type: array
          title: Missing
      type: object
      required:
      - enabled
      - callback_url
      - app_base_url
      - missing
      title: OAuthProviderInfo
    RegisterRequest:
      properties:
        email:
          type: string
          format: email
          title: Email
        password:
          type: string
          title: Password
        display_name:
          anyOf:
          - type: string
          - type: 'null'
          title: Display Name
        referral_code:
          anyOf:
          - type: string
          - type: 'null'
          title: Referral Code
      type: object
      required:
      - email
      - password
      title: RegisterRequest
    DetailResponse:
      properties:
        detail:
          type: string
          title: Detail
      additionalProperties: true
      type: object
      required:
      - detail
      title: DetailResponse
    WalletAuthRequest:
      properties:
        wallet_address:
          type: string
          title: Wallet Address
        signed_message:
          type: string
          title: Signed Message
        message_nonce:
          type: string
          title: Message Nonce
      type: object
      required:
      - wallet_address
      - signed_message
      - message_nonce
      title: WalletAuthRequest
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
            - type: string
            - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
      - loc
      - msg
      - type
      title: ValidationError
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    RefreshRequest:
      properties:
        token:
          type: string
          title: Token
      type: object
      required:
      - token
      title: RefreshRequest
    EntitlementClaims:
      properties:
        hilt_score:
          type: boolean
          title: Hilt Score
        hilt_pay:
          type: boolean
          title: Hilt Pay
        hilt_ops:
          type: boolean
          title: Hilt Ops
        merchant_analytics:
          type: boolean
          title: Merchant Analytics
        buy_notifications:
          type: boolean
          title: Buy Notifications
        receipt_exports:
          type: boolean
          title: Receipt Exports
        tax_exports:
          type: boolean
          title: Tax Exports
        custom_checkout_domains:
          type: boolean
          title: Custom Checkout Domains
        is_staff:
          type: boolean
          title: Is Staff
      type: object
      required:
      - hilt_score
      - hilt_pay
      - hilt_ops
      - merchant_analytics
      - buy_notifications
      - receipt_exports
      - tax_exports
      - custom_checkout_domains
      - is_staff
      title: EntitlementClaims
x-hilt-agent-commerce:
  offer: https://api.hilt.so/v1/agent-commerce/offer
  catalog: https://api.hilt.so/agent-catalog.json
  pricing: https://api.hilt.so/pricing
  x402: https://api.hilt.so/x402