Skip to content
create-bsv-app
4 / 9

Your first signed request

Login proves who you are once. A signed request proves it on every call: the request carries its own proof, bound to its route (the action) and its exact body. No session, no cookie.

The client is done: App.tsx posts notes with signedFetch('/api/notes', { action: 'create-note', body: { text } }) from the generated useSignedRequest() hook.

The server isn't. Post a note and look at the Server panel: note from anonymous. The route believes whatever arrives.

Your task#

In server/src/index.ts, verify the proof before trusting the note, and record the verified author:

ts
const result = await verifySignedRequest(serverWallet, proof, { action: 'create-note', body }, consumeNonce)
if (!result.valid) { res.status(401).json({ error: 'invalid proof' }); return }
notes.push({ author: result.identityKey!, text: String(body?.text ?? '') })

The imports are already at the top. Post again: the server now logs your identity key.

Your task

  • Post a note the server attributes to your identity key