Skip to main content
Creates a JWT token for a Steam user, allowing them to access client endpoints (inventory, market, trading). Authentication: API Key (api-key header, requires CORE_ACCESS scope)

Request

Body Parameters

Unknown top-level body keys are rejected with 1001 VALIDATION_FAILED.

clientData Fields

totalWager, kycLevel, fiatDeposits and cryptoDeposits feed into the risk model that determines instant deposit collateral. All fields are optional and default to 0/false/null if omitted. Keys not listed here are dropped. Having both fiatDeposits and cryptoDeposits as true combined with kycLevel: 3 applies the lowest wager threshold, so the same wager earns the most collateral. kycLevel: 3 alone, or both deposit types alone, applies the middle threshold. This endpoint only signs a token: nothing is stored when you call it. The clientData inside the token is saved to the user’s record when they create a deposit or withdrawal with that token, so issue a new token whenever the values change.

Response

Response Fields

Token Structure

The generated JWT contains: Header:
Payload:
The merchantId claim and the JWT header userId field both carry the merchant ID. AssetPay looks up your API secret by the header userId only, so a token without it fails with 1102 INVALID_TOKEN.

Rate Limits

Errors