Assign one relayer in the sender's shard and issue a lease. Nothing is reserved yet.
POST/v1/relay/assign
Call it just before the user signs: the relayer address goes into the transaction, so the user signs
once. renewFor renews the lease for a transaction that is already signed, so a slow signer does not
have to sign again. cancel returns a lease for a cancel transaction, pinned to that nonce.
Rate limits: 10/s per IP, and 2/s per sender with a burst of 10.
The caller must prove it controls the sender, in one of two ways:
- a presence proof: the sender's own key signs the message
corelayer/assign/v1|<chainId>|<sender>|<serverTimeMs>, whereserverTimeMsis within +/- 30 000 ms of the server clock. The signature is a raw Ed25519 signature over the UTF-8 bytes of the message, without the MultiversX signed-message prefix that a wallet'ssignMessageadds. Setproof.kindtosponsorwhen a sponsor API key will pay for the relay, and tokeyotherwise. The sender's key signs both kinds; - a native-auth bearer token whose address equals
sender.
This route does not read X-Api-Key, and a sponsor API key never proves presence: it goes on
POST /v1/relay, where it selects the account that pays.
A missing proof gives 401 ASSIGN_PROOF_REQUIRED; a bad or stale one gives 401 ASSIGN_PROOF_INVALID.
The prepare routes of the free purchase flow issue their own FREE lease and need no proof.
Request
Responses
- 200
- 400
- 401
- 403
- 409
- 429
- 503
Assignment.
Response Headers
Request id, also the instance of a problem document and the log correlation id.
MALFORMED_REQUEST, VARIANTS_NOT_SUPPORTED, RELAYER_SIGNATURE_PRESENT, CHAIN_ID_MISMATCH, TX_VERSION_UNSUPPORTED, TX_OPTIONS_UNSUPPORTED, LEASE_MISSING, CURSOR_INVALID.
Response Headers
Request id, also the instance of a problem document and the log correlation id.
ASSIGN_PROOF_REQUIRED or ASSIGN_PROOF_INVALID (details.serverTimeMs = signer clock), or a token error of the Unauthorized class.
FORBIDDEN, ORIGIN_NOT_ALLOWED, API_KEY_SCOPE, ACCOUNT_SUSPENDED, LEASE_INVALID, RECEIVER_NOT_ALLOWED, SENDER_NOT_AUTHORIZED, DEPLOY_NOT_ALLOWED, FREE_FLOW_BARRED.
RESIGN_REQUIRED (renewFor relayer no longer renewable) or NOTHING_TO_CANCEL.
RATE_LIMITED, GAS_BUDGET_EXCEEDED, HOURLY_BURN_EXCEEDED, TOO_MANY_IN_FLIGHT, QUOTA_EXHAUSTED (the latter without Retry-After; details.reason = CAP_REACHED_PAYG_OFF | PAYG_ESCROW_EMPTY).
Response Headers
Seconds (HTTP standard). Millisecond precision is in details.retryAfterMs of the problem body.
Requests (or RU on the relay path) allowed in the current window.
Remaining units in the current window.
Seconds until the window resets (IETF RateLimit header fields).
NO_RELAYER_AVAILABLE, SIGNER_UNAVAILABLE or SIGNER_FENCED; carries Retry-After.
Response Headers
Seconds (HTTP standard). Millisecond precision is in details.retryAfterMs of the problem body.