Loading the key
The recommended way is a key file, which keeps key material out of source code:The recovery phrase is the key: its 256 bits of entropy are used directly as the Ed25519 private key, with no derivation path and no passphrase, exactly as the Walley app encodes it at registration. See Recovery Phrase.
Keys, fingerprints, and party ids
TheSigner class converts between representations:
<hint>::<fingerprint>, so the key and the party are cryptographically bound. Identify the party either way:
party_id whose namespace doesn’t match the key’s fingerprint is rejected up front.
Signing arbitrary messages
w.sign(...) produces a signature bundle any verifier can check against the party id. This is useful for login proofs and off-ledger attestations:
signMessage.
How reads authenticate
Reads (balances, holdings, history, ledger queries) need a bearer token, which the SDK gets through the auth endpoints: it requests a challenge, signs it with your key, and trades the signature for a short-lived access token. This happens automatically on the first read and again whenever the token expires, so there is nothing to configure.Configuration reference
audience must match the target deployment’s auth configuration. Override it together with api_base when pointing at a non-production environment.