# Address Challenge

The message a user signs to prove they control an address the onramp may deliver to.

## Overview

- Needs the onramp offered in that environment and your tenant's `provenAddresses` on: `403` `CARD_ONRAMP_OFF` or `CARD_ONRAMP_PROVEN_ADDRESSES_OFF`.
- `message` is the exact text to sign, line breaks included. It names your tenant by its own name, the address and its kind, the environment, your tenant's and the user's ids, a nonce and when it expires — ten minutes after it was issued.
- An EVM address is stored with its checksum: a mixed-case address with a wrong checksum, or the zero address, is refused; a Solana address must be 32 bytes in base58 (`400` `CARD_ONRAMP_ADDRESS_INVALID`).
- A user holds at most five open challenges (`409` `CARD_ONRAMP_ADDRESS_CHALLENGE_LIMIT`, with `details.limit`).

## Endpoint

### `POST /v1/ramp/card/addresses/challenge`

Authentication: bearer token required.

A challenge for proving one address.

**Request body**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `isTestnet` | boolean | no | `true` for the sandbox |
| `family` | string | yes | `evm` or `solana` |
| `address` | string | yes | The address |

**Responses**

`201` Issued

```json
{
  "challengeId": "0f6a2c1e-8b3d-4e5f-9a7b-1c2d3e4f5a6b",
  "family": "evm",
  "address": "0x52908400098527886E0F7030069857D2E4169EE7",
  "environment": "sandbox",
  "message": "Brand Bank asks you to prove that you control this address, to receive the crypto you buy by card.\nSigning this message moves no funds and costs nothing.\n\nAddress: 0x52908400098527886E0F7030069857D2E4169EE7\nAddress type: EVM\nEnvironment: sandbox\nTenant: 7c1e2d3f-4a5b-4c6d-8e9f-0a1b2c3d4e5f\nUser: 5d2c1b0a-9e8f-4a7b-8c6d-5e4f3a2b1c0d\nNonce: 3f9a…\nIssued at: 2026-09-24T15:00:00.000Z\nExpires at: 2026-09-24T15:10:00.000Z",
  "issuedAt": "2026-09-24T15:00:00.000Z",
  "expiresAt": "2026-09-24T15:10:00.000Z"
}
```

`403` Not allowed

```json
{
  "statusCode": 403,
  "error": "ForbiddenError",
  "message": "This tenant does not let the onramp deliver to an address you proved.",
  "details": { "code": "CARD_ONRAMP_PROVEN_ADDRESSES_OFF", "environment": "sandbox" }
}
```

---

Web version: https://docs.aureahub.com/#card-onramp-address-challenge
