# Verify an Address

Keep the address a signed challenge proves.

## Overview

- EVM: the `personal_sign` (EIP-191) signature, 65 bytes in hex, from the address's key — the key controls the address on every EVM chain, so one proof serves every EVM pair. A smart account (EIP-1271) cannot prove an address this way. Solana: the ed25519 signature of the message's bytes, 64 bytes in base58.
- `201` with the proven address; `200` with it when the user already held it.
- A wrong signature: `400` `CARD_ONRAMP_ADDRESS_SIGNATURE_INVALID` with `details.reason` (`malformed` or `wrong_signer`) and `details.attemptsLeft`; after five, `CARD_ONRAMP_ADDRESS_CHALLENGE_BURNT`. `400` `CARD_ONRAMP_ADDRESS_CHALLENGE_EXPIRED`, `409` `CARD_ONRAMP_ADDRESS_CHALLENGE_USED`, `404` `CARD_ONRAMP_ADDRESS_CHALLENGE_NOT_FOUND` for a challenge that is not the user's.
- `label` is the user's name for the address, up to 100 characters.

## Endpoint

### `POST /v1/ramp/card/addresses/verify`

Authentication: bearer token required.

Keeps the address a signed challenge proves.

**Request body**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `challengeId` | string (uuid) | yes | The challenge's id |
| `signature` | string | yes | The signature over the challenge's message |
| `label` | string \| null | no | The user's name for the address |

**Responses**

`201` Proven

```json
{
  "id": "b7e1c2d3-4f5a-4b6c-8d7e-9f0a1b2c3d4e",
  "family": "evm",
  "address": "0x52908400098527886E0F7030069857D2E4169EE7",
  "label": "Ledger",
  "proof": "eip191",
  "environment": "sandbox",
  "verifiedAt": "2026-09-24T15:01:12.340Z"
}
```

`400` Wrong signer

```json
{
  "statusCode": 400,
  "error": "BadRequestError",
  "message": "The signature was not made with this address's key over the challenge's message.",
  "details": { "code": "CARD_ONRAMP_ADDRESS_SIGNATURE_INVALID", "reason": "wrong_signer", "attemptsLeft": 4 }
}
```

---

Web version: https://docs.aureahub.com/#card-onramp-address-verify
