Export internal account wallet credentials
Export the wallet credentials of an Embedded Wallet internal account. The returned wallet credentials are HPKE-encrypted to the clientPublicKey supplied in the request body.
Export is a two-step signed-retry flow (same pattern as add-additional credential, revoke credential, and revoke session):
-
Call POST /internal-accounts/{id}/export with the request body { "clientPublicKey": "..." } and no signature headers. Grid binds the clientPublicKey into the payloadToSign it returns, so the subsequent Grid-Wallet-Signature commits to the target encryption key. The response is 202 with payloadToSign, requestId, and expiresAt.
-
Sign the payloadToSign with the session private key of a verified authentication credential on the same internal account and retry with the signature as the Grid-Wallet-Signature header and the requestId echoed back as the Request-Id header. The retry body must carry the same clientPublicKey submitted in step 1 — Grid rejects the retry with 401 if it disagrees with what was bound into payloadToSign. The signed retry returns 200 with encryptedWalletCredentials, which the client decrypts with the matching private key.
The clientPublicKey is ephemeral: generate a fresh P-256 keypair for this export and discard the private key after decrypting. Do not reuse the keypair from any prior verify call — that private key was already discarded after decrypting the session signing key it was issued against.
Path parameters
The id of the internal account to export.
Headers
Signature over the payloadToSign returned in a prior 202 response, produced with the session private key of a verified authentication credential on the target internal account and base64-encoded. Required on the signed retry; ignored on the initial call.
The requestId returned in a prior 202 response, echoed back on the signed retry so the server can correlate it with the issued challenge. Required on the signed retry; must be paired with Grid-Wallet-Signature.
Request body
Example request
{
"clientPublicKey": "04f45f2a22c908b9ce09a7150e514afd24627c401c38a4afc164e1ea783adaaa31d4245acfb88c2ebd42b47628d63ecabf345484f0a9f665b63c54c897d5578be2"
}Response
Signed retry accepted. Returns the encrypted wallet credentials.
Example response
{
"id": "InternalAccount:019542f5-b3e7-1d02-0000-000000000002",
"encryptedWalletCredentials": "5KqM8nT3wJz2F9b6H1vRgLpXcA7eD4YuN0sBaE8kPyW5iVfG2xQoZ3MnK9LhU6jT1dS4rCyPbH7oVwX2AgE5uYsNq8fLzR3D7JeM1bVkWcHa9Tp"
}