---
title: "Draw an authorization request's random values (sign-in pages)"
method: POST
path: "/products/identity/{account_id}/entropy"
tags: ["identity"]
---

# Draw an authorization request's random values (sign-in pages)

`POST /products/identity/{account_id}/entropy`

The draw a page that holds no SparkVault credential takes its sign-in values from: an authorization request's PKCE verifier, state and nonce, which the browser SDK's `signIn()` and the hosted sign-in pages draw here. Every call first spends one draw of its network address's hourly budget, before anything is read, counted whichever account the path names, and the call past it is refused 429 with nothing drawn. A browser on an origin the account has not verified is then refused, with nothing drawn.

## Path parameters

- `account_id` string, required

## Request body

- object
  - `num_bytes` integer, required — Bytes to draw: 1 to 64.

## Response `200`

The draw.

- object
  - `data` object, required
    - `value` string, required — The bytes as unpadded base64url.
    - `num_bytes` integer, required
  - `meta` ResponseMeta — Envelope metadata present on every successful response.
    - `api_version` string
    - `request_id` string
    - `response_ms` integer
    - `timestamp` integer — Unix seconds.
    - `pools` object — Storage and bandwidth capacity snapshot for the account.
    - `billing` object
      - `past_due` boolean
    - `quota` object — This minute of the account request budget. Present on authenticated success responses that passed the throttle; absent otherwise.
      - `limit` integer
      - `used` integer
      - `remaining` integer
      - `resets_at` integer — Unix seconds.

## Other responses

- `400` — VALIDATION_ERROR — `num_bytes` is not an integer from 1 to 64; or ORIGIN_NOT_ALLOWED — the browser's origin is not a verified domain of the account.
- `429` — RATE_LIMIT_EXCEEDED — this network address has started too many sign-ins this hour, whichever account each named. `Retry-After` carries the seconds until the budget reopens, and `details` carries `limit`, `used` and `resets_at`.

## Changes

- **2026-10-06** `ddca8926a12f` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/sparkvault/apis/sparkvault-api/changes/products/identity/:account_id/entropy/post.md)

---

[API](https://skmtc.dev/sparkvault/apis/sparkvault-api.md) · [All operations](https://skmtc.dev/sparkvault/apis/sparkvault-api/llms.txt) · [OpenAPI document](https://skmtc.dev/sparkvault/apis/sparkvault-api/revisions/ddca8926a12f?raw)
