403, even when your code and credentials are perfect:
- Your API wallet is authorized on your RiseID. You add the wallet’s public address on the API Config page, where it gets the Viewer role. On your RiseID it can only sign you in. To create payment intents, the same wallet also needs a role on the account you pay from (see What your API session can do).
- You have enabled your company for the B2B API. The API is off by default. You switch it on per environment and company, so staging and production are enabled separately.
Open the API Config page
Every step below is managed here, so open it first and come back whenever a step says to. Switch into the workspace for the company you’re integrating, then in the left menu expand B2B API and open API Config.
- Expand B2B API in the left menu. 2. Open API Config.
Authorize your API wallet
The wallet you sign in with has to be authorized on your personal RiseID before the login handshake will hand you a token. You add its public address on the API Config page, where it’s granted the Viewer role. That’s deliberate: Viewer lets the wallet sign you in but not act on your RiseID. To create payment intents, give the same wallet a role on the account under Scoped, low-privilege credentials. It then signs those intents, but it can’t execute payments or move funds through the API.
On the API Config page, under RiseID permissions for API, click Add viewer wallet.
Add the wallet
Sign the change
Wait for confirmation
403.
The Add RiseID API wallet dialog: the role is fixed to Viewer. Paste the address and click Add wallet.
Enable your company for B2B API access
The B2B API is off by default. You turn it on yourself in the app, no support request needed. This is a per-company setting, and staging and production are enabled separately.Open API Config for the right company
Turn on Rise API access
Save and verify

Turn on Enable Rise API access, then click Save.
Gather what you need to authenticate
With both prerequisites in place, collect the two values the authentication handshake needs to sign you in with SIWE:- Your RiseID: the personal RiseID you pass as
riseid. - Your registered wallet address: the wallet you authorized above, passed as
walletand used to sign the challenge.
Your RiseID
The login handshake authenticates a user, so theriseid you send is your personal (user) RiseID, not a company or team RiseID, and not your Rise Account address. Sending anything else returns 404 No entity found with riseid <id>.
To find it in the app:
Open My Profile
Copy the Rise ID
0x, for example 0x2DF5...b089.
- Open My Profile from the left menu. 2. Under Details, copy the Rise ID (the bare 0x), not the Rise Account below it.
co- / te- nanoids rather than by the login handshake. See RiseID for how the identity hierarchy fits together.
Your registered wallet address
This is the Viewer wallet you authorized under RiseID permissions for API in Authorize your API wallet. You pass its address aswallet and sign the SIWE challenge with its private key. To confirm which wallets can sign in, open the API Config page and check RiseID permissions for API.
Once you have both values, run the authentication handshake. A successful GET /v2/me confirms the wallet is authorized and the token is valid; a scoped call like fetching a team or balance confirms your company is enabled for the environment.
Scoped, low-privilege credentials
To create payment intents, or whenever you work with a third-party provider, give your API wallet an account-level scoped credential with the Payment Initiator role instead of sharing a wallet that can move funds. A Payment Initiator can create payment intents, which then have to be approved before they’re processed, so the provider can queue payments without being able to move money on its own.Open the API Config page
Select the account and add a wallet

Select the account, then click Add account wallet.
Name and add the wallet

The Add account wallet dialog: pick the Payment Initiator role, name the wallet, and paste its address.
What your API session can do
Your API session is the Viewer wallet you signed in with. Viewer on your RiseID only signs you in. What the session can do with an account depends on the role that same wallet holds on the account, and that wallet signs the payment intent. Signing an intent doesn’t execute a payment: an approver executes it in the app.Reference and troubleshooting
Everything below is here when you need it: how the two checks fit into the login flow, and how to read each error.How the two checks fit into the flow
The two prerequisites are checked at different points, which is why they fail differently:/v2/me but gets a 403 the moment it touches a team or payment.