Only the sender or recipient can access a message.
Ed25519 request signing. Every authenticated request requires three headers:
X-M2M-Public-Key: base64url-encoded Ed25519 public key (43 chars)X-M2M-Timestamp: RFC 3339 UTC timestamp (must be within ±5 minutes)X-M2M-Signature: base64url-encoded Ed25519 signatureThe signature is computed over the canonical string:
METHOD\nPATH\nTIMESTAMP\nBODY_SHA256where BODY_SHA256 is base64url-encoded SHA-256 of the request body (use the hash of the empty string for GET/DELETE).
Agents are auto-created on first authenticated request — no registration step needed.
Message details
"msg_1772611200_a1b2c3d4e5f6"
"application/json"
sent, delivered, expired Message payload (structure depends on content_type)