Strategy success-fee claim summary (per agent)
Aggregates unified per-agent claimable USD (subscriber success fees, subscription-earnings CLAIMABLE ledger, legacy TradingBot.feeEarnings). Same claim rail as Main App claimAgentFees.
Authorizations
User JWT access token issued by POST /api/auth/verify or POST /api/auth/social/verify. Routes that accept both auth modes declare api-key and bearer-jwt security schemes.
Headers
HMAC-SHA256 signature: HMAC-SHA256(secretKey, timestamp + METHOD + path + body). Required for API-key authenticated requests (JWT/OAuth session auth is exempt).
Request timestamp in epoch milliseconds. Required with x-signature for API-key auth. Rejected if drift exceeds 5 minutes.