Skip to main content
Market data needs no key. An API key is for acting as your account: today that is GET /account; order entry, your orders, fills and positions will use the same key when they ship.
API keys are in early access. To request one, contact support.

What a key can and can’t do

A key is tied to one account and carries the permissions you gave it when you made it. A key can never withdraw, transfer or change your account. Moving money out stays in the app, behind your own sign-in. If a key leaks, the worst it can do is trade within the limits you set.

Test and live keys

Build and test with a test key, then make a live key when you are ready.

Key format

The key id identifies the key in lists and logs. The secret is shown once, when you create the key — updown stores only a one-way fingerprint of it and can never show it again. If you lose it, revoke the key and make a new one.

Sending a key

Send it as a bearer token on every request that needs it:
Call GET /account first whenever you set up a new key: it confirms the key works and shows exactly what it is allowed to do.

Limits on a key

When you create a key you can narrow it further. Every limit is optional. An account can have up to 5 active keys. The trading limits take effect with order entry; GET /account already shows them.

When a key is refused

A refused key gets HTTP 401 with code UNAUTHORIZED and a message saying why: Repeated failed attempts from one address are locked out for a while and answer 429. Revoking a key takes effect within about 10 seconds.

Keeping keys safe

  • Keep keys in environment variables or a secrets manager — never in code, a repository, a chat or a screenshot.
  • Give each program its own key with only the permissions and limits it needs, so you can revoke one without stopping the others.
  • Use an IP allowlist for anything running on a fixed server.
  • If a key may have been seen by anyone else, revoke it straight away.