GET /account; order entry, your orders, fills and positions will use the same key when they ship.
API keys are in early access. To request one, contact support.
What a key can and can’t do
A key is tied to one account and carries the permissions you gave it when you made it.
A key can never withdraw, transfer or change your account. Moving money out stays in the app, behind your own sign-in. If a key leaks, the worst it can do is trade within the limits you set.
Test and live keys
Build and test with a test key, then make a live key when you are ready.
Key format
Sending a key
Send it as a bearer token on every request that needs it:GET /account first whenever you set up a new key: it confirms the key works and shows exactly what it is allowed to do.
Limits on a key
When you create a key you can narrow it further. Every limit is optional.
An account can have up to 5 active keys. The trading limits take effect with order entry;
GET /account already shows them.
When a key is refused
A refused key gets HTTP401 with code UNAUTHORIZED and a message saying why:
Repeated failed attempts from one address are locked out for a while and answer
429. Revoking a key takes effect within about 10 seconds.
Keeping keys safe
- Keep keys in environment variables or a secrets manager — never in code, a repository, a chat or a screenshot.
- Give each program its own key with only the permissions and limits it needs, so you can revoke one without stopping the others.
- Use an IP allowlist for anything running on a fixed server.
- If a key may have been seen by anyone else, revoke it straight away.