Skip to main content
Every request authenticates with an API key in the Authorization header:

Creating and revoking keys

Create keys on the account page. A key is shown once, when you create it; we keep only a hash. Store it as you would a password. Revoke a key on the same page. A revoked key stops working on its very next request.
Create a separate key for each program or agent, with the smallest limits it needs. Then you can revoke one without stopping the others, and each key’s limits bound what it can do.

Limits

Every key has three limits, set when you create it and changed only on the account page. Nothing in the API can change a key’s limits. An order outside its key’s limits is refused before anything is recorded, with an error that states the limit and what remains.

How the 24-hour limit counts

  • The window is rolling: at any moment, it covers the last 24 hours.
  • An order counts its requested value while it is pending, and what actually filled once it is final. A rejected order counts nothing.
  • Reduce-only orders and closes never count. A key that hits its limit can still get out of its positions.
  • Orders from a key are admitted one at a time, so two orders sent together can’t both slip under the limit.

Reading a key’s limits

GET /v1/api_key returns the calling key’s limits and usage. Call it before trading to find out what the key may do:
next_release says when the oldest order in the window leaves it, and how much room that frees. A key that has used its limit can wait until then instead of retrying. A key with limits: null was created before limits existed and cannot trade. Set its limits on the account page.

What keys cannot do

  • Withdraw or move money out of the account.
  • Change their own limits, or create other keys.
  • Trade markets outside their list.