> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tradingapi.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys and limits

> Create keys, set what each one may trade, and read a key's remaining budget.

Every request authenticates with an API key in the `Authorization` header:

```bash theme={"system"}
curl https://tradingapi.dev/v1/account \
  -H "Authorization: Bearer tapi_..."
```

## Creating and revoking keys

Create keys on the [account page](https://tradingapi.dev/account). A key is shown once, when you create it; we keep only a hash. Store it as you would a password.

Revoke a key on the same page. A revoked key stops working on its very next request.

<Tip>
  Create a separate key for each program or agent, with the smallest limits it needs. Then you can revoke one without stopping the others, and each key's limits bound what it can do.
</Tip>

## Limits

Every key has three limits, set when you create it and changed only on the account page. Nothing in the API can change a key's limits.

| Limit | What it bounds |
| - | - |
| **Markets** | The markets the key may trade, closes included. |
| **Max order** | The largest single order, in USD. |
| **Max per 24 hours** | The total value of orders the key may place in any 24 hours, in USD. |

An order outside its key's limits is refused before anything is recorded, with an error that states the limit and what remains.

### How the 24-hour limit counts

* The window is rolling: at any moment, it covers the last 24 hours.
* An order counts its requested `value` while it is pending, and what actually filled once it is final. A rejected order counts nothing.
* Reduce-only orders and closes never count. A key that hits its limit can still get out of its positions.
* Orders from a key are admitted one at a time, so two orders sent together can't both slip under the limit.

## Reading a key's limits

`GET /v1/api_key` returns the calling key's limits and usage. Call it before trading to find out what the key may do:

```json theme={"system"}
{
  "object": "api_key",
  "name": "research-agent",
  "limits": {
    "markets": ["BTC", "ETH", "SOL"],
    "max_order_value": "250.00",
    "max_daily_value": "1000.00"
  },
  "usage": {
    "daily_value_used": "842.60",
    "daily_value_remaining": "157.40",
    "next_release": { "at": "2026-09-27T18:02:40.000Z", "value": "250.00" }
  }
}
```

`next_release` says when the oldest order in the window leaves it, and how much room that frees. A key that has used its limit can wait until then instead of retrying.

A key with `limits: null` was created before limits existed and cannot trade. Set its limits on the account page.

## What keys cannot do

* Withdraw or move money out of the account.
* Change their own limits, or create other keys.
* Trade markets outside their list.
