Authentication

Network

The API answers only the egress IP addresses we have listed for you. A request from any other address never reaches the application, whatever key it carries. Tell us before your addresses change.

Keys

Authorization: Bearer <your key>

GET /v1/whoami needs any valid key and no scope. It answers the tenant, the key's prefix, label and scopes, and your payout wallets. If you hold keys for more than one tenant, check each key here before you use it.

Scopes

ScopeOpens
deposits:readGET /v1/deposits, GET /v1/deposit-addresses, GET /v1/deposit-xpubs
deposits:writeRegistering, deriving and retiring addresses and xpubs, watch-now, sweep holds, POST /v1/deposit-keys (also signed)
deposits:issuePOST /v1/deposit-addresses/issue: addresses whose keys we hold. Granted only by name
chain_payouts:writePOST /v1/chain-payouts, always together with a signature
chain_payouts:readGET /v1/chain-payouts/{payout_id}, payout estimates
withdrawals:writePOST /v1/withdrawals
withdrawals:readWithdrawals, destinations, the withdrawal limit, withdrawal estimates, POST /v1/payments/proof
quotes:readGET /v1/currencies, GET /v1/pairs, GET /v1/fees, GET /v1/limits, POST /v1/quotes
swaps:write / swaps:readConversions
register:readGET /v1/float, the statement, the register and its summary
events:readGET /v1/events
customers:write / customers:readRegistering your end users and their identity checks
transfers:*, accounts:*Fiat transfers and accounts

Scopes are granted in bundles, and a job that moves money gets its own key:

BundleScopes
depositsdeposits:read, deposits:write, events:read
chain_payoutschain_payouts:write, chain_payouts:read, events:read
withdrawalswithdrawals:read, withdrawals:write, register:read, events:read
swapsquotes:read, swaps:read, swaps:write, register:read, events:read
swaps_for_customersswaps plus customers:read, customers:write

Separate keys are revoked separately: pulling a payout key stops money leaving without stopping the rest of your product.

Rate limits

Per key, on a 60-second sliding window:

Per minute
Reads600
Writes (POST, PUT, PATCH, DELETE)120

Your tenant may carry a lower ceiling agreed at onboarding; it can only tighten these. Over either limit you get 429 rate_limited with a Retry-After header and detail.retry_after_seconds and detail.limit_per_minute. GET /v1/limits returns the numbers applied to your key.

Limits are counted per key, not per address.

Request ids

Every response carries X-Request-Id. Send your own and it is kept, so your logs and ours join on the same value.