Docs
API keys

Create a key

POST
/v1/api-keys

Returns the key in key, once. We cannot show a key again after creation, or recover it. A lost key is replaced, not recovered.

admin and keys:manage cannot be granted here. Issue narrow keys: an integration that only reads positions should hold trading:read and nothing else.

Authorization

apiKey
AuthorizationBearer <token>

Authorization: Bearer fx_live_<id>_<secret>.

A key is shown once, at creation. We cannot show it again or recover it for you. Keys carry an environment (live or test) in the key itself, so a test key pasted into a production config fails immediately instead of at the worst possible moment.

Scopes are per key. A key without accounts:write can read accounts and nothing else.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/v1/api-keys" \  -H "Content-Type: application/json" \  -d '{    "name": "Production trading server",    "scopes": [      "accounts:read"    ]  }'
{  "data": {    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",    "name": "string",    "publicId": "string",    "hint": "string",    "environment": "live",    "scopes": [      "string"    ],    "lastUsedAt": null,    "expiresAt": null,    "revokedAt": null,    "createdAt": "2019-08-24T14:15:22Z",    "key": "string"  }}