API Key Creation
API Key Creation
This guide covers creating and managing API keys for programmatic access to the PRIME API.
Overview
API keys enable machine-to-machine authentication without user credentials. They are ideal for:
- Automated trading bots
- Integration with external systems
- Scheduled data retrieval
Prerequisites
- Authenticated user session (JWT token)
- 2FA enabled on the account
- Access to the email associated with the account
API Key Properties
API Key Permissions
API keys are scoped to a single sub-account with specific permissions:
Note: Read access is implicitly granted with any API key.
Step 1: Request Validation Code
Before creating an API key, you must request a validation code sent to your email.
Endpoint: POST /api/rest/v1/users/authentication/api-keys/validation
Request
Request Fields
Response (200 OK)
Empty response. A validation code is sent to your email.
Step 2: Create API Key
After receiving the validation code via email, create the API key.
Endpoint: POST /api/rest/v1/users/authentication/api-keys
Request
Request Fields
Response (201 Created)
Response Fields
Important: The secret is only returned once at creation and cannot be retrieved later. Store it securely.
Step 3: Using API Keys
API keys use HMAC-SHA256 signatures for authentication. Include the key ID and signature in request headers.
The signature is computed over the request details using the secret (decoded from hex).
Step 4: List API Keys
Endpoint: GET /api/rest/v1/users/authentication/api-keys
Request
Response (200 OK)
Note: The secret is never returned after creation.
Step 5: Delete API Key
Endpoint: DELETE /api/rest/v1/users/authentication/api-keys/{keyId}
Request
Response (200 OK)
Empty response on success.
Security Best Practices
- Minimum Permissions: Only grant necessary permissions
- Secret Storage: Never commit secrets to version control
- Rotation: Regularly delete and recreate API keys
- Single Purpose: Create separate keys for different applications
Error Scenarios
Related
- Authentication - JWT-based authentication
- Getting Started: Authentication - Full auth documentation