Trading API
Sending your API key, what it can do, rotating and revoking keys, and rate limits.
Last updated
Every /v1 request needs your API key. There are no sessions, tokens to refresh or request signatures on a managed account: the key is the only credential.
Sending your key
Send the key in either header:
Authorization: Bearer hlk_...
X-API-Key: hlk_...curl -s https://hl-api-production-65c8.up.railway.app/v1/account -H "Authorization: Bearer $API_KEY"A missing, invalid or revoked key returns 401 with the code unauthorized.
What a key can do
A key is bound to one account, which is one Hyperliquid master address. On a managed account the key alone can:
- place, modify and cancel orders;
- change leverage;
- read positions, orders, fills and balances.
It can never withdraw or transfer funds. The trading agent that signs for you has no withdrawal permission on Hyperliquid, so neither the key nor the API can move your money.
Still, treat the key as a trading credential: anyone holding it can trade your account. Keep it in a secret manager, never in source control or client-side code, and give it only to the systems that trade.
Rotating and revoking keys
You get keys yourself: every time your master wallet signs in at markets.xyz/api-access (or through POST /v1/sign-up), a new key is issued for the same account. Older keys keep working, which makes rotation seamless:
- Create a new key.
- Deploy it to your systems.
- Ask the Markets team (support@markets.xyz) to revoke the old one.
If a key leaks, ask us to revoke it straight away. A revoked key stops working within 30 seconds. For an immediate stop, you can also revoke the trading agent yourself on Hyperliquid (see Onboarding): that blocks all trading on the account, whichever key is used.
Rate limits
Each account has a request rate limit: 10 requests per second by default, with bursts up to the same number. Every request counts, reads included. Over the limit, requests return 429 with the code rate_limited and a Retry-After header in seconds; wait that long, then retry. GET /v1/account shows your limit in rate_limit_rps, and we can raise it if your strategy needs more.
Hyperliquid applies its own per-address limits on top, which grow with your trading volume. GET /v1/rate-limit shows where you stand.
To stay well inside both:
- batch orders and cancels (up to 50 per request) rather than sending one per request;
- prefer modifying an order over cancelling and replacing it;
- cache market metadata instead of fetching it before every order.
Request ids
Every response carries an x-request-id header. Include it when you report a problem to us.