[{"data":1,"prerenderedAt":291},["ShallowReactive",2],{"docs-nav:1.0.0":3,"docs:\u002Fdocs\u002Fapi-keys":91},[4,10,14,18,22,26,30,34,38,44,48,52,55,58,61,64,67,70,73,76,80,84,87],{"path":5,"title":6,"section":7,"order":8,"generated":9},"\u002Fdocs\u002Faccount-groups","Account groups","overview",15,false,{"path":11,"title":12,"section":7,"order":13,"generated":9},"\u002Fdocs\u002Fapi-keys","API keys",20,{"path":15,"title":16,"section":7,"order":17,"generated":9},"\u002Fdocs\u002Fapi-summary","What the API covers",5,{"path":19,"title":20,"section":7,"order":21,"generated":9},"\u002Fdocs\u002Fauthentication","Authentication",25,{"path":23,"title":24,"section":7,"order":25,"generated":9},"\u002Fdocs\u002Fenvironments","Environments",10,{"path":27,"title":28,"section":7,"order":29,"generated":9},"\u002Fdocs","API documentation",1,{"path":31,"title":32,"section":7,"order":33,"generated":9},"\u002Fdocs\u002Fmaking-requests","Making requests",30,{"path":35,"title":36,"section":7,"order":37,"generated":9},"\u002Fdocs\u002Fsigned-intent","Signed order intent",27,{"path":39,"title":40,"section":41,"order":42,"generated":43},"\u002Fdocs\u002Freference\u002Faccount-groups","Reading account groups","websocket",3,true,{"path":45,"title":46,"section":47,"order":17,"generated":43},"\u002Fdocs\u002Freference\u002Favailable-instruments","Available instruments","rest",{"path":49,"title":50,"section":47,"order":51,"generated":43},"\u002Fdocs\u002Freference\u002Fbalances","Balances",8,{"path":53,"title":54,"section":47,"order":21,"generated":43},"\u002Fdocs\u002Freference\u002Fclient-withdrawals","Withdrawals",{"path":56,"title":57,"section":41,"order":33,"generated":43},"\u002Fdocs\u002Freference\u002Ferror-codes","Trade error codes",{"path":59,"title":60,"section":47,"order":21,"generated":43},"\u002Fdocs\u002Freference\u002Forder-lookup","Reading orders back",{"path":62,"title":63,"section":41,"order":25,"generated":43},"\u002Fdocs\u002Freference\u002Forder-sessions","Order sessions and recovery",{"path":65,"title":66,"section":41,"order":13,"generated":43},"\u002Fdocs\u002Freference\u002Forder-status","Order status",{"path":68,"title":69,"section":41,"order":17,"generated":43},"\u002Fdocs\u002Freference\u002Fprice-channel","Price channel",{"path":71,"title":72,"section":47,"order":13,"generated":43},"\u002Fdocs\u002Freference\u002Fsettlement-parties","Settlement parties",{"path":74,"title":75,"section":47,"order":8,"generated":43},"\u002Fdocs\u002Freference\u002Ftrades","Trades",{"path":77,"title":78,"section":47,"order":79,"generated":43},"\u002Fdocs\u002Freference\u002Ftrading-limit","Trading limit",9,{"path":81,"title":82,"section":83,"order":33,"generated":43},"\u002Fdocs\u002Freference\u002Ftransaction-codes","Transaction code tables","shared",{"path":85,"title":86,"section":47,"order":25,"generated":43},"\u002Fdocs\u002Freference\u002Ftransactions","Transactions",{"path":88,"title":89,"section":47,"order":90,"generated":43},"\u002Fdocs\u002Freference\u002Ftransfers","Internal transfers",7,{"page":92,"elsewhere":9},{"path":11,"title":12,"description":93,"body":94,"examples":290},"Creating an API key, choosing its permissions, and what to do when a secret is lost.",{"type":95,"value":96,"toc":282},"minimark",[97,101,151,158,163,206,217,221,224,254,257,261,275,279],[98,99,100],"p",{},"An API key authenticates your application to the REST and WebSocket APIs. It has\ntwo parts, and they are used very differently.",[102,103,104,120],"table",{},[105,106,107],"thead",{},[108,109,110,114,117],"tr",{},[111,112,113],"th",{},"Part",[111,115,116],{},"What it is",[111,118,119],{},"How it is used",[121,122,123,140],"tbody",{},[108,124,125,129,132],{},[126,127,128],"td",{},"API key",[126,130,131],{},"A public identifier",[126,133,134,135,139],{},"Sent on every request, in the ",[136,137,138],"code",{},"Rest-Key"," header",[108,141,142,145,148],{},[126,143,144],{},"API secret",[126,146,147],{},"A private credential",[126,149,150],{},"Signs the request. Never sent over the network",[98,152,153,154,157],{},"The secret never leaves your systems. It is used to compute a signature, and\nonly the signature travels — see ",[155,156,20],"a",{"href":19},".",[159,160,162],"h2",{"id":161},"creating-a-key","Creating a key",[164,165,166,170,180,186,197,203],"ol",{},[167,168,169],"li",{},"Sign in to the client portal for your entity and environment.",[167,171,172,173,177,178,157],{},"Open ",[174,175,176],"strong",{},"Settings",", then ",[174,179,12],{},[167,181,182,183,157],{},"Choose ",[174,184,185],{},"Create API key",[167,187,188,189,192,193,196],{},"Optionally tick ",[174,190,191],{},"Add RSA public key"," and paste one, if you intend to use\n",[155,194,195],{"href":35},"signed order intent",". This can be added or changed\nlater.",[167,198,182,199,202],{},[174,200,201],{},"Submit",", then confirm with the one-time code from your\nauthenticator.",[167,204,205],{},"The new secret appears above the key list. Copy it straight away.",[207,208,210],"caution",{"title":209},"The secret is shown once",[98,211,212,213,216],{},"It is displayed only immediately after creation and cannot be retrieved\nafterwards. If it is lost, use ",[174,214,215],{},"Reset secret"," on the key — the previous secret\nstops working immediately, so have the replacement in place before the next\ncall.",[159,218,220],{"id":219},"permissions","Permissions",[98,222,223],{},"Permissions are set on the key list, not while creating the key: a new key\nstarts with none, and you switch on what the application actually needs.",[102,225,226,236],{},[105,227,228],{},[108,229,230,233],{},[111,231,232],{},"Permission",[111,234,235],{},"Grants",[121,237,238,246],{},[108,239,240,243],{},[126,241,242],{},"Move funds",[126,244,245],{},"Moving balances between sub-accounts",[108,247,248,251],{},[126,249,250],{},"Place & manage orders",[126,252,253],{},"Executing trades over the RFS WebSocket",[98,255,256],{},"A key with neither is read-only. That is the right setting for anything that\nonly queries balances, trades or transactions.",[159,258,260],{"id":259},"changing-a-key","Changing a key",[98,262,263,264,267,268,270,271,274],{},"Each key's actions menu offers ",[174,265,266],{},"Edit"," — which changes the attached RSA public\nkey — ",[174,269,215],{},", and ",[174,272,273],{},"Delete",". Editing and resetting both require a\none-time code, the same as creation.",[159,276,278],{"id":277},"using-more-than-one-key","Using more than one key",[98,280,281],{},"Separate keys per application and per environment are worth the small overhead:\nthey let you give each system only the permissions it needs, rotate one without\ninterrupting the others, and withdraw access to one system without touching the\nrest.",{"title":283,"searchDepth":42,"depth":42,"links":284},"",[285,287,288,289],{"id":161,"depth":286,"text":162},2,{"id":219,"depth":286,"text":220},{"id":259,"depth":286,"text":260},{"id":277,"depth":286,"text":278},[],1787826505449]