Skip to main content
The auth service issues and verifies the two credentials the rest of the API accepts, and mints the short-lived tickets used to open websockets. See Authentication for the signing scheme and worked examples.

Endpoints

Scopes

Keys carry read, trade, and withdraw. Password sessions are capped at read and trade, so a session can never mint a withdraw-scoped key.