PhoenixPerpetualsDocs API v1
Get an API key

Get started

Keys and limits⁠.

API keys, the two environments, what a key may and may never do, and the limits you can put on each one.

View as Markdown

On this page
  1. Two environments
  2. Read, or read and trade
  3. Limits you can set on a key
  4. Expiry and rotation
  5. What a key can never do
  6. Keeping keys safe
  7. When a key is refused

Every request carries one API key in the Authorization header. You create keys in your dashboard, under Developers, and you decide there exactly what each one may do.

curl https://api.phoenixperpsfunding.com/v1/me \
  -H "Authorization: Bearer $PHOENIXPERPS_API_KEY"

GET /v1/me answers with what the key you are calling with may do: its environment, access, accounts, limits and rate budget. Call it first when something is refused and you are not sure why.

Two environments#

A key belongs to one environment for life, and its prefix says which:

PrefixHostReaches
ppk_live_api.phoenixperpsfunding.comYour evaluation and funded accounts
ppk_test_sandbox-api.phoenixperpsfunding.comYour sandbox accounts

You can hold up to 5 active keys in each environment. A key used on the other host is refused with 401 wrong_environment, and the message names the right host.

Read, or read and trade#

Read keys see accounts, risk, positions, orders, fills, history and market data. Read and trade keys can also place, change and cancel orders, close positions and run server-side strategies. Give a dashboard or a journal a read key: it then cannot trade, whatever happens to it.

Limits you can set on a key#

Each key can carry its own guard rails. They are checked before an order reaches the engine, and they hold even if your code has a bug.

  • Accounts: all your accounts in the environment, or only the ones you pick. A key limited to one account does not follow it when that account is reset or funded.
  • Markets: only the markets you list.
  • Reduce-only: the key can close and shrink positions, never open or grow them.
  • Max order and max position, in dollars of notional.
  • Daily loss stop: when the account loses this much in the day, the key flattens the account, cancels its orders and stops trading on it until midnight New York.
  • IP allowlist: up to 10 addresses or ranges. A request from anywhere else is refused with 403 ip_not_allowed.
  • Rate budget: a lower request rate than the default, for a key you hand to something you trust less.

Expiry and rotation#

Live keys expire after 90 days unless you pick another length, up to 365 days. A live key that never expires needs an IP allowlist. We email you 7 days before a key expires. Sandbox keys never expire unless you choose a date.

Creating a live key takes a code we email you, valid 10 minutes. Sandbox keys need none.

What a key can never do#

Whatever its access, a key cannot withdraw money or ask for a payout, change your password or email, read your trading platform login, or create keys, TradingView links or webhook endpoints. Those stay in your dashboard, behind your password.

Keeping keys safe#

  • Keep the key in an environment variable or a secret store, never in your code or a repository.
  • Never put a key in a web page or a mobile app: anyone could read it there.
  • One key per bot or tool. When one is exposed, revoke it in the dashboard; it stops working at once, and nothing else is affected.
  • Never share a key with another person or service. Letting someone else trade your account breaks the API terms.

When a key is refused#

CodeStatusMeaning
missing_api_key401No Authorization header
invalid_api_key401Unknown or mistyped key
expired_api_key401The key passed its expiry date
revoked_api_key401The key was revoked
wrong_environment401A live key on the sandbox host, or the reverse
ip_not_allowed403The request came from outside the allowlist
insufficient_permission403A read key tried to trade

Every code is in the error catalogue.

Guides, endpoints, fields and error codes.