MMashDiv

API reference — what the app calls

The server routes the app calls, grouped by area, the headers it sends and reads back, its eleven WebSocket paths and which need a signed-in session, and the products and actions your server refuses to the app whatever its settings.

2 min readUpdated 26 September 2026reference, api, websockets, headers, native-app, routes

Lookup material for proxies, firewalls, logs and support questions. For what the settings behind these routes do, see Server settings.

Every REST path below is requested from the host in baseUrl, and every socket from the host in wsBaseUrl. Apart from the Stripe, Google sign-in and Firebase libraries, which talk to their own services, and web pages a customer opens from a link, the app sends its requests to your server. It calls no /api/admin route.

Headers

What the app sends:

Header Sent on Value
platform Every HTTP request, and the upgrade of each signed-in WebSocket mobile. Marks the request as the app's; see Server settings
accesstoken Every request while signed in The access token. This is the header the backend authenticates from
sessionid Every request while signed in The session ID. The server renews the access token from it
csrftoken Every request while signed in The session's CSRF token, required on POST, PUT, PATCH and DELETE
Authorization Every request while signed in Bearer <access token>. Sent, but the backend's session check reads accesstoken
X-CSRF-Token Every request while signed in A copy of csrftoken
client-device-id POST /api/auth/logout only The same per-account device id the app registered for push, so the server stops push to this phone for this account. Left out when the phone has none

Signed-in WebSocket upgrades carry platform, accesstoken, sessionid and csrftoken as headers. The public market sockets are opened with none of them. The app uses no cookies.

What the app reads back:

  • Sign-in responses carry the credentials in the JSON body, because the request is from the app. The app stores them on the phone.
  • Renewed credentials arrive as the response headers accessToken, csrfToken and sessionId on any request where the server renewed them. The app stores any value that changed.
  • A 401, or a 200 whose body says statusCode: 401, ends the app's session only when the message says the session is gone (Authentication Required..., Session expired, Session not found and similar). Any other 401, such as a wrong code, PIN or password, is shown where it was typed and the customer stays signed in.

Refusals any route can give

Status and message Cause
401 Authentication Required A signed-in route called with neither accesstoken nor sessionid, or after the session has ended
403 CSRF Token or Session ID missing / Invalid CSRF Token / Invalid Session A POST, PUT, PATCH or DELETE without a valid csrftoken and sessionid
404 Not found The route belongs to an add-on that is switched off
403 This feature requires a valid license for <extension>. Please activate your license to continue. The add-on is not licensed
429 Rate Limit Exceeded, Try Again Later The per-address limit on POST, PUT, PATCH and DELETE; see rate limits
403 with the geo notice The request comes from a country your Geo Restrictions block
503 Service temporarily unavailable. Maintenance in progress. The platform is stopped and the maintenance server is answering

Sign-in and session

POST/api/auth/login/flutter
Email and password sign-in. No captcha. Answers with the credentials in the body, or with a two-factor challenge.
POST/api/auth/login/google
Google sign-in for an account already linked to Google. It signs in; it does not create accounts. Answers with the credentials in the body, or with the same two-factor challenge as a password sign-in.
POST/api/auth/otp/login
Completes a sign-in that asked for two-factor, with a six-digit code or a recovery code. The app strips spaces from a recovery code before sending it.
POST/api/auth/otp/resend
Sends the sign-in code again by email or SMS.
POST/api/auth/logout
Signs out and ends the session on the server. Carries client-device-id, which also stops push to that phone for that account.
GET/api/auth/pow/challenge
A proof-of-work challenge for sign-up or password reset, asked with action=register or action=reset immediately before that request. Also reports which captcha provider the server uses.
POST/api/auth/register
Creates an account. Runs the server's captcha; under proof-of-work the app sends its solution as powSolution.
POST/api/auth/reset
Sends the password-reset email. Runs the server's captcha; under proof-of-work the app sends its solution as powSolution. Change Password in the app uses this too.

Account

GET/api/user/modules
Which features this customer may use, and why each hidden one is hidden. Read at sign-in and at start-up.
GET/api/settings
Every public setting. Needs no sign-in. Read at start-up and every five minutes.
GET/api/user/profile
The customer's profile.
PUT/api/user/profile
Updates the profile.
GET/api/user/profile/username
Whether a username is free.
POST/api/user/profile/otp/secret
Two-factor setup, step 1: a new secret and QR code, or an SMS code.
POST/api/user/profile/otp/verify
Two-factor setup, step 2: checks a code against the new secret.
POST/api/user/profile/otp
Two-factor setup, step 3: saves it and issues recovery codes.
POST/api/user/profile/otp/status
Turns the account's two-factor on or off.
GET/api/user/profile/transfer-pin
Transfer PIN status.
POST/api/user/profile/transfer-pin
Sets or changes the transfer PIN.
DELETE/api/user/profile/transfer-pin
Removes the transfer PIN.
GET/api/user/account/delete
What stands in the way of deleting the account, and what deletion removes and keeps.
POST/api/user/account/delete
Deletes the account after the password is confirmed, and ends every session.
POST/api/user/push/subscribe
Registers the phone for push notifications: type fcm, the token, platform android or ios, and a deviceId for this account on this phone. The deviceId is what makes the server switch push on for a customer who never chose.
POST/api/user/push/unsubscribe
Removes the phone's push token, at sign-out.
POST/api/user/report
Reports a blog comment or a support ticket to your moderators.

Identity verification

GET/api/user/kyc/level
The KYC levels.
GET/api/user/kyc/level/{id}
One KYC level and its form.
GET/api/user/kyc/application
The customer's applications.
POST/api/user/kyc/application
Submits an application.
GET/api/user/kyc/application/{id}
One application.
PUT/api/user/kyc/application/{id}
Updates an application.
POST/api/upload/kyc-document
Uploads one document, as base64 in JSON, up to 10 MB. Stored privately.

Notifications

GET/api/user/notification
The customer's notifications.
DELETE/api/user/notification
Deletes all of them.
POST/api/user/notification/mark-all-read
Marks all as read.
POST/api/user/notification/{id}/read
Marks one as read.
POST/api/user/notification/{id}/unread
Marks one as unread.
DELETE/api/user/notification/{id}
Deletes one.

Content and support

GET/api/news
Market news from your own feed, or the CryptoCompare proxy. Needs no sign-in.
GET/api/news/article/{id}
One news article.
GET/api/content/default-page/{pageId}
The Terms of Service or Privacy Policy text, with pageId terms or privacy. Needs no sign-in.
GET/api/faq
Help centre questions.
GET/api/user/support/ticket
The customer's support tickets.
POST/api/user/support/ticket
Opens a ticket.
GET/api/user/support/ticket/{id}
One ticket.
POST/api/user/support/ticket/{id}
Replies to a ticket.
PUT/api/user/support/ticket/{id}/close
Closes a ticket.
PUT/api/user/support/ticket/{id}/review
Rates a ticket.
GET/api/user/support/chat
The live chat session, created if the customer has none open.
POST/api/user/support/chat
Sends a live chat message.
DELETE/api/user/support/chat
Ends the live chat session.

The blog screens read /api/blog/post, /api/blog/post/{slug}, /api/blog/category, /api/blog/tag and /api/blog/author (and its top, all and {id} forms), read and post comments at /api/blog/comment/{postId}, and send an author application with POST /api/blog/author.

Markets and trading

GET/api/exchange/market
The market list. The app asks with eco=true, which returns exchange and ecosystem markets together. Read at start-up; a 503 here raises the maintenance banner.
GET/api/exchange/ticker
Tickers for all exchange markets.
GET/api/exchange/ticker/{currency}/{pair}
The ticker for one pair.
GET/api/exchange/chart
Candles for an exchange market.
GET/api/ecosystem/chart
Candles for an ecosystem market.
GET/api/exchange/order
The customer's exchange orders.
POST/api/exchange/order
Places an exchange order. Gated by licence attestations when enforced (Spot trading).
DELETE/api/exchange/order/{id}
Cancels an exchange order.
GET/api/ecosystem/order
The customer's ecosystem orders.
POST/api/ecosystem/order
Places an ecosystem order. Gated as Spot trading when attestations are enforced.
DELETE/api/ecosystem/order/{id}
Cancels an ecosystem order. The app also sends the order's creation time as the optional timestamp query parameter, which lets the server find the order directly.

Futures screens use GET /api/futures/market, GET /api/futures/chart, GET and POST /api/futures/order, DELETE /api/futures/order/{id}, GET /api/futures/position and DELETE /api/futures/position/{id}. See the Futures API.

Wallets, deposits, withdrawals and transfers

GET/api/finance/wallet
The customer's wallets.
GET/api/finance/wallet/stats
Wallet totals.
GET/api/finance/wallet/symbol
One wallet's details, by symbol.
GET/api/finance/wallet/{type}/{currency}
One wallet by type and currency.
GET/api/finance/wallet/transfer-options
Where a transfer can go.
GET/api/finance/currency
Currencies by wallet type.
GET/api/finance/currency/{type}/{code}
One currency's deposit or withdrawal details, by wallet type.
GET/api/finance/currency/{type}/{code}/{method}
One currency on one network or method, including the spot deposit address.
GET/api/finance/currency/price
A currency's price.
GET/api/finance/currency/valid
Currencies with their current rates.
GET/api/finance/transaction
Transaction history.
GET/api/finance/transaction/{id}
One transaction.

Deposits

POST/api/finance/deposit/spot
Claims a spot deposit by its transaction hash.
GET/api/finance/deposit/spot/intent
The customer's open spot deposit declarations.
POST/api/finance/deposit/spot/intent
Declares a spot deposit before the coins are sent.
POST/api/finance/deposit/spot/intent/{id}/cancel
Cancels a declaration.
POST/api/finance/deposit/fiat
A fiat deposit through one of your custom deposit methods.
POST/api/finance/deposit/fiat/stripe
Starts a Stripe card deposit.
POST/api/finance/deposit/fiat/stripe/verify-intent
Confirms a Stripe payment.
POST/api/finance/deposit/fiat/paypal
Starts a PayPal deposit.
POST/api/finance/deposit/fiat/paypal/verify
Confirms a PayPal payment.
GET/api/ecosystem/wallet/{currency}
An ecosystem wallet by currency, issuing its deposit address if it has none yet.

Withdrawals

GET/api/finance/withdraw/verification
The withdrawal two-factor policy for this customer.
POST/api/finance/withdraw/verification
Sends a withdrawal code on the customer's channel.
POST/api/finance/withdraw/verification/verify
Exchanges the code for a single-use token that goes with the withdrawal.
POST/api/finance/withdraw/spot
A spot withdrawal.
POST/api/finance/withdraw/fiat
A fiat withdrawal.
POST/api/ecosystem/withdraw
An ecosystem withdrawal.
GET/api/ecosystem/withdraw/max
The most that can be withdrawn on one chain, and the network fee.

Transfers

GET/api/finance/transfer/validate
Checks a transfer's recipient before the transfer is sent.
GET/api/finance/transfer/verification
The transfer verification policy: PIN or two-factor, and whether the PIN is locked.
POST/api/finance/transfer/verification
Sends a transfer code, when the policy uses two-factor.
POST/api/finance/transfer/verification/verify
Exchanges a PIN or code for a single-use token bound to the recipient.
POST/api/finance/transfer
Makes the transfer.

Add-ons

Each add-on's routes answer only while the add-on is installed, switched on and licensed. The full route lists are in each add-on's own reference.

Add-on What the app calls Reference
P2P /api/p2p/offer, /api/p2p/trade (confirm, release, cancel, dispute, evidence, appeal, messages, review), /api/p2p/payment-method, /api/p2p/market/*, /api/p2p/dashboard/*, /api/p2p/guided-matching, /api/p2p/trader/*, /api/p2p/location, /api/p2p/cryptocurrencies P2P API
Staking /api/staking/pool, /api/staking/position, /api/staking/stats, /api/staking/statements, /api/staking/real/quote Staking API
Token offerings /api/ico/offer, /api/ico/plan, /api/ico/blockchain, /api/ico/token/type, /api/ico/stats, /api/ico/portfolio, /api/ico/transaction ICO API
Store /api/ecommerce/product, /api/ecommerce/category, /api/ecommerce/order, /api/ecommerce/wishlist, /api/ecommerce/review, /api/ecommerce/shipping, /api/ecommerce/discount/validate, /api/ecommerce/download E-commerce API
Merchant GET /api/gateway/merchant, /api/gateway/balance, /api/gateway/payment, /api/gateway/payout, /api/gateway/api-key; POST /api/gateway/merchant; POST /api/gateway/payment/{id}/refund Payment gateway API
AI Investment /api/ai/investment/plan, /api/ai/investment/log AI Investments API
Affiliate /api/affiliate, /api/affiliate/network, /api/affiliate/referral, /api/affiliate/reward, /api/affiliate/condition MLM API and data
Bot console GET /api/hb/console, POST /api/hb/console/panic, GET /api/hb/keys, DELETE /api/hb/keys/{id}, POST /api/hb/keys/{id}/disable and /enable Hummingbot API

WebSockets

Eleven paths, each opened on wsBaseUrl. The signed-in ones check the session at the upgrade, from the headers above. Their ?userId= query is not used to identify the customer.

Path Sign-in Carries
/api/exchange/ticker no Tickers for exchange markets
/api/exchange/market no One exchange market's live data, such as its order book and candles
/api/ecosystem/ticker no Tickers for ecosystem markets
/api/ecosystem/market no One ecosystem market
/api/futures/market no Futures market data
/api/user yes Notifications and the Home announcements
/api/user/support/ticket yes Support ticket replies
/api/exchange/order yes The customer's open orders
/api/finance/deposit/spot yes A spot deposit being confirmed, by transaction hash
/api/finance/deposit/spot/intent yes A declared spot deposit being matched
/api/ecosystem/deposit yes Ecosystem deposits arriving

On an install without the Ecosystem add-on, the ecosystem ticker socket closes straight away. The app stops retrying it after a few attempts; spot tickers are unaffected. Every socket goes through the same geo check as other requests.

What the server refuses to the app

These are refused with a 403 to any request marked as the app's, whatever your settings. The website is unaffected.

Product or action Routes Message
Binary options Placing a binary order, and the binary settings, markets, durations and leaderboards (/api/exchange/binary/...) Binary options trading is not available in the mobile app. Google Play prohibits it outright and Apple treats it as gambling.
Forex investment plans POST /api/forex/investment Forex investment plans are not available in the mobile app. The plan result is set by an operator rather than by the market, which app-store rules on financial products do not permit.
Launching a token Every creator route (/api/ico/creator/...) Launching a token is not available in the mobile app. The launch fee is charged to a platform wallet, and app-store rules bar a cryptocurrency balance from being used to unlock a feature.
The strategy marketplace Every marketplace route (/api/trading-bot/marketplace/...) Trading strategies cannot be bought or sold in the mobile app. You can still create, configure and run your own bots here.
Creating, rotating or re-scoping an API key POST /api/hb/keys, PUT /api/hb/keys/{id}, POST /api/hb/keys/{id}/rotate API keys are managed on the web. The app can disable or delete a key and stop a running bot, but a new key and its secret are only ever issued in a browser. Sign in on the web to create, rotate or re-scope one.

Two more are refused while Allow AI Investment & MLM in the Mobile App is off, and served when it is on:

Product Routes Message while off
AI Investment The plan list and every investment route (/api/ai/investment/plan, /api/ai/investment/log/...) AI Investment is not available in the mobile app. It offers a fixed return over a fixed duration funded from a custodial wallet, which app-store rules on financial products do not permit.
The referral (MLM) programme Claiming a referral reward (POST /api/affiliate/reward/{id}/claim) The multi-level referral programme is not available in the mobile app. App-store rules bar a cryptocurrency app from offering currency for recruiting other users.

While the switch is off, the feature list the app loads also marks both as unavailable, so the app does not offer their screens.

With Enforce Licence Attestations (Mobile App) on, nine more are refused per country; see Licence attestations.