API reference — what the app calls
The server routes the app calls, grouped by area, the headers it sends and reads back, its eleven WebSocket paths and which need a signed-in session, and the products and actions your server refuses to the app whatever its settings.
Lookup material for proxies, firewalls, logs and support questions. For what the settings behind these routes do, see Server settings.
Every REST path below is requested from the host in baseUrl, and every socket
from the host in wsBaseUrl. Apart from the Stripe, Google sign-in and Firebase
libraries, which talk to their own services, and web pages a customer opens
from a link, the app sends its requests to your server. It calls no
/api/admin route.
Headers
What the app sends:
| Header | Sent on | Value |
|---|---|---|
platform |
Every HTTP request, and the upgrade of each signed-in WebSocket | mobile. Marks the request as the app's; see Server settings |
accesstoken |
Every request while signed in | The access token. This is the header the backend authenticates from |
sessionid |
Every request while signed in | The session ID. The server renews the access token from it |
csrftoken |
Every request while signed in | The session's CSRF token, required on POST, PUT, PATCH and DELETE |
Authorization |
Every request while signed in | Bearer <access token>. Sent, but the backend's session check reads accesstoken |
X-CSRF-Token |
Every request while signed in | A copy of csrftoken |
client-device-id |
POST /api/auth/logout only |
The same per-account device id the app registered for push, so the server stops push to this phone for this account. Left out when the phone has none |
Signed-in WebSocket upgrades carry platform, accesstoken, sessionid and
csrftoken as headers. The public market sockets are opened with none of
them. The app uses no cookies.
What the app reads back:
- Sign-in responses carry the credentials in the JSON body, because the request is from the app. The app stores them on the phone.
- Renewed credentials arrive as the response headers
accessToken,csrfTokenandsessionIdon any request where the server renewed them. The app stores any value that changed. - A 401, or a
200whose body saysstatusCode: 401, ends the app's session only when the message says the session is gone (Authentication Required...,Session expired,Session not foundand similar). Any other 401, such as a wrong code, PIN or password, is shown where it was typed and the customer stays signed in.
Refusals any route can give
| Status and message | Cause |
|---|---|
401 Authentication Required |
A signed-in route called with neither accesstoken nor sessionid, or after the session has ended |
403 CSRF Token or Session ID missing / Invalid CSRF Token / Invalid Session |
A POST, PUT, PATCH or DELETE without a valid csrftoken and sessionid |
404 Not found |
The route belongs to an add-on that is switched off |
403 This feature requires a valid license for <extension>. Please activate your license to continue. |
The add-on is not licensed |
429 Rate Limit Exceeded, Try Again Later |
The per-address limit on POST, PUT, PATCH and DELETE; see rate limits |
| 403 with the geo notice | The request comes from a country your Geo Restrictions block |
503 Service temporarily unavailable. Maintenance in progress. |
The platform is stopped and the maintenance server is answering |
Sign-in and session
Account
Identity verification
Notifications
Content and support
The blog screens read /api/blog/post, /api/blog/post/{slug},
/api/blog/category, /api/blog/tag and /api/blog/author (and its top,
all and {id} forms), read and post comments at /api/blog/comment/{postId},
and send an author application with POST /api/blog/author.
Markets and trading
Futures screens use GET /api/futures/market, GET /api/futures/chart,
GET and POST /api/futures/order, DELETE /api/futures/order/{id},
GET /api/futures/position and DELETE /api/futures/position/{id}. See the
Futures API.
Wallets, deposits, withdrawals and transfers
Deposits
Withdrawals
Transfers
Add-ons
Each add-on's routes answer only while the add-on is installed, switched on and licensed. The full route lists are in each add-on's own reference.
| Add-on | What the app calls | Reference |
|---|---|---|
| P2P | /api/p2p/offer, /api/p2p/trade (confirm, release, cancel, dispute, evidence, appeal, messages, review), /api/p2p/payment-method, /api/p2p/market/*, /api/p2p/dashboard/*, /api/p2p/guided-matching, /api/p2p/trader/*, /api/p2p/location, /api/p2p/cryptocurrencies |
P2P API |
| Staking | /api/staking/pool, /api/staking/position, /api/staking/stats, /api/staking/statements, /api/staking/real/quote |
Staking API |
| Token offerings | /api/ico/offer, /api/ico/plan, /api/ico/blockchain, /api/ico/token/type, /api/ico/stats, /api/ico/portfolio, /api/ico/transaction |
ICO API |
| Store | /api/ecommerce/product, /api/ecommerce/category, /api/ecommerce/order, /api/ecommerce/wishlist, /api/ecommerce/review, /api/ecommerce/shipping, /api/ecommerce/discount/validate, /api/ecommerce/download |
E-commerce API |
| Merchant | GET /api/gateway/merchant, /api/gateway/balance, /api/gateway/payment, /api/gateway/payout, /api/gateway/api-key; POST /api/gateway/merchant; POST /api/gateway/payment/{id}/refund |
Payment gateway API |
| AI Investment | /api/ai/investment/plan, /api/ai/investment/log |
AI Investments API |
| Affiliate | /api/affiliate, /api/affiliate/network, /api/affiliate/referral, /api/affiliate/reward, /api/affiliate/condition |
MLM API and data |
| Bot console | GET /api/hb/console, POST /api/hb/console/panic, GET /api/hb/keys, DELETE /api/hb/keys/{id}, POST /api/hb/keys/{id}/disable and /enable |
Hummingbot API |
WebSockets
Eleven paths, each opened on wsBaseUrl. The signed-in ones check the session
at the upgrade, from the headers above. Their ?userId= query is not used to
identify the customer.
| Path | Sign-in | Carries |
|---|---|---|
/api/exchange/ticker |
no | Tickers for exchange markets |
/api/exchange/market |
no | One exchange market's live data, such as its order book and candles |
/api/ecosystem/ticker |
no | Tickers for ecosystem markets |
/api/ecosystem/market |
no | One ecosystem market |
/api/futures/market |
no | Futures market data |
/api/user |
yes | Notifications and the Home announcements |
/api/user/support/ticket |
yes | Support ticket replies |
/api/exchange/order |
yes | The customer's open orders |
/api/finance/deposit/spot |
yes | A spot deposit being confirmed, by transaction hash |
/api/finance/deposit/spot/intent |
yes | A declared spot deposit being matched |
/api/ecosystem/deposit |
yes | Ecosystem deposits arriving |
On an install without the Ecosystem add-on, the ecosystem ticker socket closes straight away. The app stops retrying it after a few attempts; spot tickers are unaffected. Every socket goes through the same geo check as other requests.
What the server refuses to the app
These are refused with a 403 to any request marked as the app's, whatever your settings. The website is unaffected.
| Product or action | Routes | Message |
|---|---|---|
| Binary options | Placing a binary order, and the binary settings, markets, durations and leaderboards (/api/exchange/binary/...) |
Binary options trading is not available in the mobile app. Google Play prohibits it outright and Apple treats it as gambling. |
| Forex investment plans | POST /api/forex/investment |
Forex investment plans are not available in the mobile app. The plan result is set by an operator rather than by the market, which app-store rules on financial products do not permit. |
| Launching a token | Every creator route (/api/ico/creator/...) |
Launching a token is not available in the mobile app. The launch fee is charged to a platform wallet, and app-store rules bar a cryptocurrency balance from being used to unlock a feature. |
| The strategy marketplace | Every marketplace route (/api/trading-bot/marketplace/...) |
Trading strategies cannot be bought or sold in the mobile app. You can still create, configure and run your own bots here. |
| Creating, rotating or re-scoping an API key | POST /api/hb/keys, PUT /api/hb/keys/{id}, POST /api/hb/keys/{id}/rotate |
API keys are managed on the web. The app can disable or delete a key and stop a running bot, but a new key and its secret are only ever issued in a browser. Sign in on the web to create, rotate or re-scope one. |
Two more are refused while Allow AI Investment & MLM in the Mobile App is off, and served when it is on:
| Product | Routes | Message while off |
|---|---|---|
| AI Investment | The plan list and every investment route (/api/ai/investment/plan, /api/ai/investment/log/...) |
AI Investment is not available in the mobile app. It offers a fixed return over a fixed duration funded from a custodial wallet, which app-store rules on financial products do not permit. |
| The referral (MLM) programme | Claiming a referral reward (POST /api/affiliate/reward/{id}/claim) |
The multi-level referral programme is not available in the mobile app. App-store rules bar a cryptocurrency app from offering currency for recruiting other users. |
While the switch is off, the feature list the app loads also marks both as unavailable, so the app does not offer their screens.
With Enforce Licence Attestations (Mobile App) on, nine more are refused per country; see Licence attestations.