Skip to main content
POST
POST /accounts creates an API account and returns its API key ID (apiKey) and secret key (secretKey). The password you send becomes the account’s passphrase. You sign every request to the signed endpoints with these three values, as described in Sign requests. This endpoint is public: it takes no signed headers.

What you get back

The account can call signed endpoints as soon as this call returns. There is no activation step. Credentials covers how the three values work together.

Choose the passphrase

  • Use at least 24 random characters from a password manager. The API accepts 8 or more, but the passphrase guards your account as much as the secret key does.
  • Use printable ASCII only, with no leading or trailing spaces. The API trims the x-passphrase header, and browsers can’t send characters outside ISO-8859-1. A passphrase with leading or trailing spaces, or with characters a client can’t send in a header, creates an account you can’t sign requests for. Printable ASCII avoids both.
  • Protect it like the secret key. Every signed request carries it in x-passphrase, so anything that logs request headers can capture it.
  • name is only a label. It needs at least 6 characters, and names don’t have to be unique.
A name shorter than 6 characters or a password shorter than 8 fails with 400 VALIDATION_ERROR, and the detail reads "name is required" or "password is required" even when the field is present.

Store the credentials right away

The secret key appears in this response and nowhere else. Olympex stores only a hash of the passphrase and an encrypted copy of the secret key, and no endpoint returns either one again. Write all three values to your secrets manager before you do anything else, and keep the response out of logs, tickets and chat. The 200 example on this page shows the API key ID and the secret key of the known-answer vectors, which are test values, not a real account. Your secret key is a different random string.
Credentials can’t be rotated or changed after you create them. If any of the three values leaks, email partners@olympex.io to deactivate the account, then create a new one and switch your integration to it.

Test and production accounts

The console on this page creates a real account with a passphrase generated in your browser. Use it to try the API. If your browser blocks the call, use the cURL example on this page or create a key from a terminal. For production, create a separate account from a machine you control, with a passphrase from your password manager, and load the credentials from your secrets manager at runtime. There is no sandbox: both accounts call the same production API. Limit orders and DCA strategies created with either account are real orders, and only the account that created them can read, change or cancel them. Going to production has the full checklist.
Every successful call creates a new account. If a request fails before you read the response, an account may already exist whose secret key you never saw. Create another one by hand (names don’t have to be unique), and never retry this call automatically.

Body

application/json
name
string
required

Label for the account, at least 6 characters. Names don't have to be unique.

Minimum string length: 6
Example:

"acme-trading-desk"

password
string
required

Becomes the account passphrase, sent as x-passphrase on every signed request. Use at least 24 random printable-ASCII characters with no leading or trailing spaces: the API trims the header, and browsers can't send characters outside ISO-8859-1, so other values create an account you can't use.

Minimum string length: 8

Response

Account created. The account can call signed endpoints immediately.

success
enum<boolean>
required
Available options:
true
data
object
required
meta
object
required