requestId, or check your own signer against headers you know are correct.
If your browser blocks the request, use Copy as cURL to send the same signed request from a terminal. PATCH and DELETE requests may need it. To create a key without the browser, see Create a test API key.
You need an API key ID, a secret key and a passphrase. No key yet? Create a test API key on this page.
Explore safely
The console runs on a page hosted by Mintlify that loads analytics. Treat anything you type here as visible to the page. A test key calls the same production API as any other key. Quotes use live prices,POST /swap returns real mainnet calldata, and the limit orders and DCA strategies you create are real orders.
Creating a limit order or a DCA strategy needs the maker wallet’s signature for the token pair. The create examples start with a placeholder signature, and Send request and Copy as cURL stay disabled until signature is a 65-byte hex signature (0x and 130 hexadecimal characters). Click Sign with wallet: your browser wallet signs the pair, and the console fills in accountTo with the wallet’s address and signature with its signature. Signing doesn’t grant an allowance or move funds. Without a browser wallet, sign the pair with your own tooling, as shown in Order signatures and allowances, and paste the signature. Olympex doesn’t check the signature when you create an order: a wrong signature is accepted, and the order fails at execution. To try POST /dca-order/strategies without scheduling orders, add "status": "cancelled" to the body: the strategy is created stopped. Cancel what you don’t need: a limit order with DELETE /limit-order/{id}, a DCA strategy with PATCH /dca-order/strategies/{id} and {"status":"cancelled"}.
The console keeps the secret key and the passphrase in this tab’s memory only, and masks them on screen until you choose to show them, for example with Reveal on a key you just created.
- Enter your credentials once: every console on this site uses them, including the Try it panel on each signed endpoint page, until you reload.
- The response panel hides credential values, such as
passphrase,passwordandsecretKeyfields. - Copy as cURL never includes your passphrase. The copied command reads it from
$OLYMPEX_PASSPHRASE, and stops with a message before it sends anything if the variable isn’t set.
Send a request
1
Add your credentials
Enter your API key ID, secret key and passphrase, or open No key yet? Create a test API key to create one without leaving the console.
2
Choose an endpoint and an example
Pick an endpoint, then an example. Fill in the path and query parameters, such as an order ID or
chainId. For POST and PATCH, edit the JSON body as you like: the console sends it as canonical JSON (keys sorted, no whitespace), which is exactly what bodyHash covers. The signature also covers the method, the path and the query. For POST /limit-order and POST /dca-order/strategies, click Sign with wallet before you send.3
Send the request
Click Send request. The console signs the method, the path, the query and the body, or the empty string for
GET and DELETE, with a new timestamp and nonce, calls the API, and shows the response.4
Reuse it outside the browser
Click Copy as cURL to run the same signed request from a terminal. See Copy as cURL.
POST /accounts is available through Create a test API key.
IDs fill in for you
Endpoints with{id} in the path have an ID field. You don’t have to copy IDs by hand: when a create or list response returns a limit order, a DCA strategy or a DCA order, the console fills its ID into the ID field of every console for that resource, until you reload.
A list fills in the ID of its first item. Check the ID before you send a
PATCH or DELETE.
Read the response
- Status line. The HTTP status, the round-trip time, and
meta.requestIdwhen Olympex answered. Gateway response marks amessage-only body from the API gateway. Conventions explains each one. - Filled-in ID. When the response filled in an ID for other consoles, a line under the status names it.
- Hint. For an error, a one-line explanation of the likely cause and the fix.
- Body. The full response, with credential fields hidden.
requestId of any response you want to ask about: support needs it to find your request. A Gateway response has no requestId, and the browser can’t read the apigw-requestid header that identifies it. Click Copy as cURL, add -i right after curl so that curl prints the response headers, and run the command in a terminal. Send support the apigw-requestid value from that response, with the time of the request in UTC.
Create a test API key
This creates a real API account withPOST /accounts. It suggests a name (docs-test- and eight random hexadecimal characters) that you can change, and generates a 32-character random passphrase in your browser.
When the account is created, the console shows the API key ID, the secret key, the passphrase and the request’s requestId, and loads them into every console on this site until you reload. Copy as .env and Download .env give you the three OLYMPEX_* variables that the reference signers read.
If the browser blocks the call, the console shows a terminal command that creates the same account, with the name exactly as you entered it. The command prompts for the passphrase without echoing it: copy the generated passphrase with its own button and paste it at the prompt, so it stays out of the command and your shell history. The response, secret key included, prints in your terminal: store the credentials right away, then clear the terminal. Create a test API key covers creating credentials from a terminal and storing them.
Copy as cURL
Copy as cURL signs the current request and copies acurl command for bash or zsh, with the method, the path and query string, and the body for POST and PATCH. PATCH and DELETE requests may need it: if your browser blocks the request, run the copied command from a terminal.
The command carries the signed headers as literals and reads your passphrase from the environment, so set OLYMPEX_PASSPHRASE first. If it isn’t set, the command stops with set OLYMPEX_PASSPHRASE first before it sends anything. Setting it this way keeps the passphrase off the screen and out of your shell history:
apigw-requestid, add -i right after curl (curl -i -sS …), or -D - in the same place.
Signing details
After you send or copy a request, Signing details lists every value the console computed, so you can compare them with your own signer:
The passphrase is sent as
x-passphrase and is not shown. To compare, sign the same method, URL and body with the same credentials, timestamp and nonce in your code:
Use a fixed timestamp and nonce only to compare values. Don’t send a request signed this way: the server rejects a nonce it has already seen and a timestamp older than 300 seconds.
To test a signer without any credentials, use the known-answer vectors in Sign requests.
Troubleshooting
What’s next
Sign requests
Move from the console to signed requests in your own code.
Create a test API key
Create credentials from a terminal and store them safely.
Errors and retries
What each error means and when to retry.
Conventions
Units, chain IDs, the envelope and request IDs.
