docs-test- plus a random suffix (you can change it; names need at least 6 characters and don’t have to be unique), generates a 32-character random passphrase in your browser, and calls POST /accounts. The new key is also loaded into every API console on this site until you reload the page. Use a key created in the browser to try the API, and keep it out of production. If your browser blocks the call, create the key from a terminal instead.
What you receive
Store them as
OLYMPEX_API_KEY_ID, OLYMPEX_SECRET_KEY and OLYMPEX_PASSPHRASE: the reference signers read these names from the environment.
Olympex stores only a hash of the passphrase and an encrypted copy of the secret key, and no endpoint returns your credentials again. If you lose the secret key or the passphrase, create a new account.
Store your credentials
- On your machine, keep the three values in environment variables. The console’s Download .env button saves them as
olympex.env; add that file to.gitignore. - On servers, keep them in a secret manager, such as AWS Secrets Manager, Google Cloud Secret Manager or HashiCorp Vault, and inject them as environment variables at runtime.
- Never put them in source control, client-side code, mobile apps, browser storage, logs, tickets or chat. Sign requests on a server: whatever signs holds the secret key.
.env format:
What a test key can do
- It is a real account on the live API. There is no sandbox or testnet environment.
- It works immediately. Every signed endpoint accepts it as soon as the account exists.
- Reads change nothing. Chain and token lists, quotes and chain checks are read-only, and
POST /swapreturns unsigned calldata: it never signs or sends a transaction. - Orders are real. A limit order or DCA strategy you create with a test key is a real order. It belongs to that API key: no other key can list, read or cancel it.
If a credential leaks
Credentials don’t expire, and there is no rotation, revocation or scoping. If a secret key or passphrase leaks:- Email partners@olympex.io and ask to deactivate the account. Include the API key ID, never the secret key or the passphrase.
- If the account has open limit orders or DCA strategies, whoever holds the credentials can change or cancel them. Cancel them with the same credentials before the account is deactivated, or set the maker wallet’s allowance to the Olympex order contract to
0to stop every order that sells that token. See Credentials. - Create a new account and move your integration to its credentials.
Create a key from a terminal
POST /accounts is public, so it needs no signature. Creating the account from a terminal or a server you control keeps the secret key out of the browser; use this path for credentials you keep beyond testing.
Generate a passphrase of at least 24 random characters in your password manager, using letters, digits, - and _. Other printable ASCII characters also work, as long as the passphrase doesn’t start or end with a space, but this set is safe to embed in the JSON body below.
olympex-account.json, carries your API key ID in apiKey and your secret key in secretKey:
secretKey is a random string, and this response is the only time Olympex returns it.
Move both values to a new olympex.env, which only you can read, and load it. The block prints your API key ID and nothing else, or the error if the call failed. It refuses to overwrite an existing olympex.env:
olympex.env to .gitignore, and keep the passphrase in your password manager: the file doesn’t hold it.
A name shorter than 6 characters or a password shorter than 8 returns 400 VALIDATION_ERROR, with "name is required" or "password is required" in error.details. Create an account has the full reference.
Integrator fees and volume
Talk to the Olympex team about integrator fees, volume or anything else.Talk to us
Book a call about integrator fees or expected volume, or email partners@olympex.io.
What’s next
Quickstart
Send your first signed request with the key you created.
Sign requests
The signing algorithm and reference signers in TypeScript, Python and bash.
Credentials
How the API key ID, secret key and passphrase work together.
Going to production
The checklist before you route real user flow through Olympex.
