Skip to main content
A test API key is a real API account on the live Olympex API. Create one below and you can sign requests right away: there is no approval or activation step. The console names the account docs-test- plus a random suffix (you can change it; names need at least 6 characters and don’t have to be unique), generates a 32-character random passphrase in your browser, and calls POST /accounts. The new key is also loaded into every API console on this site until you reload the page. Use a key created in the browser to try the API, and keep it out of production. If your browser blocks the call, create the key from a terminal instead.

What you receive

Store them as OLYMPEX_API_KEY_ID, OLYMPEX_SECRET_KEY and OLYMPEX_PASSPHRASE: the reference signers read these names from the environment. Olympex stores only a hash of the passphrase and an encrypted copy of the secret key, and no endpoint returns your credentials again. If you lose the secret key or the passphrase, create a new account.
Copy the secret key and the passphrase before you leave or reload the page. The console shows them once, and Olympex can’t show either one to you again.

Store your credentials

  • On your machine, keep the three values in environment variables. The console’s Download .env button saves them as olympex.env; add that file to .gitignore.
  • On servers, keep them in a secret manager, such as AWS Secrets Manager, Google Cloud Secret Manager or HashiCorp Vault, and inject them as environment variables at runtime.
  • Never put them in source control, client-side code, mobile apps, browser storage, logs, tickets or chat. Sign requests on a server: whatever signs holds the secret key.
The passphrase is as sensitive as the secret key. It travels in x-passphrase on every signed request, so anything that logs request headers captures it. Protect it exactly like the secret key.
The downloaded file uses the standard .env format:
Load olympex.env into a bash or zsh session with set -a; . ./olympex.env; set +a.

What a test key can do

  • It is a real account on the live API. There is no sandbox or testnet environment.
  • It works immediately. Every signed endpoint accepts it as soon as the account exists.
  • Reads change nothing. Chain and token lists, quotes and chain checks are read-only, and POST /swap returns unsigned calldata: it never signs or sends a transaction.
  • Orders are real. A limit order or DCA strategy you create with a test key is a real order. It belongs to that API key: no other key can list, read or cancel it.
The calldata from POST /swap is real mainnet calldata: broadcasting it from a funded wallet moves funds. A limit order or DCA strategy moves funds too when Olympex executes it, from a maker wallet that has approved the Olympex order contract. Test orders only with a wallet and an allowance you’re prepared to spend.

If a credential leaks

Credentials don’t expire, and there is no rotation, revocation or scoping. If a secret key or passphrase leaks:
  1. Email partners@olympex.io and ask to deactivate the account. Include the API key ID, never the secret key or the passphrase.
  2. If the account has open limit orders or DCA strategies, whoever holds the credentials can change or cancel them. Cancel them with the same credentials before the account is deactivated, or set the maker wallet’s allowance to the Olympex order contract to 0 to stop every order that sells that token. See Credentials.
  3. Create a new account and move your integration to its credentials.

Create a key from a terminal

POST /accounts is public, so it needs no signature. Creating the account from a terminal or a server you control keeps the secret key out of the browser; use this path for credentials you keep beyond testing. Generate a passphrase of at least 24 random characters in your password manager, using letters, digits, - and _. Other printable ASCII characters also work, as long as the passphrase doesn’t start or end with a space, but this set is safe to embed in the JSON body below.
The response, saved in olympex-account.json, carries your API key ID in apiKey and your secret key in secretKey:
secretKey is a random string, and this response is the only time Olympex returns it. Move both values to a new olympex.env, which only you can read, and load it. The block prints your API key ID and nothing else, or the error if the call failed. It refuses to overwrite an existing olympex.env:
Add olympex.env to .gitignore, and keep the passphrase in your password manager: the file doesn’t hold it. A name shorter than 6 characters or a password shorter than 8 returns 400 VALIDATION_ERROR, with "name is required" or "password is required" in error.details. Create an account has the full reference.

Integrator fees and volume

Talk to the Olympex team about integrator fees, volume or anything else.

Talk to us

Book a call about integrator fees or expected volume, or email partners@olympex.io.

What’s next

Quickstart

Send your first signed request with the key you created.

Sign requests

The signing algorithm and reference signers in TypeScript, Python and bash.

Credentials

How the API key ID, secret key and passphrase work together.

Going to production

The checklist before you route real user flow through Olympex.