> ## Documentation Index
> Fetch the complete documentation index at: https://docs.olympex.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a test API key

> Create Olympex API credentials in one click, store them safely, and learn what a test key can and can't do.

A test API key is a real API account on the live Olympex API. Create one below and you can sign requests right away: there is no approval or activation step.

Create the account with a public `POST /accounts` request, as shown in [Create a key from a terminal](#create-a-key-from-a-terminal). The one-click console on this page calls the same endpoint from the browser.

The console names the account `docs-test-` plus a random suffix (you can change it; names need at least 6 characters and don't have to be unique), generates a 32-character random passphrase in your browser, and calls [`POST /accounts`](/api-reference/accounts/create-account). The new key is also loaded into every [API console](/api-reference/console) on this site until you reload the page. Use a key created in the browser to try the API, and keep it out of production. If your browser blocks the call, [create the key from a terminal](#create-a-key-from-a-terminal) instead.

## What you receive

| Value | What it does |
| - | - |
| **API key ID**, a UUID | Identifies your account. Sent as `x-api-key-id` on every signed request. |
| **Secret key**, a random string shown once | Keys the HMAC-SHA256 signature. It is never sent with a request. |
| **Passphrase**, generated by the console | Sent as `x-passphrase` on every signed request. It is the `password` the account was created with. |

Store them as `OLYMPEX_API_KEY_ID`, `OLYMPEX_SECRET_KEY` and `OLYMPEX_PASSPHRASE`: the reference signers read these names from the environment.

Olympex stores only a hash of the passphrase and an encrypted copy of the secret key, and no endpoint returns your credentials again. If you lose the secret key or the passphrase, create a new account.

<Warning>
  Copy the secret key and the passphrase before you leave or reload the page. The console shows them once, and Olympex can't show either one to you again.
</Warning>

## Store your credentials

* **On your machine**, keep the three values in environment variables. The console's **Download .env** button saves them as `olympex.env`; add that file to `.gitignore`.
* **On servers**, keep them in a secret manager, such as AWS Secrets Manager, Google Cloud Secret Manager or HashiCorp Vault, and inject them as environment variables at runtime.
* **Never** put them in source control, client-side code, mobile apps, browser storage, logs, tickets or chat. Sign requests on a server: whatever signs holds the secret key.

<Warning>
  **The passphrase is as sensitive as the secret key.** It travels in `x-passphrase` on every signed request, so anything that logs request headers captures it. Protect it exactly like the secret key.
</Warning>

The downloaded file uses the standard `.env` format:

```text theme={null}
OLYMPEX_API_KEY_ID=…
OLYMPEX_SECRET_KEY=…
OLYMPEX_PASSPHRASE=…
```

<Tip>
  Load `olympex.env` into a bash or zsh session with `set -a; . ./olympex.env; set +a`.
</Tip>

## What a test key can do

* **It is a real account on the live API.** There is no sandbox or testnet environment.
* **It works immediately.** Every signed endpoint accepts it as soon as the account exists.
* **Reads change nothing.** Chain and token lists, quotes and chain checks are read-only, and [`POST /swap`](/api-reference/swap/build-swap) returns unsigned calldata: it never signs or sends a transaction.
* **Orders are real.** A limit order or DCA strategy you create with a test key is a real order. It belongs to that API key: no other key can list, read or cancel it.

<Warning>
  The calldata from `POST /swap` is real mainnet calldata: broadcasting it from a funded wallet moves funds. A limit order or DCA strategy moves funds too when Olympex executes it, from a maker wallet that has approved the Olympex order contract. Test orders only with a wallet and an allowance you're prepared to spend.
</Warning>

## If a credential leaks

Credentials don't expire, and there is no rotation, revocation or scoping. If a secret key or passphrase leaks:

1. Email [partners@olympex.io](mailto:partners@olympex.io) and ask to deactivate the account. Include the API key ID, never the secret key or the passphrase.
2. If the account has open limit orders or DCA strategies, whoever holds the credentials can change or cancel them. Cancel them with the same credentials before the account is deactivated, or set the maker wallet's allowance to the Olympex order contract to `0` to stop every order that sells that token. See [Credentials](/authentication/credentials#if-a-credential-is-exposed).
3. Create a new account and move your integration to its credentials.

## Create a key from a terminal

`POST /accounts` is public, so it needs no signature. Creating the account from a terminal or a server you control keeps the secret key out of the browser; use this path for credentials you keep beyond testing.

Generate a passphrase of at least 24 random characters in your password manager, using letters, digits, `-` and `_`. Other printable ASCII characters also work, as long as the passphrase doesn't start or end with a space, but this set is safe to embed in the JSON body below.

```bash theme={null}
# Create an Olympex API account. POST /accounts is public: no signature needed.
# Paste the passphrase from your password manager and press Enter (input stays hidden).
read -rs OLYMPEX_PASSPHRASE && export OLYMPEX_PASSPHRASE
# printf is a shell builtin, so the passphrase never appears in the process list.
# The response holds the secret key: it goes to a file only you can read, not to the terminal.
( umask 077
  printf '{"name":"%s","password":"%s"}' "acme-trading-desk" "$OLYMPEX_PASSPHRASE" |
    curl -sS -X POST "https://api-rest.olympex.io/api/v1/accounts" \
      -H "content-type: application/json" \
      --data-binary @- -o olympex-account.json )
```

The response, saved in `olympex-account.json`, carries your API key ID in `apiKey` and your secret key in `secretKey`:

```json theme={null}
{
  "success": true,
  "data": {
    "message": "ACCOUNT_CREATED",
    "apiKey": "00000000-0000-4000-8000-000000000000",
    "secretKey": "…"
  },
  "meta": {
    "requestId": "ENMcEjviIAMEMYg=",
    "version": "v1"
  }
}
```

`secretKey` is a random string, and this response is the only time Olympex returns it.

Move both values to a new `olympex.env`, which only you can read, and load it. The block prints your API key ID and nothing else, or the error if the call failed. It refuses to overwrite an existing `olympex.env`:

```bash theme={null}
# Move the API key ID and the secret key to a new olympex.env, readable only by you, and load it.
if grep -q '"success":true' olympex-account.json; then
  ( umask 077; set -C
    printf 'OLYMPEX_API_KEY_ID=%s\nOLYMPEX_SECRET_KEY=%s\n' \
      "$(sed -n 's/.*"apiKey":"\([^"]*\)".*/\1/p' olympex-account.json)" \
      "$(sed -n 's/.*"secretKey":"\([^"]*\)".*/\1/p' olympex-account.json)" > olympex.env ) &&
    rm olympex-account.json && set -a && . ./olympex.env && set +a &&
    echo "Created API key ID $OLYMPEX_API_KEY_ID"
else
  cat olympex-account.json; echo # the call failed: fix the cause and run the first block again
fi
```

Add `olympex.env` to `.gitignore`, and keep the passphrase in your password manager: the file doesn't hold it.

A `name` shorter than 6 characters or a `password` shorter than 8 returns `400 VALIDATION_ERROR`, with `"name is required"` or `"password is required"` in `error.details`. [Create an account](/api-reference/accounts/create-account) has the full reference.

## Integrator fees and volume

Talk to the Olympex team about integrator fees, volume or anything else.

<Card title="Talk to us" icon="calendar" href="https://calendar.app.google/zZGNMcrzbQwMjVMJA" horizontal>
  Book a call about integrator fees or expected volume, or email [partners@olympex.io](mailto:partners@olympex.io).
</Card>

## What's next

<CardGroup cols={2}>
  <Card title="Quickstart" icon="bolt" href="/get-started/quickstart">
    Send your first signed request with the key you created.
  </Card>

  <Card title="Sign requests" icon="key" href="/authentication/sign-requests">
    The signing algorithm and reference signers in TypeScript, Python and bash.
  </Card>

  <Card title="Credentials" icon="shield-halved" href="/authentication/credentials">
    How the API key ID, secret key and passphrase work together.
  </Card>

  <Card title="Going to production" icon="list-check" href="/guides/going-to-production">
    The checklist before you route real user flow through Olympex.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.