> ## Documentation Index
> Fetch the complete documentation index at: https://docs.olympex.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Support

> How to contact the Olympex team, what to include in a support request, and how to report a leaked credential or a security issue.

The Olympex team handles integration questions, error reports, credential deactivation, security reports and commercial requests through one email address. Include the details listed under [What to include](#what-to-include) so the team can investigate without asking you for them first.

## Contact

| Channel | Use it for |
| - | - |
| [partners@olympex.io](mailto:partners@olympex.io) | Error reports, integration questions, deactivating a leaked account, security reports, integrator fees and expected volume. |
| [Book a call](https://calendar.app.google/zZGNMcrzbQwMjVMJA) | Planning an integration, commercial terms and volume. |

## Before you write

Many problems can be diagnosed from the docs in a few minutes:

* **An error envelope.** Look up `error.code` and the HTTP status in [Errors and retries](/authentication/errors-and-retries). For `400` `VALIDATION_ERROR`, `error.details` names each field at fault.
* **`401` or `403` on a signed request.** Work through the [signing troubleshooting table](/authentication/sign-requests#troubleshooting), and test your implementation against the known-answer vectors on the same page. If correctly signed requests keep failing, email [partners@olympex.io](mailto:partners@olympex.io).
* **`404` `NOT_FOUND` with `"No route for …"`.** No endpoint matches the method and path. Check that the URL starts with the [base URL](/api-reference/overview#base-url), that the method is the one the endpoint page shows, and that the path is lowercase, for example `/support-chain`.
* **`404` `NOT_FOUND` for an order or strategy ID**, with a message that names the resource. No limit order, DCA strategy or DCA order with that ID belongs to the API key you signed with: the ID doesn't exist, or another API key created it. See [Not found](/api-reference/conventions#not-found).
* **`409` `CONFLICT` on a limit order.** The order is no longer `pending`, so it can't be changed or cancelled. Read it with [`GET /limit-order/{id}`](/api-reference/limit-orders/get-limit-order) and check its `status`.
* **A limit order or DCA order that doesn't execute or fails.** Read `reasonFail[]` on the limit order or `errorMessage` on the DCA order. Check that the maker still holds the tokens, that its allowance to the [order contract](/concepts/order-authorization#the-order-contract) covers the order (plus the execution gas, for a limit order), and that the order signature recovers to the maker. For a limit order, also check that `tokenASymbol` and `tokenBSymbol` match your tokens.
* **"The browser blocked the response" in the API console.** Click **Copy as cURL** and run the request from a terminal. Add `-i` to the command (or `-D -`) to see the status and the `apigw-requestid` header. See [API console](/api-reference/console).
* **A swap whose `eth_estimateGas` reverts.** Check the allowance, the balance and the expiry, then build the swap again with the next source in the quote's `aggregatorOrder`, or request a new quote. See [Falling back with `aggregatorOrder`](/concepts/aggregation-and-routing#falling-back-with-aggregatororder).
* **`422` `NO_ROUTE`, or a chain or token pair without a route.** Retry later with backoff: sources can be briefly unavailable. If it persists, check [Supported chains and tokens](/concepts/supported-chains), then request a quote for another amount or pair.
* **A suspected outage.** Olympex doesn't publish a status page. If `500` or `503` responses persist across endpoints after retries with backoff, email [partners@olympex.io](mailto:partners@olympex.io) with the request IDs and UTC times of a few failures.

## What to include

| Include | Why |
| - | - |
| `meta.requestId` of each failing response | Identifies the request. Every enveloped response carries one, errors included. |
| Endpoint and HTTP status | For example, `POST /quotes` returned `500`. |
| Time of the request, in UTC | Gateway responses (`{"message": …}`) have no `meta.requestId`, and the reference helpers' errors carry no request ID for them. Send the value of their `apigw-requestid` response header instead, together with the time. Browsers can't read that header cross-origin; `curl -i` shows it. |
| Your API key ID | Identifies your account. Share it with Olympex support only, never in public places. |
| The request body | The JSON you sent, without credentials. Remove the `password` from `POST /accounts` bodies. |
| The response body | Exactly as received. |
| Transaction details | For a swap you broadcast: the chain ID and the transaction hash, plus the `dexHash` for a cross-chain transfer. |
| Order details | For a limit order or a DCA strategy: its `id`, the chain ID and the maker address (`accountTo`), plus the `id` of any DCA order involved. |
| Expected and observed behavior | What you expected, what happened instead, and whether it happens every time. |

<Warning>
  Never send the secret key or the passphrase, in an email, a call, a chat or a screenshot, and never send a wallet's private key or seed phrase. Remove the `x-passphrase` header from any request or log you paste. If you have already shared either one, treat the account as leaked and follow the steps under [Report a leaked credential](#report-a-leaked-credential).
</Warning>

A report with everything in place looks like this:

```text theme={null}
Subject: POST /quotes returns 422 NO_ROUTE for USDT to 0x000000000000000000000000000000000000dEaD on Polygon

meta.requestId: E7ef-j_MoAMEPBw=
Endpoint and status: POST /quotes, 422
Time (UTC): 2026-10-08T14:38:04Z
API key ID: 00000000-0000-4000-8000-000000000000

Request body:
{"mode":"single-chain","params":{"amount":"10","chainId":137,"gasPrice":"35","inTokenAddress":"0xc2132d05d31c914a87c6611c10748aeb04b58e8f","outTokenAddress":"0x000000000000000000000000000000000000dEaD","slippage":"1"}}

Response body:
{"success":false,"error":{"code":"NO_ROUTE","message":"No route found for this pair and amount. Providers may also be temporarily unavailable; retrying later can succeed.","details":[{"message":"The quote could be retrieved but the route is not available"}]},"meta":{"requestId":"E7ef-j_MoAMEPBw=","version":"v1","accountType":"integrator","apiKeyId":"00000000-0000-4000-8000-000000000000"}}

Expected: a route for this pair.
Observed: 422 NO_ROUTE on every attempt since 14:30 UTC. Other pairs on Polygon work.
```

## Report a leaked credential

API accounts have no self-service way to disable a key. If a secret key or a passphrase may have been exposed:

1. Email [partners@olympex.io](mailto:partners@olympex.io) and ask to deactivate the account. Include the API key ID only.
2. If the account has open limit orders or DCA strategies, set each maker's allowance to the order contract to `0`. Anyone with the credentials can create and change orders, and the allowance is what limits them. See [Stop everything](/concepts/order-authorization#stop-everything-set-the-allowance-to-0).
3. Create a new API account and move your integration to its credentials.
4. Remove the exposed values from wherever they leaked: logs, tickets, chats or repository history.

[Credentials](/authentication/credentials) describes the full procedure.

## Report a security issue

Email [partners@olympex.io](mailto:partners@olympex.io) with a description of the issue, the steps to reproduce it, and the `meta.requestId` of any request involved. Don't include working credentials, and don't disclose the issue publicly until Olympex has had the chance to address it. The [Security model](/concepts/security-model) describes what Olympex secures and what your integration is responsible for.

## Related

<CardGroup cols={2}>
  <Card title="Errors and retries" icon="circle-exclamation" href="/authentication/errors-and-retries">
    Error codes, gateway responses and what to retry.
  </Card>

  <Card title="Sign requests" icon="code" href="/authentication/sign-requests">
    The signing algorithm and its troubleshooting table.
  </Card>

  <Card title="FAQ" icon="list-check" href="/resources/faq">
    Answers to common integration questions.
  </Card>

  <Card title="API console" icon="terminal" href="/api-reference/console">
    Send signed requests from your browser.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.