Skip to main content
Python developers can use the official Python SDK (worm-sdk) for HMAC signing and API key bootstrap instead of implementing the flow manually.

Public vs Authenticated

Most read-only endpoints are public. Auth is required for trading, account, margin, redeem, and key-management operations.

Required Headers

All authenticated requests require these headers:
string
required
API key id.
string
required
Current unix timestamp in seconds.
string
required
Lowercase hex HMAC-SHA256 digest of the signing payload.

Signature Payload

The signature payload is:
Example payload for GET /orders/?limit=10 with no body:
The signed path must match {path}?{query} exactly as on the request URL you send to https://api.worm.wtf (including leading slash and query string). Edge routing may map these URLs to internal handlers; always sign what you actually request.

Bootstrap Flow

Generate API credentials once, then use them for HMAC:
1

Request challenge

POST https://api.worm.wtf/auth/keys/challenge/ with wallet_address to receive nonce, message, and expires_in_seconds.
2

Sign with wallet

Sign the message bytes (UTF-8) with the same Solana keypair; send the signature as hex to the create step.
3

Create API key

POST https://api.worm.wtf/auth/keys/create/ with wallet_address, message, signature, and nonce to receive api_key and secret.
4

Store credentials

Persist the key material securely. The secret is shown once.
After bootstrap, use the secret field from the create response as your HMAC signing key (WORM-SIGNATURE is computed with HMAC-SHA256(secret_utf8, payload)). This is separate from the wallet signature used only during key creation.
The signature here is only for proving you control the wallet: sign the exact UTF-8 message from the challenge step and send it as hex. Submit endpoints for orders, margin requests, and redeems use a different message (the draft program-call payload from the API), but the same idea: sign that message and send the hex signature in the submit body.

Signing Python Example

The sample below bootstraps an API key (challenge → sign → create), then calls a signed endpoint with HMAC. Install HTTP and signing dependencies:
The solana package on PyPI is optional; it depends on solders and fits stacks that already use solana-py.

Security Best Practices

Never expose API secrets in client-side code. Treat API keys and HMAC secrets like passwords: they belong only in server-side apps, secret managers, or locked-down CI — never in browsers, mobile clients, or public source control.
Storage — Keep WORM-API-KEY and WORM_API_SECRET in environment variables or a dedicated secret manager. Do not commit .env or similar files.Signing — Perform HMAC signing only on trusted backend infrastructure.Rotation and revocation — Rotate credentials regularly. Use List API keys (GET /auth/keys/) to see active keys, Revoke API key (DELETE /auth/keys/{key_id}/) to invalidate a key you no longer need, and the Create auth challenge / Create API key bootstrap flow to issue a replacement.

Troubleshooting