Public vs Authenticated
Most read-only endpoints are public. Auth is required for trading, account, margin, redeem, and key-management operations.Required Headers
All authenticated requests require these headers:string
required
API key id.
string
required
Current unix timestamp in seconds.
string
required
Lowercase hex
HMAC-SHA256 digest of the signing payload.Signature Payload
The signature payload is:GET /orders/?limit=10 with no body:
path must match {path}?{query} exactly as on the request URL you send to https://api.worm.wtf (including leading slash and query string). Edge routing may map these URLs to internal handlers; always sign what you actually request.
Bootstrap Flow
Generate API credentials once, then use them for HMAC:1
Request challenge
POST https://api.worm.wtf/auth/keys/challenge/ with wallet_address to receive nonce, message, and expires_in_seconds.2
Sign with wallet
Sign the
message bytes (UTF-8) with the same Solana keypair; send the signature as hex to the create step.3
Create API key
POST https://api.worm.wtf/auth/keys/create/ with wallet_address, message, signature, and nonce to receive api_key and secret.4
Store credentials
Persist the key material securely. The secret is shown once.
After bootstrap, use the
secret field from the create response as your HMAC signing key (WORM-SIGNATURE is computed with HMAC-SHA256(secret_utf8, payload)). This is separate from the wallet signature used only during key creation.The
signature here is only for proving you control the wallet: sign the exact UTF-8 message from the challenge step and send it as hex. Submit endpoints for orders, margin requests, and redeems use a different message (the draft program-call payload from the API), but the same idea: sign that message and send the hex signature in the submit body.Signing Python Example
The sample below bootstraps an API key (challenge → sign → create), then calls a signed endpoint with HMAC. Install HTTP and signing dependencies:solana package on PyPI is optional; it depends on solders and fits stacks that already use solana-py.