GitHub
Source, examples, and issue tracker.
PyPI
pip install worm-sdk.Features
- Full coverage of the Worm REST API — markets, events, search, spot orders, margin, redeems, and account data
- Typed responses with Pydantic models
- HMAC authentication for private endpoints
- Optional Solana wallet signing for order, margin, and redeem flows
- Cursor-based pagination helpers (
CursorPage) - HTTP/2 via httpx
Installation
Quickstart (public data)
No credentials required:Authentication
The SDK handles HMAC signing for you. Create API credentials once with a Solana wallet, then passapi_key and api_secret to the client.
SolanaWalletSigner accepts a base58 secret string, 128-character hex keypair, or raw 64-byte keypair bytes. You can also pass any object that implements SignerProtocol (Ledger, KMS, etc.).
For the raw HTTP bootstrap flow, see Authentication.
Environment variables
The SDK examples read these when set:Client namespaces
WormClient exposes namespaced APIs that map to the REST endpoints documented in this reference:
Pagination
List methods return aCursorPage[T] with items, next_cursor, and limit:
Trading helpers
When asigner is configured, convenience methods combine draft → sign → submit in one call:
Spot CLOB only.
client.orders.place targets non-margin markets. For leveraged positions, use client.margin helpers after calling Estimate margin position.Error handling
WormAPIError exposes error_code, slug, and message.
Configuration
client.last_response for rate-limit headers and response metadata. See Rate limits.
Integration checklist
- Prefer
worm-sdkfor Python services; use raw HTTP for other languages. - Base URL:
https://api.worm.wtf - Parse the standard envelope (
data,meta,error) on raw HTTP calls. - Paginate with
limit+cursor/meta.next_cursor. - Retry
429and transient5xxwith backoff; honorRetry-AfterandX-RateLimit-Reset. - Keep HMAC and wallet signing server-side only.
Next steps
Worm MCP
Use Worm from AI agents in Cursor, Claude, and other MCP clients.
Authentication
HMAC payload format and manual key bootstrap.
API introduction
Endpoint families and public vs authenticated behavior.