> ## Documentation Index
> Fetch the complete documentation index at: https://docs.0xinsider.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Event replay

> Read recorded large-trade events after a saved cursor to recover from an interruption.

Use this endpoint to catch up after a restart, a webhook outage, or a [Stream](/api-reference/endpoint/get-stream) `resync` message. Each event identifies one large Polymarket trade recorded by 0xinsider.

Save the returned cursor after you process a page. Use the stream when you need new events pushed to an open connection.

## Parameters

| Parameter | Description |
| - | - |
| `cursor` | A `next_cursor` from an earlier response, and nothing else. A value you assembled yourself returns `400` with `error.param` `cursor`. A cursor saved before September 22, 2026 still works, and the response gives you one in the current format. |
| `limit` | How many events to return, from 1 to 100. The default is 50. A value outside that range is clamped into it. |
| `trader` | Only this wallet's trades, as an address, a `trd_` id, or a username. A wallet 0xinsider does not know matches nothing, and the cursor still moves forward. |
| `condition_id` | Only this market's trades, as the raw Polymarket `condition_id` or its `mkt_` id. |
| `min_grade` | Only wallets at this grade or better, with `S` the best, read from the wallet's newest ranking. A wallet with no grade never passes. See [Grades](/concepts/grades). |
| `min_size` | Only trades of at least this USD amount, at most 1e15. Decimal and scientific spellings normalize exactly to cents, rounding midpoint ties away from zero. For dataset continuation, send the manifest's decimal string unchanged. |
| `expand` | Repeatable, and `expand[]` is accepted as an alias. `expand=trade` adds the base [large trade](/api-reference/endpoint/get-large-trade) fields to every event, using one extra query for the page. The detail route adds `counterparty_analysis`, which replay omits. |

`trader`, `condition_id`, `min_grade`, and `min_size` are recorded inside the cursor. Sending that cursor back under a different set of filters, including no filters at all, returns `400` with `error.reason` `cursor_expired`: start again without a cursor under the new filters.

A cursor from an unfiltered request is bound to no filters, so adding a filter part of the way through is refused the same way. `expand` changes what each event carries, never which events you get, so you can turn it on or off at any point.

## How to page through events

1. Call it once with no `cursor`. You get the newest `limit` events in commit order, and `has_more` is `false`.
2. Store `next_cursor` somewhere that survives a restart. After a page that is not full it moves past every row the server examined, so even an empty page moves you forward.
3. Send it back as `cursor` on the next call. You get only the events after it.
4. Repeat while `has_more` is `true`, storing `next_cursor` after you process each page. A crash then repeats a page instead of skipping one.
5. Deduplicate on `data[].id`, never on `sequence`. A lower `sequence` can follow a higher one, which is the trade an id-ordered reader used to lose.

Events come back in the order their writes became visible, and then by `sequence`. A page never reaches past the oldest write that was still open when the page was read. So a trade whose id is lower than one you already hold, but whose write finished later, arrives on a later page instead of being skipped.

## Key response fields

| Field | Meaning |
| - | - |
| `data[].id` | The event's identity. Deduplicate on this one: it is the same value across every cursor format. |
| `data[].type` | Always `whale_trades_inserted`. |
| `data[].sequence` | The trade's numeric id. It does not always rise from one event to the next, so it is not safe to deduplicate on. |
| `data[].cursor` | A cursor positioned at this one event, in case you want to resume from it rather than from the end of the page. |
| `data[].payload` | The facts as they were recorded: `count`, `whale_alert_id`, `condition_id`, `trader_id`, and `platform`, which is always `polymarket`. |
| `data[].trade` | Sent with `expand=trade`: the base [large trade](/api-reference/endpoint/get-large-trade) fields for the row, without the detail-only `counterparty_analysis`. `traded_at`, `side`, `size_usd`, `price`, `outcome`, `token_id`, `recorded_review_score`, and `trader.grade_at_trade` are facts at the time of the trade. `trader.grade`, `trader.username`, `review_score`, the `suspicion_*` fields, and `market` are read when you ask, so they can have moved since. `null` when the detail route would answer `404` for the row. |
| `data[].published_at` | When the trade happened. `freshness.observed_at` is the same instant. |
| `data[].source.kind` | Always `local_durable_replay`. Nothing is fetched from Polymarket during the request. |
| `has_more` | `true` when the page filled up and more events were already waiting. |
| `next_cursor` | Where to continue from. Store it after you have processed the page. |
| `meta.completeness.status` | `complete` when the page holds events, and `caught_up` when it is empty. |
| `meta.replay.ordering` | Always `commit_visibility_then_id_asc`. |
| `meta.replay.pending_beyond_horizon` | `true` when committed trades are waiting behind a write that had not finished when your page was read. A `caught_up` page with this set to `true` is not the end: ask again. The wait is seconds in normal operation, and as long as a backfill takes while one is running. |
| `meta.replay.filters` | The filters this `next_cursor` is bound to. Absent when you sent none. |
| `meta.replay.expand` | The expansions applied to this page, or `[]` when there were none. |
| `meta.retention.retained_events` | How many events this response carries. `meta.retention.cursor_expired` is always `false`, because a cursor is a stored database position and never ages out. |

## Example

```bash theme={null}
curl -H "Authorization: Bearer $OXINSIDER_API_KEY" \
  "https://api.0xinsider.com/api/v1/events/feed/since?cursor=$REPLAY_CURSOR&limit=100"
```

Only A-or-better wallets, with the whole trade on every event, in 1 request per page:

```bash theme={null}
curl -H "Authorization: Bearer $OXINSIDER_API_KEY" \
  "https://api.0xinsider.com/api/v1/events/feed/since?min_grade=A&expand=trade&limit=100"
```

## What it does not return

* Any other event type. Alert, following, radar, position patch, and browser-only events have no durable public record yet.
* The trade itself, unless you ask for it. `expand=trade` carries it, and without it `payload.whale_alert_id` is the id to pass to [Large trade](/api-reference/endpoint/get-large-trade).
* Exactly-once delivery. A page read again after a crash repeats its events, so deduplicate on `data[].id`.
* Events before your cursor. The window starts strictly after it, so go further back by storing an older cursor, not by editing one.


## OpenAPI

````yaml GET /api/v1/events/feed/since
openapi: 3.1.0
info:
  x-generated-rate-limit-policy-from: web/src/lib/rate-limit-facts.ts via web/scripts/generate-api-policy.ts
  title: 0xinsider API
  description: >-
    Follow provider-exposed large-trade activity from Polymarket. Polymarket
    wallet-attributed trades can add grades, P&L, strategy, and diagnostic-score
    context when sufficient source data exists. Fields can be null or
    unavailable. Normal API requests use a 30-second server timeout that returns
    HTTP 408 Request Timeout with the standard error envelope (error.code
    request_timeout) when exceeded. Every /api/v1 failure answers that envelope,
    including a body that is not JSON or does not fit the request schema (400
    invalid_body), a query or path value that does not parse (400 invalid_query,
    invalid_path), a missing Content-Type: application/json (415
    unsupported_media_type), a body over 1048576 bytes (413 payload_too_large)
    and a method the path does not serve (405 method_not_allowed), each with
    error.param naming the field where one is known and meta.request_id equal to
    X-Request-Id. Unknown query names are ignored by default and reported in
    X-Query-Ignored, while X-Effective-Query lists the normalized names and
    values applied using form-urlencoded decoding, where + is a space; strict
    mode returns 400 bad_request with error.reason unknown_query_parameter
    before the handler runs, including for an unknown name with an incomplete
    percent escape. Every list operation clamps an out-of-range limit into its
    published minimum..maximum instead of refusing it (limit=0 reads one row,
    limit=500 reads the maximum), and X-Effective-Query reports the clamped
    value; only a limit that is not an integer is refused, with 400
    invalid_query. Public REST /api/v1/* endpoints, excluding /api/v1/mcp, use
    Bearer-token based non-credentialed browser CORS: any Origin may call with
    Authorization, Content-Type, If-None-Match, Idempotency-Key, Mcp-Session-Id,
    Mcp-Protocol-Version, Last-Event-Id, and X-Query-Validation request headers.
    X-Query-Validation: strict opts into rejecting unknown query names; the
    default remains compatible. Remote MCP at /api/v1/mcp is non-credentialed,
    but still validates Origin against the 0xinsider/localhost allowlist per MCP
    Streamable HTTP DNS-rebinding guidance. Successful browser CORS preflight
    responses advertise Access-Control-Max-Age: 86400. Browser JavaScript may
    read RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, the legacy
    X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, Retry-After,
    ETag, X-Request-Id, X-Request-Cost, X-Usage-Accounting,
    X-Batch-RateLimit-Limit, X-Batch-RateLimit-Remaining,
    X-Batch-RateLimit-Reset, Mcp-Session-Id, X-Mcp-Error-Code, X-Query-Ignored,
    and X-Effective-Query response headers. Rate-limit headers describe the
    budget a request was counted against: the API key's per-minute window on an
    authenticated call, and the per-IP budget on a public route or on a refused
    credential (401, 402, 403, 423), so a client looping on a bad or lapsed key
    still sees how much room it has. Conditional GET: these operations return a
    weak ETag and answer If-None-Match with 304 Not Modified and an empty body:
    GET /api/v1/health, GET /api/v1/insider-radar, GET
    /api/v1/insider-radar/{id}, GET /api/v1/large-positions, GET
    /api/v1/leaderboard, GET /api/v1/leaderboard/trending, GET
    /api/v1/market/{condition_id}/candles, GET
    /api/v1/market/{condition_id}/flow, GET /api/v1/market/{condition_id}/intel,
    GET /api/v1/market/{condition_id}/snapshot, GET /api/v1/markets/explore, GET
    /api/v1/markets/sharp-money-flows, GET /api/v1/markets/smart-money-flows,
    GET /api/v1/pick-of-the-day, GET /api/v1/pick-of-the-day/archive, GET
    /api/v1/positions, GET /api/v1/sports-edge-observations, GET
    /api/v1/sports-edge-signals, GET /api/v1/trader/{address}, GET
    /api/v1/trader/{address}/context, GET /api/v1/trader/{address}/pnl, GET
    /api/v1/trader/{address}/position-timeline, GET
    /api/v1/traders/{trader}/position-timeline, GET /api/v1/large-trades, GET
    /api/v1/large-trades/history, GET /api/v1/large-trades/{id}, GET
    /api/v1/whale-trades, GET /api/v1/whale-trades/history, GET
    /api/v1/whale-trades/{id}, GET
    /api/v1/whale-trades/{id}/counterparties/executions, GET
    /api/v1/whale-trades/{id}/counterparties/executions/{execution_id}/makers.
    Credentialed first-party routes such as /api/keys, /api/billing, and auth
    endpoints remain restricted to configured 0xinsider origins. Protected V1
    responses, except the zero-cost /api/v1/usage route, after handler execution
    carry X-Usage-Accounting: persisted, failed, or unknown. This reports the
    usage-record write; it does not change the handler result. Do not replay a
    successful mutation to repair an unknown usage record. Before execution,
    unavailable accounting capacity returns HTTP 503 with
    error.reason=request_accounting_unavailable; honor Retry-After. Public API
    responses add the browser-readable Server-Timing header: Processing time in
    milliseconds, for example api;dur=12.345. Includes API authentication, quota
    admission, handler work and response construction. Excludes network transit
    and streamed body or export-file transfer. The engineering budget is
    strictly below 250 ms; this header reports observations, not a latency
    guarantee or a new timeout. Requests through https://0xinsider.com/api/*
    append Server-Timing: web_api;dur=<milliseconds> and X-Web-Request-Id for
    that web origin handler. The web clock includes upstream waiting and
    existing body construction, so do not add it to api;dur. It excludes
    platform routing, cold module initialization, CDN hits and later stream/file
    transfer. On a cache hit these headers describe the earlier origin fill, not
    the current request; static Markdown API routes have no fresh web clock.
  version: 1.0.0
  contact:
    name: 0xinsider
    email: support@0xinsider.com
    url: https://0xinsider.com
servers:
  - url: https://api.0xinsider.com
    description: >-
      Production (live data). Authenticate with a live key (oxi_sk_live_...);
      requires an active Pro subscription. A sandbox key (oxi_sk_test_...) is
      answered with 401 invalid_api_key and error.reason sandbox_api_key.
  - url: https://0xinsider.com/sandbox
    description: >-
      Sandbox. No credential required and no production data: every documented
      operation answers with its documented example or a deterministic sample of
      its response schema. GET /api/v1/stream is the one exclusion and answers
      400 there, because a Server-Sent Events stream is a live connection rather
      than a body. Add ?sandbox_status=<code> to receive one of the error
      responses the operation documents (for example 429 with Retry-After).
      Documented query parameters and JSON request bodies are checked against
      this document, the two context.md routes answer 200 text/markdown, GET
      /api/v1/trader/{address}/export/download answers its 302 with a Location
      the sandbox serves itself rather than an object store, and nothing is
      stored between requests. A sandbox key (oxi_sk_test_..., issued with no
      account by POST https://api.0xinsider.com/api/v1/agents/register) is
      optional: on an operation that requires a credential, a well-formed key is
      answered with X-Oxi-Sandbox-Key: valid and a malformed one with 401
      invalid_api_key.
security:
  - bearerAuth: []
  - oauth2:
      - read
tags:
  - name: Traders
    description: Traders, batch lookups, timelines, and export readiness.
  - name: Positions
    description: Current prediction-market position snapshots from backend-owned mirrors.
  - name: Large Positions
    description: Largest current open positions from graded traders (Polymarket-only).
  - name: Large trades
    description: Recent and historical large trades.
  - name: Leaderboard
    description: Ranked trader discovery and category/strategy leaderboards.
  - name: Pick of the Day
    description: >-
      One sourced sharp-money call a day: the side profitable wallets are
      backing, with pre-game odds, the holders, and the track record.
  - name: Games
    description: >-
      Sports and esports games: both sides, schedules, provider status and the
      Polymarket markets linked to each game.
  - name: Markets
    description: Market search, discovery, snapshots, and sharp-money flow.
  - name: Content
    description: Search across 0xinsider editorial content.
  - name: Suspicious trades
    description: Trades whose recorded suspicion score meets the live flag threshold.
  - name: Insider Radar
    description: >-
      Deprecated spelling of Suspicious trades; both operations stay live as
      aliases.
  - name: Events
    description: Durable public event replay streams.
  - name: Streaming
    description: Resumable real-time Server-Sent Events stream of live feed envelopes.
  - name: Webhooks
    description: Signed builder webhook destinations and delivery controls.
  - name: Usage
    description: Developer API budget and usage introspection.
  - name: Onboarding
    description: >-
      Self-serve agent registration: a sandbox key with no account, and the path
      to live access.
  - name: System
    description: Health and operational status checks.
  - name: MCP
    description: Remote Model Context Protocol transport.
  - name: Reports
    description: Daily, weekly, monthly, and trader export report snapshots.
  - name: Account
    description: Identify the account and credential authenticated for a paid API request.
externalDocs:
  description: 0xinsider API docs
  url: https://docs.0xinsider.com
paths:
  /api/v1/events/feed/since:
    get:
      tags:
        - Events
      summary: Replay public large-trade events
      description: >-
        Returns durable public large-trade events strictly after an opaque
        cursor, in commit order: events are ordered by the position at which
        their write became visible to every reader (whale_alerts.inserted_xid),
        then by whale_alerts.id, and a page never reaches past the oldest write
        transaction still open when it was read. A trade whose id is lower than
        one already delivered but whose write finished later is therefore
        delivered on a later request instead of being skipped (#16180). This is
        a separate API-key contract from the browser/session /api/events/feed
        stream: browser-only and private alert, following, radar, and position
        patch events are excluded until they have a durable public outbox.
      operationId: getEventReplaySince
      parameters:
        - name: X-Query-Validation
          in: header
          required: false
          description: >-
            Opt into strict query-name validation. The default is compatible:
            unknown names are ignored and reported in X-Query-Ignored. With
            strict, an unknown name returns 400 bad_request with error.reason
            unknown_query_parameter before the handler runs, including when its
            percent escape is incomplete.
          schema:
            type: string
            enum:
              - strict
        - name: cursor
          in: query
          required: false
          description: >-
            Opaque event replay cursor returned as next_cursor by a prior
            response. The cursor maps to the global (whale_alerts.inserted_xid,
            whale_alerts.id) commit-order position, is valid across backend
            replicas, and is bound to the filter set the walk ran with (trader,
            condition_id, min_grade, min_size): presenting it under different
            filters answers 400 bad_request with error.reason cursor_expired,
            and the walk restarts without a cursor. Cursors issued before
            2026-09-22 (id-only) stay accepted and are bound to no filters. Omit
            to fetch the latest durable public suffix.
          schema:
            type: string
        - name: limit
          in: query
          required: false
          description: >-
            Maximum durable public whale-trade events to return. Out-of-range
            values are clamped to 1..100.
          schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 50
        - name: trader
          in: query
          required: false
          description: >-
            Only this wallet's trades: a wallet address, trd_-prefixed trader id
            or username resolved against the traders table. Bound to the cursor:
            a cursor issued under other filters answers 400 with error.reason
            cursor_expired. An unknown trader matches nothing and the walk still
            advances.
          schema:
            type: string
        - name: condition_id
          in: query
          required: false
          description: >-
            Only trades on this market: the raw provider condition_id or its
            mkt_-prefixed id. Bound to the cursor.
          schema:
            type: string
        - name: min_grade
          in: query
          required: false
          description: >-
            Only trades by wallets at this grade or better (S best), read from
            the wallet's newest ranking at request time; a wallet with no grade
            never passes. Bound to the cursor.
          schema:
            type: string
            enum:
              - S
              - A
              - B
              - C
              - D
              - F
        - name: min_size
          in: query
          required: false
          description: >-
            Only trades of at least this USD amount. Decimal and scientific
            query spellings normalize exactly to cents, rounding half away from
            zero; maximum 1e15 USD. Pass the dataset continuation decimal string
            unchanged to preserve the bound. Bound to the cursor.
          schema:
            oneOf:
              - type: number
                minimum: 0
                maximum: 1000000000000000
              - type: string
                description: Exact decimal query spelling, including scientific notation.
        - name: expand[]
          in: query
          required: false
          description: 'Backward-compatible alias for expand. Repeatable: trade.'
          schema:
            type: array
            items:
              type: string
              enum:
                - trade
          style: form
          explode: true
        - name: expand
          in: query
          required: false
          description: >-
            Repeatable. trade adds the public trade read to every event (the
            object GET /api/v1/whale-trades/{id} returns for it), from one query
            per page, so a page of 100 events needs no per-event detail request.
            Not bound to the cursor: switch it on or off mid-walk.
          schema:
            type: array
            items:
              type: string
              enum:
                - trade
          style: form
          explode: true
      responses:
        '200':
          description: Public event replay window
          content:
            application/json:
              schema:
                type: object
                required:
                  - object
                  - data
                  - has_more
                  - next_cursor
                  - meta
                properties:
                  object:
                    type: string
                    const: event_replay
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/EventReplayEvent'
                  has_more:
                    type: boolean
                  next_cursor:
                    type: string
                  meta:
                    $ref: '#/components/schemas/EventReplayMeta'
              examples:
                success:
                  summary: Successful response
                  value:
                    object: event_replay
                    data: []
                    has_more: false
                    next_cursor: ZWYyXzBfMA
                    meta:
                      request_id: req_example
                      cached: false
                      cost: 1
                      replay:
                        from_cursor: ZWYyXzBfMA
                        to_cursor: ZWYyXzBfMA
                        from_sequence: 0
                        to_sequence: 0
                        ordering: commit_visibility_then_id_asc
                        pending_beyond_horizon: false
                        expand: []
                      retention:
                        status: durable_database
                        retained_events: 0
                        cursor_expired: false
                      completeness:
                        status: caught_up
                        reason: >-
                          No durable public whale-trade events were found after
                          the requested cursor.
          headers:
            X-Query-Ignored:
              $ref: '#/components/headers/X-Query-Ignored'
            X-Effective-Query:
              $ref: '#/components/headers/X-Effective-Query'
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimit-Limit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimit-Remaining'
            RateLimit-Reset:
              $ref: '#/components/headers/RateLimit-Reset'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            X-Usage-Accounting:
              $ref: '#/components/headers/X-Usage-Accounting'
            Server-Timing:
              $ref: '#/components/headers/Server-Timing'
        '400':
          description: >-
            Invalid request parameter, or (error.reason cursor_expired, param
            cursor) a cursor presented under a filter set other than the one it
            was issued with: restart without a cursor under the new filters and
            continue with next_cursor.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '401':
          description: Missing or invalid API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '402':
          description: >-
            Active Pro subscription required. The key is valid but the account
            has no active Pro subscription; error.reason is
            subscription_inactive and error.message names the reactivation URL
            (https://0xinsider.com/billing). Permanent until a person
            reactivates: no Retry-After, never retry on a schedule.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '403':
          description: Account access denied
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '408':
          description: >-
            The handler did not answer inside the server's 30-second timeout.
            error.code is request_timeout. On GET and HEAD the response carries
            Retry-After and error.retry_at; on a mutation it carries neither,
            because the request may have completed on the server: check its
            state before repeating it, and reuse its Idempotency-Key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '423':
          description: Account is locked
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '429':
          description: >-
            Rate limit exceeded. Three independent budgets. (1) 100
            requests/minute per user (sliding window), on every authenticated
            route. (2) On the BATCH routes only: 2500 batch item units/minute
            per user, reserved before any item is executed. A batch with N
            requested items costs N item units, including duplicate and invalid
            items. 2500 = 100 requests x 25 items per batch, which is the most
            item work a key can buy through the request limiter at all: a caller
            may spend their entire 100-request minute on full 25-item batches
            without the item budget being what stops them. The REQUEST budget is
            the effective ceiling, and batching is never the more expensive
            choice. The item budget can still deny at a sliding-window boundary
            (both counters carry the previous window forward with a floor, and
            the item counter runs 25x the request counter), so honor a 429 from
            either. Over-quota batches return 429 with Retry-After plus
            RateLimit-Limit, RateLimit-Remaining, and RateLimit-Reset before any
            item work is done. (3) The monthly quota: Pro includes 500,000 and
            Max includes 2,000,000 authenticated requests per UTC calendar
            month. Over the plan's included requests: with pay as you go on, the
            excess bills at USD 0.20 per 1,000 on a monthly invoice, up to four
            times the included allowance (2,000,000 requests for Pro); without
            it, from October 1, 2026, the next request answers 429 rate_limited
            with error.reason monthly_quota_exceeded and a Retry-After to the
            month's reset. Pay-as-you-go accounts receive the same refusal at
            their ceiling. A refused request is not counted. Every authenticated
            response carries X-Monthly-Quota-Limit, X-Monthly-Quota-Remaining,
            and X-Monthly-Quota-Reset (unix seconds, the first of next month).
            (4) The per-address budget: 1200 requests/minute per IP, shared by
            every caller behind one address and counted before authentication,
            on every route. A 429 from it carries error.reason ip_rate_limited
            and describes that bucket in RateLimit-*; a throttled address
            (sustained over-limit traffic) carries error.reason ip_throttled
            with a Retry-After of minutes to days, and a request before it does
            not shorten the cooldown. Every 429 is the standard error envelope
            with meta.request_id equal to X-Request-Id.
          headers:
            Retry-After:
              description: Seconds until rate limit resets.
              schema:
                type: integer
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimit-Limit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimit-Remaining'
            RateLimit-Reset:
              $ref: '#/components/headers/RateLimit-Reset'
            X-RateLimit-Limit:
              schema:
                type: integer
            X-RateLimit-Remaining:
              schema:
                type: integer
            X-RateLimit-Reset:
              schema:
                type: integer
            X-Request-Id:
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '500':
          description: Unexpected server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '503':
          description: >-
            Redis-backed authenticated rate limiter unavailable; retry after the
            per-process outage cooldown
          headers:
            Retry-After:
              description: >-
                Seconds until the middleware will probe the Redis-backed rate
                limiter again.
              schema:
                type: integer
            X-Request-Id:
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
      x-codeSamples:
        - lang: curl
          label: cURL
          source: |-
            curl -sS \
              -H "Authorization: Bearer $OXINSIDER_API_KEY" \
              'https://api.0xinsider.com/api/v1/events/feed/since'
components:
  schemas:
    EventReplayEvent:
      type: object
      required:
        - id
        - type
        - cursor
        - sequence
        - published_at
        - payload
        - source
        - freshness
      properties:
        id:
          type: string
          description: >-
            Opaque event identity: the ef_-encoded whale_alerts.id, stable
            across cursor formats. Deduplicate on this, never on cursor or
            sequence.
        type:
          type: string
          enum:
            - whale_trades_inserted
        cursor:
          type: string
          description: >-
            Cursor positioned at this event: its (inserted_xid, id) commit-order
            position. Store the page's next_cursor to continue; this one resumes
            from exactly this event.
        sequence:
          type: integer
          minimum: 1
          description: >-
            whale_alerts.id of the event. Not monotonic across a replay: events
            arrive in commit order, so a lower id can follow a higher one when
            its write finished later. Order and resume by cursor, deduplicate by
            id.
        published_at:
          type: string
          format: date-time
        payload:
          type: object
          description: >-
            What the event announces. Every field is present on every event; a
            field added later is additive, so a client tolerates keys it does
            not know.
          required:
            - count
            - whale_alert_id
            - condition_id
            - trader_id
            - platform
          properties:
            count:
              type: integer
              minimum: 1
              description: >-
                Whale trades this event announces. One event is minted per
                stored whale trade, so this is 1.
            whale_alert_id:
              type: integer
              minimum: 1
              description: >-
                The raw whale_alerts.id of the trade, the same number as
                sequence. GET /api/v1/whale-trades/{id} accepts it and returns
                the trade with its wallet, grade, size, price and market.
            condition_id:
              type: string
              description: The Polymarket condition id of the market the trade was in.
            trader_id:
              type: integer
              description: >-
                0xinsider's numeric id for the wallet's trader row. It is not
                the trd_ id, which is derived from the address; read the address
                and grade from the whale trade.
            platform:
              type: string
              enum:
                - polymarket
              description: Provider discriminator. Polymarket only.
          additionalProperties: true
        trade:
          oneOf:
            - $ref: '#/components/schemas/LargeTrade'
            - type: 'null'
          description: >-
            Present only with expand=trade: the base trade fields for this row,
            read at request time from one query per page. GET
            /api/v1/large-trades/{id} adds counterparty_analysis; replay does
            not include it. traded_at, side, size_usd, price, outcome, token_id,
            recorded_signal_score and trader.grade_at_trade with its status are
            the row's event-time facts; trader.grade, trader.username,
            signal_score, suspicion_score, suspicion_track and market
            title/slug/category are enrichment that can move after the event.
            null when that route would answer 404 for the row (its trader or
            market is not synced yet).
        source:
          $ref: '#/components/schemas/EventReplaySource'
        freshness:
          $ref: '#/components/schemas/EventReplayFreshness'
    EventReplayMeta:
      type: object
      required:
        - request_id
        - cached
        - cost
        - replay
        - retention
        - completeness
      properties:
        request_id:
          type: string
          description: >-
            Unique request ID (req_ prefix). The same value as the X-Request-Id
            response header, the request's usage accounting row and its log
            lines.
        cached:
          type: boolean
        cache_age_s:
          type: integer
        cost:
          type: integer
          description: >-
            Advisory request weight (relative compute cost). 1 for simple reads;
            higher for heavier endpoints. Not a credit/price.
        replay:
          type: object
          required:
            - from_cursor
            - to_cursor
            - from_sequence
            - to_sequence
            - ordering
            - pending_beyond_horizon
            - expand
          properties:
            from_cursor:
              type: string
              description: >-
                The request cursor in canonical form (an id-only cursor is
                re-encoded), or the zero position when omitted.
            to_cursor:
              type: string
              description: >-
                Identical to next_cursor. After a full page, the cursor of the
                last event; after a page that is not full, the commit horizon
                itself, since every row below it, matching or not, has been
                examined. An empty page therefore still advances.
            from_sequence:
              type: integer
              minimum: 0
              description: >-
                whale_alerts.id component of the request cursor (0 when
                omitted).
            to_sequence:
              type: integer
              minimum: 0
              description: >-
                whale_alerts.id of the last event on this page, or from_sequence
                when the page is empty. Can sit below the position next_cursor
                encodes after a page that is not full.
            ordering:
              type: string
              const: commit_visibility_then_id_asc
              description: >-
                Events are ordered by the position at which their write became
                visible (whale_alerts.inserted_xid), then by whale_alerts.id,
                and a page is bounded by the oldest write transaction still open
                when it was read. Before 2026-09-22 this read
                whale_alerts_id_asc; that order could skip a late-committing
                lower id (#16180).
            pending_beyond_horizon:
              type: boolean
              description: >-
                True when committed whale-trade rows newer than this page's
                commit-visibility horizon exist. They are held until every older
                write transaction has finished and are served on a later
                request, so a caught_up page with this true is not the end of
                the stream: poll again. A long open write transaction on the
                database (a single-transaction backfill) is what keeps this true
                for more than a few seconds.
            filters:
              type: object
              description: >-
                The effective filter set this page ran with and next_cursor is
                bound to. Absent on an unfiltered walk.
              properties:
                trader:
                  type: string
                  description: The trader parameter as given.
                condition_id:
                  type: string
                  description: The raw provider condition id after mkt_ is stripped.
                min_grade:
                  type: string
                  enum:
                    - S
                    - A
                    - B
                    - C
                    - D
                    - F
                min_size:
                  type: number
            expand:
              type: array
              items:
                type: string
                enum:
                  - trade
              description: >-
                The expansions applied to every event on this page; empty when
                none.
        retention:
          type: object
          required:
            - status
            - retained_events
            - cursor_expired
          properties:
            status:
              type: string
              enum:
                - durable_database
            retained_events:
              type: integer
              minimum: 0
            cursor_expired:
              type: boolean
              const: false
        completeness:
          type: object
          required:
            - status
            - reason
          properties:
            status:
              type: string
              enum:
                - complete
                - caught_up
              description: >-
                complete: the page carries every durable event matching the
                filters after the cursor below the commit horizon, up to limit.
                caught_up: nothing matching after the cursor is visible below
                the horizon; read pending_beyond_horizon to tell an idle stream
                from held rows, and note next_cursor has still advanced to the
                horizon.
            reason:
              type: string
    ApiError:
      type: object
      required:
        - object
        - error
        - meta
      properties:
        object:
          type: string
          const: error
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              description: >-
                FROZEN: an existing value never changes meaning. request_timeout
                (408, #16146) was added the way insufficient_scope was: the
                handler did not answer inside the server's 30-second timeout.
                Retry-After and retry_at ride on it only for a safe method (GET,
                HEAD); a timed-out mutation may have completed, so check its
                state and reuse its Idempotency-Key.
              enum:
                - bad_request
                - invalid_api_key
                - subscription_required
                - forbidden
                - insufficient_scope
                - not_found
                - account_locked
                - rate_limited
                - rate_limit_unavailable
                - internal_error
                - request_timeout
            message:
              type: string
            doc_url:
              type: string
            param:
              type: string
            retry_at:
              type: string
              format: date-time
              description: >-
                The recommended next request instant (RFC3339), always in the
                future. Present on every retryable error: `pick_not_released`,
                `rate_limited`, `rate_limit_unavailable`, and
                `read_model_warming`. Omitted otherwise. The absolute twin of
                `Retry-After`; prefer the header for the sleep duration. For
                `pick_not_released`, the earliest of the next scheduled release,
                the next automatic selector attempt, the operating-window start,
                or about 60 seconds. See that response.
            freshness:
              $ref: '#/components/schemas/FreshnessFailure'
            reason:
              type: string
              enum:
                - cursor_expired
                - unknown_endpoint
                - pick_not_released
                - trader_not_tracked
                - read_model_warming
                - database_unavailable
                - request_accounting_unavailable
                - idempotency_in_progress
                - webhook_delivery_in_progress
                - webhook_secret_rotation_not_prepared
                - webhook_secret_rotation_overlap_active
                - sandbox_api_key
                - api_key_in_query
                - subscription_inactive
                - monthly_quota_exceeded
                - invalid_query
                - unknown_query_parameter
                - invalid_path
                - invalid_body
                - unsupported_media_type
                - payload_too_large
                - method_not_allowed
                - ip_rate_limited
                - ip_throttled
                - export_expired
                - freshness_ceiling_unsatisfied
              description: >-
                ADDITIVE (#7209). The specific, actionable cause behind `code`,
                when there is one more specific than the code itself. `code`
                keeps its published values, so existing clients are unaffected;
                new clients branch on `reason`. Omitted when the code already
                says everything we know. pick_not_released: no Pick of the Day
                is published for the current product day; schedule one request
                against retry_at instead of polling. unknown_endpoint: the PATH
                is not a route on this API -- read GET /api/v1, do not retry.
                trader_not_tracked: the wallet is real and the URL is right, but
                the trader is outside the HOT/WARM sync tiers -- stop asking for
                this wallet. cursor_expired: pagination went stale mid-walk --
                re-request the first page and continue. read_model_warming: the
                requested endpoint cannot serve its read model yet; exact causes
                are endpoint-specific and can include a cold or contended
                refresh or a dependency that prevented refresh.
                database_unavailable: the API's database or its connection pool
                is temporarily unreachable (a connection-class failure, not a
                query fault); code stays rate_limit_unavailable, nothing is
                rate-limited, retry after Retry-After / retry_at.
                idempotency_in_progress: retain the exact Idempotency-Key and
                request body, then retry shortly. webhook_delivery_in_progress:
                retry the URL or signing-secret configuration change after the
                destination's active request completes.
                request_accounting_unavailable: accounting capacity is
                unavailable before the handler executes; retry after Retry-After
                / retry_at. sandbox_api_key: the credential is a sandbox key
                (oxi_sk_test_) from POST /api/v1/agents/register, which only the
                sandbox server accepts -- call the sandbox base URL with it, or
                get a live key or OAuth access token; do not retry it here.
                api_key_in_query: the key was sent as a ?token= query parameter,
                which no route reads because URLs land in logs and history; the
                key itself was not checked -- resend it as Authorization:
                Bearer. subscription_inactive: the key is valid but the
                account's Pro subscription has lapsed (402
                subscription_required); permanent until a person reactivates at
                https://0xinsider.com/billing, which the message names -- stop
                retrying on a schedule and surface the link. The key owner is
                emailed once per lapse. monthly_quota_exceeded: the account has
                used the requests Pro includes for the UTC calendar month (429
                rate_limited); retry_at and Retry-After name the first of next
                month, the only retry that can succeed, and the message names
                https://0xinsider.com/developers, where pay as you go for
                requests over the quota is turned on. The X-Monthly-Quota-Limit,
                X-Monthly-Quota-Remaining and X-Monthly-Quota-Reset headers on
                every authenticated response say how close the account is.
                invalid_query, invalid_path, invalid_body (400 bad_request,
                #16146): a query parameter, a path segment or the JSON body did
                not parse or does not fit the route's schema, so no handler ran;
                param names the field when the parser named one (a query key, a
                path segment, a JSON path such as traders[0], or body); fix the
                request, never retry it as sent. unsupported_media_type (415
                bad_request, param content-type): send the body with
                Content-Type: application/json. payload_too_large (413
                bad_request, param body): the body is over 1048576 bytes.
                method_not_allowed (405 bad_request): the path is a route but
                not with this method; the Allow header names the methods it
                serves. ip_rate_limited (429 rate_limited, #16380): the
                per-address budget every caller behind one IP shares, counted
                before authentication, is spent; not the key's own window, and
                the RateLimit-* headers describe that bucket. ip_throttled (429
                rate_limited): the address is in a cooldown after sustained
                over-limit traffic; Retry-After is minutes to days, and a
                request before it does not shorten the cooldown.
        meta:
          $ref: '#/components/schemas/ResponseMeta'
    LargeTrade:
      type: object
      required:
        - id
        - traded_at
        - size_usd
        - side
        - outcome
        - token_id
        - price
        - review_score
        - signal_score
        - recorded_review_score
        - recorded_signal_score
        - suspicion_score
        - suspicion_track
        - trader
        - market
      properties:
        id:
          type: string
          description: Prefixed ID (wt_...).
        traded_at:
          type: string
          format: date-time
        size_usd:
          type: number
        side:
          type: string
          enum:
            - BUY
            - SELL
        outcome:
          type: string
          nullable: true
          description: >-
            Traded outcome label (e.g. "Yes"/"No"/team name), resolved
            provider-first from the trade's outcome_index against
            market_canonical (index 0 -> yes, 1 -> no). Distinct axis from side
            (BUY/SELL): side is the trade direction, outcome is which leg was
            traded. null for multi-outcome (outcome_index >= 2) or unsynced
            markets, and for a Polymarket trade recorded before
            2026-04-02T00:00:00Z, whose stored outcome_index is not trusted (a
            defaulted 0 for about a third of those rows; the side is unknown,
            not defaulted).
        token_id:
          type: string
          nullable: true
          description: >-
            The Polymarket CLOB token id (ERC1155 asset id, decimal string) for
            the traded outcome; null when unavailable (e.g. unsynced markets)
            and for a Polymarket trade recorded before 2026-04-02T00:00:00Z,
            where the traded side is unknown.
        price:
          type: number
        review_score:
          type: number
          description: >-
            Current trade review score on a 0..1 scale; higher values indicate a
            stronger review signal. This is the current response value and can
            differ from the recorded score. Missing measurements remain
            unavailable.
        signal_score:
          deprecated: true
          type: number
          description: >-
            Deprecated alias of review_score with the same current value and
            0..1 scale.
        recorded_review_score:
          type: number
          nullable: true
          description: >-
            0.0–1.0 review score written once when the trade row is inserted,
            from the trader's statistics at that moment. Populated from
            2026-08-03T11:59Z; older rows return null and are never backfilled,
            because a backfill could only read today's statistics. If a trade is
            added later, its time-sensitive recorded score reflects that delay.
            Canonical since #16311; recorded_signal_score carries the same
            value.
        recorded_signal_score:
          deprecated: true
          type: number
          nullable: true
          description: >-
            0.0–1.0 review score written once when the trade row is inserted;
            null before 2026-08-03T11:59Z. Deprecated (#16311):
            `recorded_review_score` is the canonical spelling and carries the
            same value; this key stays on the wire.
        suspicion_score:
          type: integer
          minimum: 0
          maximum: 100
          nullable: true
          description: >-
            Persisted live suspicion score from the scorer. Null when the row
            has no persisted score.
        suspicion_track:
          type: string
          enum:
            - whale
            - fresh_conviction
            - sliced_position
          nullable: true
          description: >-
            Persisted scorer track. Null when a legacy row has no stored track
            label.
        market_volume_share:
          type: number
          minimum: 0
          maximum: 1
          description: >-
            This fill's size relative to its market: size_usd divided by a
            market volume figure recorded at or after the trade, so the value
            always falls between 0 and 1 inclusive. A $10,000 fill is 0.00005 of
            a $200M market and 0.125 of an $80,000 one, which size_usd alone
            cannot distinguish. Absent when no volume figure recorded at or
            after the trade is available; never 0 as a stand-in and never capped
            at 1, because a denominator we cannot trust publishes nothing rather
            than a trimmed number. A market's volume keeps growing, so the same
            trade reports a smaller share as the market trades on.
        trader:
          type: object
          required:
            - id
            - address
            - grade_at_trade
            - grade_at_trade_status
          properties:
            id:
              type: string
            address:
              type: string
            username:
              type: string
            grade:
              type: string
              description: >-
                The trader's grade today, on every row however old. For what the
                grade was when the trade happened, read grade_at_trade.
            grade_at_trade:
              type: string
              enum:
                - S
                - A
                - B
                - C
                - D
                - F
              nullable: true
              description: >-
                The grade the trader held when the trade happened, from recorded
                grade history (recorded from 2026-09-19T23:00Z). Null unless
                grade_at_trade_status is graded. Never today's grade projected
                backward.
            grade_at_trade_status:
              type: string
              enum:
                - graded
                - ungraded
                - unknown
              description: >-
                graded: grade_at_trade holds the recorded grade. ungraded: the
                trader was recorded without a grade at that moment. unknown: no
                record covers the moment, which is every trade before
                2026-09-19T23:00Z and a trade that fell between a grade change
                and its confirmation. unknown never means ungraded.
        market:
          type: object
          required:
            - id
            - condition_id
            - title
          properties:
            id:
              type: string
            condition_id:
              type: string
            title:
              type: string
            slug:
              type: string
            category:
              type: string
              description: Provider-backed market_canonical category.
    EventReplaySource:
      type: object
      required:
        - kind
        - producer_family
        - owner
        - provider_fetch_at_request_time
      properties:
        kind:
          type: string
          const: local_durable_replay
        producer_family:
          type: string
          enum:
            - whale_trades
        owner:
          type: string
          const: whale_alerts
        provider_fetch_at_request_time:
          type: boolean
          const: false
    EventReplayFreshness:
      type: object
      required:
        - status
        - observed_at
      properties:
        status:
          type: string
          const: observed
        observed_at:
          type: string
          format: date-time
    FreshnessFailure:
      type: object
      required:
        - max_age_s
        - data_quality_status
      properties:
        max_age_s:
          type: integer
          format: int64
          minimum: 0
          description: The caller's requested whole-response freshness ceiling in seconds.
        actual_age_s:
          type: integer
          format: int64
          minimum: 0
          description: >-
            Age in seconds of the oldest stored data_quality.as_of clock, when
            one is available.
        as_of:
          type: string
          format: date-time
          description: >-
            The oldest stored data-quality clock used to calculate actual_age_s,
            when one is available.
        data_quality_status:
          type: string
          enum:
            - fresh
            - partial
            - unknown
            - untracked
            - unavailable
          description: >-
            The trader body's whole-response data-quality status. Only fresh can
            satisfy max_age_s.
    ResponseMeta:
      type: object
      required:
        - request_id
        - cached
        - cost
      properties:
        request_id:
          type: string
          description: >-
            Unique request ID (req_ prefix). The same value as the X-Request-Id
            response header, the request's usage accounting row and its log
            lines.
        cached:
          type: boolean
        cache_age_s:
          type: integer
          description: >-
            Cache age in seconds. Omitted when the response was not cached, and
            also when it was cached but its age cannot be established (an entry
            stored before its cache carried a computed instant). Never a
            placeholder: an unknown age is reported as no value rather than as
            the cache TTL.
        cost:
          type: integer
          description: >-
            Advisory request weight (relative compute cost). 1 for simple reads;
            higher for heavier endpoints. Not a credit/price.
        ranking_generation:
          type: integer
          description: >-
            Committed PostgreSQL-owned leaderboard generation for the returned
            rows and cursor. Present on GET /api/v1/leaderboard; omitted on
            endpoints that do not read this ranking.
        ranking_as_of:
          type: string
          format: date-time
          description: >-
            Authoritative RFC3339 timestamp from cache_generations.updated_at
            for ranking_generation. It is read in the same repeatable-read
            snapshot as the leaderboard rows and is not request time, cache
            write time, or row insertion order.
        directional_source:
          type: string
          enum:
            - live
            - degraded
          description: >-
            Which path produced the team-directional read on this response. Only
            present on endpoints that compute one (today: GET
            /api/v1/sports-edge-signals). "live" means the read RAN. "degraded"
            means it FAILED, so nothing was measured and the ranking fell back
            to raw conviction. The flag describes the READ, not its consequence:
            a read that ran and found nothing groupable also leaves the
            directional fields null, and that is honestly "live" -- the
            per-signal nulls already say "nothing to enrich here", so this
            snapshot-level flag carries only what they cannot, namely whether
            the read ran at all. A degraded response is cached on the shorter
            degraded TTL so it self-heals. Reported SEPARATELY from
            ranking_source because the two degradations are independent -- a
            sharp-money DB miss weakens the ranking DATA, a directional failure
            removes a ranking WEIGHT -- and a consumer down-weighting a degraded
            response needs to know which input it lost. Omitted on endpoints
            that compute no directional read.
        ranking_source:
          type: string
          enum:
            - live
            - db_only
          description: >-
            Which ranking-data path produced this response. Only present on
            endpoints that can degrade a ranking (today: GET
            /api/v1/sports-edge-signals). "live" is the normal path (the current
            holder pile from the provider batch); "db_only" is the degraded
            fallback (a truthful but weaker trader_markets ranking) served when
            the live sharp-money ranking batch is unavailable (a sharp-money DB
            read failure, not a Polymarket outage) and cached on a shorter TTL,
            so a consumer can down-weight or skip it. Omitted on endpoints that
            never degrade.
        category_skill_source:
          type: string
          enum:
            - live
            - partial
            - degraded
            - unavailable
          description: >-
            Whole filtered snapshot category-evidence status before pagination.
            Operational live always remains partial source coverage.
        category_skill_model_version:
          type: string
        category_skill_taxonomy_version:
          type: string
        category_skill_platform:
          type: string
          const: polymarket
        category_skill_scope:
          type: string
          const: observed_goldsky_primary_taker_fill
        category_skill_source_coverage:
          type: string
          enum:
            - partial_whale_threshold_fills
            - graded_wallet_fills
        category_skill_observation_started_at:
          type: string
          format: date-time
        category_skill_model_operationally_degraded:
          type: boolean
          description: >-
            Whole-model operational readiness captured with the category model
            snapshot. Present on category-enriched responses even when the
            filtered signal list is empty. When true, category_skill_source is
            degraded and sports-edge-signals uses the shorter degraded cache
            TTL.
        category_skill_status_counts:
          type: object
          required:
            - live
            - insufficient
            - stale
            - unknown
            - degraded
          properties:
            live:
              type: integer
              minimum: 0
            insufficient:
              type: integer
              minimum: 0
            stale:
              type: integer
              minimum: 0
            unknown:
              type: integer
              minimum: 0
            degraded:
              type: integer
              minimum: 0
        category_skill_base_payload_hash:
          type: string
          pattern: ^[0-9a-f]{64}$
          description: >-
            SHA-256 of the funded signal membership/order/rank/cursor vector
            immediately before category-skill enrichment. Sports-edge-signals
            only.
        category_skill_enriched_base_payload_hash:
          type: string
          pattern: ^[0-9a-f]{64}$
          description: >-
            Independent SHA-256 recomputation over the same base fields
            immediately after category-skill enrichment. Equality with
            category_skill_base_payload_hash proves shadow enrichment did not
            change funded inputs. Sports-edge-signals only.
  headers:
    X-Query-Ignored:
      description: >-
        Comma-separated, percent-encoded query names the operation did not
        publish and therefore ignored in compatible mode. Names are sorted and
        de-duplicated.
      schema:
        type: string
    X-Effective-Query:
      description: >-
        Normalized, percent-encoded query string containing only the recognized
        names and values applied by the operation. Query names and values use
        form-urlencoded decoding, where + is a space. Repeated names are
        retained and sorted by name. A limit outside the operation's published
        minimum..maximum is reported as the clamped value the page used, so the
        header states the page size served rather than the one requested.
      schema:
        type: string
    RateLimit-Limit:
      description: >-
        Request limit of the budget this request was counted against, for its
        current window: the API key's per-minute sliding window on an
        authenticated call; the per-IP budget on a public route and on a refused
        credential (401, 402, 403, 423), which never reaches the per-key
        limiter. Standard RateLimit header spelling.
      schema:
        type: integer
        example: 100
    RateLimit-Remaining:
      description: >-
        Requests remaining in that budget's current window after this response.
        Standard RateLimit header spelling.
      schema:
        type: integer
        example: 84
    RateLimit-Reset:
      description: >-
        Seconds until that budget's current window resets. Standard RateLimit
        header spelling.
      schema:
        type: integer
        example: 42
    X-RateLimit-Limit:
      description: >-
        Request limit of the budget this request was counted against, for its
        current window: the API key's per-minute sliding window on an
        authenticated call; the per-IP budget on a public route and on a refused
        credential (401, 402, 403, 423).
      schema:
        type: integer
        example: 100
    X-RateLimit-Remaining:
      description: Requests remaining in that budget's current window after this response.
      schema:
        type: integer
        example: 84
    X-RateLimit-Reset:
      description: Unix timestamp when that budget's current window resets.
      schema:
        type: integer
        example: 1710772860
    X-Request-Id:
      description: >-
        Server-generated request identifier for support and tracing. On every
        /api/v1 response, including 304, 408, CORS preflights and every error,
        and always equal to meta.request_id in the body. It is the key of the
        request's usage accounting row and of every log line the request
        emitted, so quote either form to support. A client-supplied X-Request-Id
        request header is ignored: the value is never adopted or echoed.
      schema:
        type: string
        example: req_550e8400
    X-Usage-Accounting:
      description: >-
        Usage-record persistence for a protected V1 handler response. persisted:
        confirmed row; failed: write failed; unknown: completion could not be
        confirmed. Independent of handler success; do not replay successful
        mutations to repair accounting. Absent before accounting admission and
        on public routes. The zero-cost /api/v1/usage route also omits it.
      schema:
        type: string
        enum:
          - persisted
          - failed
          - unknown
    Server-Timing:
      description: >-
        Processing time in milliseconds, for example api;dur=12.345. Includes
        API authentication, quota admission, handler work and response
        construction. Excludes network transit and streamed body or export-file
        transfer. The engineering budget is strictly below 250 ms; this header
        reports observations, not a latency guarantee or a new timeout.
      schema:
        type: string
      example: api;dur=12.345
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Legacy default or named integration API key, or OAuth 2.1 access token,
        in the Authorization header as `Bearer oxi_sk_live_...` or `Bearer
        oxi_at_...`. Default keys retain full access; integration keys are
        limited to their approved read, webhooks, export and usage scopes and
        expire within 90 days. All credentials share the owner's account limits.
        Data calls require an active Pro subscription and return live data. A
        401 carries WWW-Authenticate: Bearer
        resource_metadata="https://api.0xinsider.com/.well-known/oauth-protected-resource"
        (RFC 6750 section 3, RFC 9728).
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.1 authorization code flow with PKCE S256 for apps and MCP
        clients acting for a user. Public clients only (no client secret):
        register with RFC 7591 at https://api.0xinsider.com/oauth/register or
        present an https client ID metadata document URL as client_id.
        Authorization server metadata:
        https://api.0xinsider.com/.well-known/oauth-authorization-server. The
        access token (oxi_at_..., one hour) is sent as `Authorization: Bearer`;
        refresh tokens rotate on every use. A route outside the token's scopes
        answers 403 insufficient_scope. Walkthrough:
        https://0xinsider.com/auth.md.
      flows:
        authorizationCode:
          authorizationUrl: https://0xinsider.com/oauth/authorize
          tokenUrl: https://api.0xinsider.com/oauth/token
          refreshUrl: https://api.0xinsider.com/oauth/token
          scopes:
            read: >-
              Read markets, traders, large trades, positions, reports, search,
              the event stream and every MCP tool
            webhooks: Create, list, verify, rotate and delete webhook endpoints
            export: Start, poll and download trader exports
            usage: Read the caller's API usage counters

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.