Skip to main content
Most API endpoints require an active Pro or Max subscription and a Bearer credential. Send a live API key or an OAuth access token in the Authorization header:

Get your first key

1

Subscribe to Pro or Max

Choose a plan on Pricing.
2

Create a key

Open Developers and click Create key. Copy the full key; it is shown once.
3

Save it on your server

Read the key from your environment or a secret manager. Use the environment variable OXINSIDER_API_KEY with the official clients.
The Developers page later shows only the prefix and the first 4 hex characters. If you lose the full key, create a replacement and revoke the lost key. You can build against the sandbox before subscribing. It requires no credential and returns sample data.

Choose a credential

Live API keys start with oxi_sk_live_, followed by 64 hex characters, for 76 characters total. OAuth access tokens start with oxi_at_, followed by 64 hex characters; their oxi_rt_ refresh tokens last 30 days. An account can have multiple active default keys and up to 10 named integrations. Creating a default key keeps your existing keys valid. During rotation, an integration can temporarily have 2 live keys; the server stores key hashes, rather than the original secrets. OAuth supports authorization code with PKCE and device authorization for a headless agent or CLI. Follow the OAuth instructions to build either flow.

Set scopes

Default keys carry all 4 scopes. Integration keys and OAuth tokens must include the scope required by the endpoint: A missing scope returns 403 insufficient_scope. The WWW-Authenticate header names the scope you need.

Keep credentials private

Never put a live key in a public browser bundle, mobile binary, repository, Dockerfile, or command-line argument. Anyone who copies it can use its permissions.
Give each integration only the scopes it needs. For an MCP client, use its environment configuration or a secret store rather than including the secret in its arguments. Keys in URLs are also refused. On an authenticated endpoint, ?token= returns 401 invalid_api_key with error.reason set to api_key_in_query; move it to the Bearer header.

Endpoints that need no credential

Public API endpoints ignore a supplied credential and a ?token= parameter. Other data endpoints, Remote MCP tools/call, and the live event stream require a valid credential and active Pro or Max access.

Manage your live API keys

Click Create key on Developers to add a key. Each key stays valid until you revoke it. Click Revoke beside a key to stop only that key; your other keys keep working. These account-management endpoints require a signed-in Pro or Max website session. A developer API key does not authenticate them. To replace a key, create a new one, update every consumer that uses the old key, and revoke the old key. If a key appears in a log, commit, or shared terminal, revoke it immediately. Requests using a revoked key return 401 invalid_api_key. The legacy POST /api/keys/regenerate endpoint still revokes every active default key and creates 1 replacement. Use it only when you intend to replace all default keys. Named integration keys and OAuth tokens are unaffected.

Manage an integration key

These account-management endpoints require a signed-in Pro or Max website session. A developer API key does not authenticate them. For example, this creation body permits API reads and usage inspection, but excludes webhook management and exports:
Creation returns the full key once and its stable integration_id. Rotation returns a new key and overlap_ends_at; switch consumers before that time. The rotation overlap lasts 15 minutes. A 409 means a prior overlap is still active; wait for it to end or revoke the integration. Revocation stops both keys immediately. Listing returns prefixes, scopes, expiry, last use, revocation, and monthly counts without exposing secrets. The default page has at most 100 rows, the maximum is 200, and next_before_id becomes the next request’s before_id. Usage totals update every 5 minutes.

Fix an authentication error

Limits

A 0xinsider credential cannot place a Polymarket order and contains no Polymarket trading credential. All of an account’s API keys and OAuth tokens share its rate limits; creating another key does not create another allowance.