0xinsider command to read markets, wallets, large trades, positions, picks, reports, and your account usage. Data commands print JSON. login and logout manage the CLI’s session.
You need Node.js 22 or newer and an active Pro or Max account. For example data without an account, use the sandbox; the CLI has no sandbox mode.
Install and sign in
login prints a verification URL and a code, then waits for approval. Open the URL, sign in, confirm the code, and approve the read and usage scopes. The CLI never asks for your password or API key during sign-in.
The browser does not open automatically. You can sign in from another device when the terminal has no browser. Ctrl-C cancels the wait; if you already approved the connection, revoke it on Developers.
Upgrade or switch packages
0xinsider@2 installs the same runtime as @0xinsider/mcp@2. 0xinsider --version reports the runtime version. To try the command without installing it globally, run npx --yes 0xinsider@2 --help.
The install command upgrades 0xinsider@1 in place. If you already installed @0xinsider/mcp globally, keep using it or uninstall it before switching: npm uninstall --global @0xinsider/mcp. Both packages install the same executable, so do not install both globally or overwrite one with --force.
The 1.x package is the older MCP runtime for Node.js 18 or 20. It has no product CLI commands. Homebrew uses a separate release channel; the commands on this page use npm.
Use an API key in scripts
SetOXINSIDER_API_KEY in your environment, then run a data command. This works for agents, CI, and Windows, where stored sign-in sessions are unavailable.
The environment key takes precedence over a stored session. The CLI never saves it, and logout does not revoke it. Pass credentials through the environment, never through --query token=... or a URL.
Commands
Each command below reads one endpoint.login, logout, and completions are covered in their own sections.
api call refuses every mutation, and it refuses the webhook, stream, MCP, export, and Markdown routes even though they are reads.
Options
complete is false, next_cursor contains the continuation point, and the command exits with code 8. Save that cursor to continue later.
If a later page fails, the output retains the pages already fetched and stderr reports where to resume. A nonzero exit means you must check whether the result is incomplete.
Sign out and manage the session
logout revokes the stored connection before deleting its file. If revocation fails, the file stays so you can retry. To change accounts, log out first; login refuses to replace an existing session.
The file is $XDG_CONFIG_HOME/0xinsider/cli/session.json, or ~/.config/0xinsider/cli/session.json when XDG_CONFIG_HOME is unset. OXINSIDER_CONFIG_DIR overrides the directory. The file permissions are 0600, and its directory permissions are 0700.
The session works only with the API origin that issued it. OXINSIDER_API_URL accepts the production origin or a loopback development origin.
A session.lock blocks session commands while another process owns the session. After a crash, check the lock’s owner.json and confirm that process has stopped before removing the lock.
Exit codes
--help, --version, and completions bash|zsh|fish work offline without credentials.
| Exit | Meaning || --- | --- |
| 0 | Success. |
| 2 | A command or parameter error, or the API answered 400. |
| 3 | The credential is missing, invalid, or revoked (401). |
| 4 | Subscription, scope, or account access was denied (402, 403, 423). |
| 5 | Rate limited (429). |
| 6 | An upstream, storage, or response-contract failure. |
| 7 | A network or timeout failure. |
| 8 | The --pages bound was reached before the traversal finished. |
| 130 | Interrupted. |
A connection failure or interrupted response body exits with code 7. Invalid JSON or an invalid response shape exits with code 6. Ctrl-C exits with code 130.
Sign-in registration, token refresh, and revocation are not retried automatically. If their response is lost, the operation may have completed; follow the session’s recovery instructions before retrying. Failure messages identify the error without printing response bodies or credentials.
Limits
- Data commands require Pro or Max access. A lapsed subscription exits with code 4.
- The CLI does not place orders or provide webhook management commands.
- Running
0xinsiderwith no arguments, or withserve, starts the stdio MCP server.initconfigures an MCP client. - The MCP server reads
OXINSIDER_API_KEY; it does not use a CLI sign-in session.