> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omnibook.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# The authenticated key's own scopes and rate limits

> Reports the calling key's scopes, effective read/write/cancel token
buckets, trailing 30-day fill volume, write-rate floor, dollars per extra
write/s, batch cap, and per-request response budget.
Answered from the key record + gateway config, so it carries no
`as_of_seq`. There are no named usage tiers.




## OpenAPI

````yaml /api-spec/venue-openapi.yaml get /v1/account/limits
openapi: 3.1.0
info:
  title: Exchange API — REST lane
  version: 1.0.0
  summary: Client-facing REST surface for the binary prediction-market exchange.
  description: |
    The client-visible REST contract of the API lane.

    ## Conventions
    - **Versioning:** every path is under `/v1/`. Unknown *request* fields are
      rejected (`400 unknown_field`); clients MUST ignore unknown *response*
      fields (additive changes are non-breaking).
    - **Numbers:** prices are integer **ticks** in **pips** (1–9999; 1 pip =
      0.01¢; `$1 = 10_000` pips). Quantities are integer shares; money is
      integer pips. u64-domain values (`order_id`, `client_order_id`, `seq`,
      pip amounts, timestamps) render as decimal **strings**; u32-and-below
      render as JSON numbers. Floats never appear. Old cent-era ticks 1–99
      are rejected (`bad_price_tick`), never scaled.
    - **Timestamps:** `ts`/`*_ts` fields are nanoseconds since the Unix epoch as
      decimal strings — the sequencer's stamp, untranslated.
    - **`as_of_seq`:** every read response carries the stream sequence number
      its answer is current as of. Two reads with the same `as_of_seq` describe
      one consistent instant.
    - **Pagination:** list endpoints take `limit` (default 100, max 1000) and an
      opaque `cursor`; responses echo `cursor` for the next page (empty string
      when exhausted).

    ## Authentication
    Every request — there is no anonymous surface — carries three headers:
    `DX-ACCESS-KEY`, `DX-ACCESS-TIMESTAMP` (Unix ms), and `DX-ACCESS-SIGNATURE`
    (base64 HMAC-SHA256 over the canonical string
    `timestamp + "\n" + METHOD + "\n" + path?query + "\n" + body`, ±5000 ms
    replay window). Keys carry scopes `read` (GETs), `trade` (order mutations),
    and `withdraw` (`POST /v1/withdrawals`); the required scope per operation
    is given in `x-required-scope`. Rate limits are per-key token buckets
    (read 100/s +200 burst; write volume-scaled, floor 20/s burst = rate,
    cap 400/s; cancel is `2 ×` write; 1 token per HTTP request, including
    batches) answered with `429
    rate_limited` whose body carries `details.retry_after_ms` (decimal-string
    milliseconds — no `Retry-After` header in v1).

    ## Execution outcomes are not errors
    Post-only cross, FOK infeasible, IOC remainder, STP and max-cost-infeasible
    arrive as a **successful** placement response with `status: "canceled"` and
    a `reason` — they are the order's history, not a protocol failure. Only the
    reject taxonomy maps to non-2xx.
  x-other-lanes:
    websocket:
      endpoint: wss://{host}/v1/ws
      note: >-
        AsyncAPI territory — subscribe/unsubscribe command envelope, public
        channels (orderbook_snapshot, orderbook_delta, trades, oracle, rounds)
        and the private `user` channel with snapshot+resume. `ticker` is
        deferred (wscode 4). Not modelled in this OpenAPI document.
    mcp:
      endpoint: POST /v1/mcp
      note: >-
        JSON-RPC 2.0 agent lane exposing the same reads/writes as MCP tools.
        Described by its own tool schema, not OpenAPI.
servers:
  - url: https://api.omnibook.xyz
    description: >-
      Production. Every request is authenticated — there is no anonymous access,
      including market data. See Authentication.
security:
  - DxAccessKey: []
    DxAccessTimestamp: []
    DxAccessSignature: []
tags:
  - name: Exchange
    description: Exchange-wide control state and retention caps.
  - name: Account
    description: The authenticated key's own scopes and rate limits.
  - name: Markets
    description: Market metadata, orderbooks, public tape, oracle and rounds.
  - name: Portfolio (read)
    description: Key-scoped balance, positions, fills and orders.
  - name: Orders (write)
    description: Order placement, cancel, decrease, batch, cancel-batch and cancel-all.
  - name: Funding
    description: Deposit address and withdrawals.
  - name: Admin
    description: >
      Control-plane operator actions. Served on a SEPARATE listener from every
      path above — see the operation's own `servers` override; the top-level
      `servers` block does not reach it.
externalDocs:
  description: Normative API surface specification (REST + WebSocket).
  url: https://docs.omnibook.xyz/
paths:
  /v1/account/limits:
    get:
      tags:
        - Account
      summary: The authenticated key's own scopes and rate limits
      description: >
        Reports the calling key's scopes, effective read/write/cancel token

        buckets, trailing 30-day fill volume, write-rate floor, dollars per
        extra

        write/s, batch cap, and per-request response budget.

        Answered from the key record + gateway config, so it carries no

        `as_of_seq`. There are no named usage tiers.
      operationId: getAccountLimits
      responses:
        '200':
          description: The key's scopes and limits.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountLimits'
              example:
                scopes:
                  - read
                  - trade
                read:
                  sustained_rate_per_s: 100
                  burst: 200
                write:
                  sustained_rate_per_s: 50
                  burst: 50
                cancel:
                  sustained_rate_per_s: 100
                  burst: 100
                trailing_volume_30d: '0'
                write_floor: 20
                usd_per_extra_rps: 100000
                batch_cap: 20
                response_budget_ms: 2000
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/MissingScope'
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  schemas:
    AccountLimits:
      type: object
      description: The authenticated key's scopes and limits.
      properties:
        scopes:
          type: array
          items:
            type: string
            enum:
              - read
              - trade
              - withdraw
        read:
          $ref: '#/components/schemas/RateBucket'
        write:
          $ref: '#/components/schemas/RateBucket'
        cancel:
          $ref: '#/components/schemas/RateBucket'
        trailing_volume_30d:
          allOf:
            - $ref: '#/components/schemas/U64String'
          description: Trailing 30-day fill shares (SUM qty) for this user_id.
        write_floor:
          type: integer
        usd_per_extra_rps:
          type: integer
        batch_cap:
          type: integer
        response_budget_ms:
          type: integer
      required:
        - scopes
        - read
        - write
        - cancel
        - trailing_volume_30d
        - write_floor
        - usd_per_extra_rps
        - batch_cap
        - response_budget_ms
    RateBucket:
      type: object
      description: One token bucket.
      properties:
        sustained_rate_per_s:
          type: integer
        burst:
          type: integer
      required:
        - sustained_rate_per_s
        - burst
    U64String:
      type: string
      description: A u64-domain value rendered as a decimal string.
      pattern: ^[0-9]+$
      example: '182390'
    ErrorEnvelope:
      type: object
      description: The uniform error body.
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: lowercase snake_case reject/gateway code.
            num:
              type:
                - integer
                - 'null'
              description: >-
                The u16 reject code; non-null iff origin is `core` or `port`
                drawing from the shared registry (funding-port rejects carry a
                null num).
            origin:
              type: string
              enum:
                - core
                - port
                - gateway
            message:
              type: string
            details:
              type:
                - object
                - 'null'
          required:
            - code
            - num
            - origin
            - message
            - details
      required:
        - error
  responses:
    BadRequest:
      description: >
        Edge validation fault (origin gateway: `unknown_field`,
        `malformed_json`, `schema_violation`, `bad_client_withdrawal_id`,
        `bad_amount`, `bad_destination`) or a core/port validity reject
        (`bad_price_tick`, `bad_qty`, `invalid_decrease`,
        `client_order_id_required`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            error:
              code: unknown_field
              num: null
              origin: gateway
              message: unknown_field
              details: null
    Unauthorized:
      description: Missing or invalid signature (`unauthorized`, origin gateway).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            error:
              code: unauthorized
              num: null
              origin: gateway
              message: unauthorized
              details: null
    MissingScope:
      description: >-
        Key lacks the required scope (`missing_scope`), or a risk reject
        (`per_market_limit`, `user_suspended`, `reduce_only_violation`, …).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            error:
              code: missing_scope
              num: null
              origin: gateway
              message: missing_scope
              details: null
    RateLimited:
      description: |
        Token bucket empty (`rate_limited`). Retry after
        `error.details.retry_after_ms` milliseconds (decimal string). v1 does
        not emit a `Retry-After` HTTP header.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            error:
              code: rate_limited
              num: null
              origin: gateway
              message: rate limited
              details:
                retry_after_ms: '10'
  securitySchemes:
    DxAccessKey:
      type: apiKey
      in: header
      name: DX-ACCESS-KEY
      description: The public API key (alphanumeric access_key string).
    DxAccessTimestamp:
      type: apiKey
      in: header
      name: DX-ACCESS-TIMESTAMP
      description: Request timestamp, Unix milliseconds (decimal). ±5000 ms replay window.
    DxAccessSignature:
      type: apiKey
      in: header
      name: DX-ACCESS-SIGNATURE
      description: >
        base64(HMAC-SHA256(secret, "timestamp\nMETHOD\npath?query\nbody")). For
        the WS handshake the body is empty and the path is `/v1/ws`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.