Create an API key
- Sign in at omnibook.xyz.
- Go to Settings → API keys (
/settings#keys). - Click Create key, give it a name, and copy both values.
The three headers
The canonical string
The signature covers the timestamp, method, request target and body, joined by newlines, with a trailing newline after the target:GET /v1/portfolio/balance with no body:
- The request target includes the query string. Sign
/v1/rounds?limit=5, not/v1/rounds. - The body is the raw bytes you send, byte-for-byte. If you re-serialize your JSON between signing and sending, the signature breaks.
- The signature covers the body, so you cannot sign once and replay with different parameters.
Working examples
Clock skew
Your timestamp must be within ±5 seconds of the server’s clock. Outside that window the request is rejected as a replay, with the same401 as a bad
signature.
If you see intermittent 401s that go away on retry, check your clock before
you check your signing code.
Why a request failed
Every authentication failure returns the same response:- Did you hex-decode the secret?
- Does the signed target include the query string?
- Is the signed body byte-identical to what you sent?
- Is your clock within 5 seconds?
- Is the key still live? A revoked key cannot be restored.