Production
Every REST endpoint lives under
/v1/. There is no anonymous access, even
market data requires a signed request.
Sandbox
Omnibook does not publish a separate sandbox environment. Integrate against production with small sizes, or run the local dev stack from the exchange repo if you need an isolated venue.Signing is host-independent
The HMAC canonical string coverstimestamp, METHOD, request-target, and
body, not the hostname. The same signing code works against any deployment
as long as you point BASE at the correct host. Query strings are part of the
request target: sign /v1/rounds?limit=5, not /v1/rounds. That includes the
multi-asset filters — sign /v1/oracle/price?feed=1 and
/v1/rounds?category=4, exactly as sent.
WebSocket handshake signing is fixed: