Skip to main content
Every production call carries a credential. Without one, trading endpoints answer 401 AUTH_REQUIRED and the streaming endpoint declines the handshake. Compliance-sensitive operations such as order submission may also require the X-TetraFi-Attestation header.

Getting a Key

Create a service account and issue a key from the dashboard (Workspace → Service Accounts → API Keys). Keys carry fine-grained scopes - quotes, orders, trades, settlements, treasury, compliance, and more - so a quoting integration holds only what it needs. tfk_test_ keys hit the sandbox, tfk_live_ production. Every request passes two gates: the key’s scope and the owner’s live workspace permission, re-derived each time. Demote the owner and the key narrows immediately. Minting keys is session-only: a credential cannot create a credential. Prove the loop on a tfk_test_ key before flipping to tfk_live_. No workspace yet? Reach the team.

Sending Credentials

Beyond the Key

None of this is wallet authority; signing from a wallet is a separate, owner-approved grant (Wallets & Signing).

Rate Limits and Key Safety

Throughput is metered per key and per workspace; ask for more headroom. A key belongs on your backend, never in client bundles, public repos, or a browser’s network tab. Leaked? Kill it in the dashboard and mint a fresh one.