POST /keys
Create an API key
Create an API key.
operationId: createApiKey
Not reachable through CCXT. Session/credential lifecycle. CCXT takes credentials as constructor config; it never mints them.
Authentication: bearerAuth.
Create a new HMAC API key for the authenticated wallet. Returns the secret once — it is never stored or shown again. Requires a session token (Bearer) from POST /auth/login.
The host you call this on decides which network the key is valid on. There is no network parameter in the request and none in the response: the key belongs to the network of the instance that mints it, and any other host refuses it with an opaque 401 that is indistinguishable from an unknown key. Call this on the host you intend to trade against — api.testnet.nexus.xyz for play funds, api.nexus.xyz for real funds — and mint a separate key per network rather than reusing one. See “API keys are bound to one network” in the API description.
Responses
200
— (no schema declared)
Key created
401
— (no schema declared)
Valid session token required for this host. A session token minted by another network's POST /auth/login is refused here like any invalid token.
Example
curl -X POST 'https://exchange.nexus.xyz/api/exchange/keys' \
-H 'Authorization: Bearer <token>'import requests
headers = {
"Authorization": "Bearer <token>"
}
response = requests.post("https://exchange.nexus.xyz/api/exchange/keys", headers=headers)
response.raise_for_status()
print(response.json())const response = await fetch("https://exchange.nexus.xyz/api/exchange/keys", {
method: "POST",
headers: {
"Authorization": "Bearer <token>"
},
});
if (!response.ok) throw new Error(`${response.status} ${await response.text()}`);
console.log(await response.json());Generated from eng/apps/exchange/api/openapi.json (spec 0.9.36). Do not edit by hand — regenerate with python3 product/docs/tools/api-reference/generate.py. Hand-authored context lives in the Guides pages.
Last updated

