POST /orders
Submit an order
Submit an order.
operationId: createOrder · CCXT method: createOrder · Rate-limit class: trading
Authentication: hmacAuth.
Request body
Required. OrderRequest — application/json.
Responses
200
Idempotent replay: this client_id was already accepted, and the body is the order that first request created. Nothing was placed by this request, so branch on the status rather than assuming 201. fills is empty here even if the original order has since traded; read its current state from GET /orders/{order_id}. Reachable only while the original order is still resting. The replay answers from the live book, so a fully-filled, cancelled or expired original, and any market/IOC/FOK order that never rested, is answered 409 instead. The duplicate is prevented either way; what differs is whether the original can be handed back inline.
400
— (no schema declared)
Validation error (insufficient margin, invalid tick size, etc.)
401
— (no schema declared)
—
403
— (no schema declared)
—
409
— (no schema declared)
This client_id is already claimed, and the order it created is not currently resting, so it cannot be returned inline (code: DuplicateClientId). This is the expected answer whenever the original is no longer on the book, not a rare edge: a filled, cancelled or expired order, and anything that never rested, all land here. The message names the order's id; find it in GET /orders/history, which retains terminal orders. Do not retry with the same key, since the outcome will not change, and do not re-submit under a new key without first establishing what the original order did. A 409 also covers the market-lifecycle admission gate, distinguished from the case above by code: MarketHalted when the market is halted, MarketReduceOnly when the market is in reduce-only and the order is neither reduce_only nor a liquidation, and MarketSuspended when the market is settling or delisted.
429
— (no schema declared)
—
Example
curl -X POST 'https://exchange.nexus.xyz/api/exchange/orders' \
-H 'X-API-Key: nx_7f3a1b...' \
-H 'X-Timestamp: 1776033911836' \
-H 'X-Signature: <hmac-sha256>' \
-H 'Content-Type: application/json'import requests
headers = {
"X-API-Key": "nx_7f3a1b...",
"X-Timestamp": "1776033911836",
"X-Signature": "<hmac-sha256>",
"Content-Type": "application/json"
}
response = requests.post("https://exchange.nexus.xyz/api/exchange/orders", headers=headers)
response.raise_for_status()
print(response.json())const response = await fetch("https://exchange.nexus.xyz/api/exchange/orders", {
method: "POST",
headers: {
"X-API-Key": "nx_7f3a1b...",
"X-Timestamp": "1776033911836",
"X-Signature": "<hmac-sha256>",
"Content-Type": "application/json"
},
});
if (!response.ok) throw new Error(`${response.status} ${await response.text()}`);
console.log(await response.json());X-Signature is a placeholder: it is derived from this specific request. See Authentication for the canonical string and the HMAC rule.
Generated from eng/apps/exchange/api/openapi.json (spec 0.9.36). Do not edit by hand — regenerate with python3 product/docs/tools/api-reference/generate.py. Hand-authored context lives in the Guides pages.
Last updated

