For the complete documentation index, see llms.txt. This page is also available as Markdown.

POST /ws/token

Mint a WebSocket token

Mint a WebSocket token.

operationId: createWsToken

Not reachable through CCXT. WebSocket transport and token minting. Covered by the CCXT Pro channel map, not by a REST unified method.

Authentication: hmacAuth.

Returns a short-lived (60s), single-use token bound to the authenticated account. Pass it as ?token=TOKEN when upgrading to GET /ws. Supports HMAC keys, registered agent keys, and session tokens (Bearer). The token encodes the account identity so per-account channels (orders, fills, positions, balances, liquidations) are automatically scoped to the connected wallet.

Responses

Status
Body
Meaning

200

(no schema declared)

Token minted

401

(no schema declared)

Authentication required

Example

curl -X POST 'https://exchange.nexus.xyz/api/exchange/ws/token' \
  -H 'X-API-Key: nx_7f3a1b...' \
  -H 'X-Timestamp: 1776033911836' \
  -H 'X-Signature: <hmac-sha256>'
import requests

headers = {
    "X-API-Key": "nx_7f3a1b...",
    "X-Timestamp": "1776033911836",
    "X-Signature": "<hmac-sha256>"
}

response = requests.post("https://exchange.nexus.xyz/api/exchange/ws/token", headers=headers)
response.raise_for_status()
print(response.json())
const response = await fetch("https://exchange.nexus.xyz/api/exchange/ws/token", {
  method: "POST",
  headers: {
    "X-API-Key": "nx_7f3a1b...",
    "X-Timestamp": "1776033911836",
    "X-Signature": "<hmac-sha256>"
  },
});
if (!response.ok) throw new Error(`${response.status} ${await response.text()}`);
console.log(await response.json());

X-Signature is a placeholder: it is derived from this specific request. See Authentication for the canonical string and the HMAC rule.


Generated from eng/apps/exchange/api/openapi.json (spec 0.9.36). Do not edit by hand — regenerate with python3 product/docs/tools/api-reference/generate.py. Hand-authored context lives in the Guides pages.

Last updated