Authentication
How to authenticate, the environment prefixes, the base URL, and the rate limits.
Every endpoint except /health requires an API key, created in Settings (the Developer tab) once your account has beta access. The plaintext key is shown a single time at creation; store it then. You can hold up to 20 active keys, and revoking one does not replace it.
Get a key
Send the key on every request in the X-API-Key header:
curl https://api.perpsfund.com/v1/me \ -H "X-API-Key: pk_test_your_key_here"
An Authorization: Bearer <key> header is accepted as a fallback. A separate per-IP throttle rejects repeated failed-auth attempts before the key is even looked up, so a valid key keeps you clear of it.
Environments
Keys are scoped to an environment by their prefix. A key only authenticates against its own environment.
| Prefix | Environment | Can trade |
|---|---|---|
pk_test_ | Sandbox | The /sandbox/* routes: your simulated paper account |
pk_live_ | Live | Every account you can trade in the terminal (free trial, challenge, tournament, funded), on the live routes |
The environments never cross. A pk_live_ key on a /sandbox/* route, or a pk_test_ key on a live route, returns 403 wrong_environment.
A key is only as good as its owner's access: if your beta access is withdrawn, or your account is suspended, banned or deleted, every key you hold stops working on its next request with 403 api_access_denied. One key reaches every account you own, so this is all or nothing.
Base URL
All endpoints sit under the versioned /v1 prefix on the API subdomain:
https://api.perpsfund.com/v1Call /v1/* directly. The legacy /api/v1/* path still redirects here, but some HTTP clients drop the X-API-Key header when they follow a redirect, so always target the /v1 base.
Rate limits
Requests are capped at 600 per minute per key. Over the limit, the API returns 429 rate_limited with standard back-off headers:
| Header | Meaning |
|---|---|
Retry-After | Seconds to wait before retrying (currently the full window, 60). |
X-RateLimit-Limit | The ceiling (requests per window). |
X-RateLimit-Remaining | Remaining budget (0 on a 429). |
X-RateLimit-Reset | Unix seconds when the window resets. |
Live orders also pass through the terminal's own per-user limit, which your terminal and every key you hold share: 150 per minute for each of market orders, limit orders, closes, cancels and TP/SL changes, and 20 per minute for each Pro order type. It answers 429 rate_limited too, but carries only Retry-After, not the X-RateLimit-* headers.