API key
API keys provide authenticated programmatic access to NovaFlow perpetual trading. Create a key in Account & Funds → API, then use it to read positions, open market positions, and close positions.
Each key is restricted to perpetual read and trade scopes. API keys cannot access deposits, withdrawals, or administration.
Create and manage keys
Sign in to issue keys for your own NovaFlow account. A key can trade perpetual contracts but cannot withdraw funds.
AUTHENTICATION
Authenticate a request
Send the API key in the HTTP Authorization header using the Bearer scheme. Never place a key in a URL, query string, client-side bundle, or public repository.
Authorization: Bearer YOUR_API_KEY
Content-Type: application/jsonUse a trusted environmentFor automated integrations, keep keys on infrastructure you control and never expose them in public browser pages or client-side bundles.
ENDPOINTS
Read, open, and close
All requests use the production trading endpoint below. Symbols currently supported by the terminal are also available through the API.
curl https://novaflow-trading.2026720.workers.dev/api/account/trades \
-H "Authorization: Bearer YOUR_API_KEY"curl -X POST https://novaflow-trading.2026720.workers.dev/api/account/trades \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: order-20260911-001" \
-d '{"product":"perp","symbol":"ETH","side":"Long","margin":10,"leverage":10}'curl -X PATCH https://novaflow-trading.2026720.workers.dev/api/account/trades \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"id":"TRADE_ID","action":"close"}'Idempotency is required for openingUse a unique Idempotency-Key for every intended position. Retrying the same request with the same value returns the original trade instead of opening a duplicate.
KEY LIFECYCLE
Issue, store, and rotate
- Request the minimum required accessDefine the integration purpose and the exact permissions it needs.
- Copy and store the key securelySave it in a secrets manager or protected server environment variable.
- Verify the integrationStart with read-only access and confirm request logging and error handling.
- Rotate regularlyReplace keys periodically and immediately after any suspected exposure.
PERMISSIONS
Use the narrowest scope
SECURITY
Protect your API key
- Never share a key in chat, email, screenshots, tickets, or source code.
- Restrict infrastructure and network access wherever supported.
- Monitor request activity and investigate unfamiliar usage immediately.
- Revoke and replace a key before changing the owner of an integration.
- Use separate keys for separate services so one credential can be revoked without interrupting every system.
RESPONSES