NNOVAFLOW
Documentation
Open trading terminal
DEVELOPERS

API key

API keys provide authenticated programmatic access to NovaFlow perpetual trading. Create a key in Account & Funds → API, then use it to read positions, open market positions, and close positions.

AVAILABLE NOWPerpetual trading API

Each key is restricted to perpetual read and trade scopes. API keys cannot access deposits, withdrawals, or administration.

API KEY MANAGEMENT

Create and manage keys

Sign in to issue keys for your own NovaFlow account. A key can trade perpetual contracts but cannot withdraw funds.

Loading secure sign-in…
01

AUTHENTICATION

Authenticate a request

Send the API key in the HTTP Authorization header using the Bearer scheme. Never place a key in a URL, query string, client-side bundle, or public repository.

Request headers
Authorization: Bearer YOUR_API_KEY
Content-Type: application/json

Use a trusted environmentFor automated integrations, keep keys on infrastructure you control and never expose them in public browser pages or client-side bundles.

02

ENDPOINTS

Read, open, and close

All requests use the production trading endpoint below. Symbols currently supported by the terminal are also available through the API.

List account and perpetual positions
curl https://novaflow-trading.2026720.workers.dev/api/account/trades \
  -H "Authorization: Bearer YOUR_API_KEY"
Open an ETH long position
curl -X POST https://novaflow-trading.2026720.workers.dev/api/account/trades \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: order-20260911-001" \
  -d '{"product":"perp","symbol":"ETH","side":"Long","margin":10,"leverage":10}'
Close a perpetual position
curl -X PATCH https://novaflow-trading.2026720.workers.dev/api/account/trades \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"id":"TRADE_ID","action":"close"}'

Idempotency is required for openingUse a unique Idempotency-Key for every intended position. Retrying the same request with the same value returns the original trade instead of opening a duplicate.

03

KEY LIFECYCLE

Issue, store, and rotate

  1. Request the minimum required accessDefine the integration purpose and the exact permissions it needs.
  2. Copy and store the key securelySave it in a secrets manager or protected server environment variable.
  3. Verify the integrationStart with read-only access and confirm request logging and error handling.
  4. Rotate regularlyReplace keys periodically and immediately after any suspected exposure.
04

PERMISSIONS

Use the narrowest scope

Read access

Account, balance, market, order, and trade-history data allowed for the integration.

Trading access

Order placement or position management should be enabled only when explicitly required.

Withdrawal protection

Do not grant withdrawal capability to general trading or reporting integrations.

05

SECURITY

Protect your API key

  • Never share a key in chat, email, screenshots, tickets, or source code.
  • Restrict infrastructure and network access wherever supported.
  • Monitor request activity and investigate unfamiliar usage immediately.
  • Revoke and replace a key before changing the owner of an integration.
  • Use separate keys for separate services so one credential can be revoked without interrupting every system.
If a key may be exposedStop using it, revoke it immediately, issue a replacement, and review all activity associated with the old credential.
06

RESPONSES

Common authentication responses

401Missing, invalid, expired, or revoked API key.
403The key is valid but does not have permission for the requested action.
429The request rate is above the allowed limit. Retry with backoff.
ImportantAPI orders use the same real balance, market pricing, fees, rebates, account locks, and settlement rules as orders placed in the trading terminal.