Skip to main content

Trade over REST

CeFi direct REST covers the same trading actions as FIX, over HTTPS. It's reachable over the internet, so you don't need the private network connection that FIX uses.

Sign a request​

Sign every request with the API key and secret we issued to your firm. The signature is an HMAC-SHA256 of four strings joined with no separator: the timestamp, the HTTP method, the path without its query string, and the request body. An empty body adds nothing.

The timestamp is Unix seconds. We reject a request whose timestamp is more than 15 seconds old or more than 1 second in the future, so keep your clock in sync.

Send the result in four headers, plus the schema version:

HeaderValue
x-truex-auth-tokenyour API key
x-truex-auth-timestampthe timestamp you signed
x-truex-auth-signaturethe signature, base64
x-truex-auth-useridthe id of the client the request acts for
X-Truex-Versionv2026_01_23

The key identifies your firm, so you never send an organization id. The client id goes on every call except Get clients, so call that first to find yours. A principal account has one client, your firm.

X-Truex-Version picks the response format. Without it you get v2024_01_01, which stops being served on November 1, 2026, so send v2026_01_23 now. Its list responses come wrapped in data and pagination.

Send every request to https://api.truex.co.

sign.ts: sign one request with your secret
import { createHmac } from "node:crypto";

const [method, path, body = ""] = process.argv.slice(2);
const timestamp = String(Math.floor(Date.now() / 1000));
const payload =
timestamp + method + path.split("?")[0] + body;
const secret = process.env.CEFI_SECRET!;
const signature = createHmac("sha256", secret)
.update(payload)
.digest("base64");

console.log(`${timestamp} ${signature}`);
Read your balances
read TS SIG <<< \
"$(npx tsx sign.ts GET /v1/cefi/balances)"

curl -s "https://api.truex.co/v1/cefi/balances" \
-H "x-truex-auth-token: $CEFI_API_KEY" \
-H "x-truex-auth-timestamp: $TS" \
-H "x-truex-auth-signature: $SIG" \
-H "x-truex-auth-userid: $CEFI_CLIENT_ID" \
-H "X-Truex-Version: v2026_01_23"

Endpoints​

Orders

Balances and transfers

Next: CeFi direct REST reference