Skip to main content
POST
Generate a wallet user's main-account trading key

Authorizations

x-qfex-hmac-signature
string
header
required

HMAC-SHA256 signature (hex-encoded).

x-qfex-nonce
string
header
required

Unique request nonce (hex encoded, max 100 characters).

x-qfex-public-key
string
header
required

QFEX API Authentication requires these headers:

  • x-qfex-public-key: Your public API key
  • x-qfex-hmac-signature: HMAC signature of the request (hex encoded)
  • x-qfex-nonce: Unique nonce for the request (hex encoded, max 100 characters)
  • x-qfex-timestamp: Unix timestamp of the request

These four are required. Optionally send x-qfex-requested-account-id (UUID) to act as a subaccount; see Signature Generation below.

Signature Generation:

  1. Generate a cryptographically secure random nonce (hex encoded, max 100 characters) and capture the current Unix timestamp.
  2. Build the string ${nonce}:${unix_ts} and compute an HMAC-SHA256 using your secret key.
  3. Hex-encode the HMAC result to get the signature.
  4. Send the required auth headers below. The nonce must be unique within a 15 minute window.

Important: The signature itself must be hex-encoded before being sent in the x-qfex-hmac-signature header.

Optional header: x-qfex-requested-account-id (UUID) selects a subaccount; omit it to use the primary account.

x-qfex-timestamp
string
header
required

Unix timestamp (seconds since epoch).

Headers

x-qfex-public-key
string
required

The public key associated with your API credentials. Used to identify the requester.

x-qfex-hmac-signature
string
required

HMAC-SHA256 signature for request validation, hex-encoded. Generated by computing HMAC-SHA256 of the string ${nonce}:${unix_ts} using your secret key, then hex-encoding the result.

x-qfex-nonce
string
required

A cryptographically secure random nonce (hex encoded, max 100 characters). Used to prevent replay attacks. Must be unique within a 15 minute window.

x-qfex-timestamp
string
required

Unix timestamp (in seconds) of when the request was created. Used for request validation and replay attack prevention. The timestamp should be within an acceptable time window (typically ±5 minutes).

Body

application/json
message
string
required

The exact SIWE message returned by GET /builder/web3/message, unchanged.

Required string length: 64 - 20480
signature
string
required

Wallet personal_sign signature for the message, encoded as 65 bytes of hexadecimal with a 0x prefix.

Pattern: ^0x[0-9a-fA-F]{130}$

Response

Created

account_id
string<uuid>
required

The wallet user's main account ID, equal to user_id.

public_key
string
required

The wallet user's new API public key.

secret_key
string
required

The wallet user's new API secret. Store securely; do not log or cache it.

user_id
string<uuid>
required

QFEX user associated with the signing wallet.