> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qfex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate a wallet user's main-account trading key

> Requires the builder's existing API key with register_user and an active builder code owned by that key's user. Verifies the wallet signature and builder authorization issued within ten minutes, creates or resumes the wallet user, and issues a trading-only key for their main account. Replaces the previous key with the same builder-username label; withdrawals are disabled. Returns API keys, user_id, and account_id, without access or refresh tokens.



## OpenAPI

````yaml /api-reference/openapi.yaml post /builder/web3/api-key
openapi: 3.1.0
info:
  contact:
    email: support@qfex.com
    name: QFEX Support
  description: REST API for QFEX
  license:
    name: QFEX License
    url: https://qfex.com/license
  title: QFEX REST API
  version: 0.1.0
servers:
  - description: Production server
    url: https://api.qfex.com
security: []
paths:
  /builder/web3/api-key:
    servers:
      - url: https://api.qfex.io
        description: Pre-production
    post:
      tags:
        - builder
      summary: Generate a wallet user's main-account trading key
      description: >-
        Requires the builder's existing API key with register_user and an active
        builder code owned by that key's user. Verifies the wallet signature and
        builder authorization issued within ten minutes, creates or resumes the
        wallet user, and issues a trading-only key for their main account.
        Replaces the previous key with the same builder-username label;
        withdrawals are disabled. Returns API keys, user_id, and account_id,
        without access or refresh tokens.
      operationId: builder-web3-api-key
      parameters:
        - $ref: '#/components/parameters/x-qfex-public-key'
        - $ref: '#/components/parameters/x-qfex-hmac-signature'
        - $ref: '#/components/parameters/x-qfex-nonce'
        - $ref: '#/components/parameters/x-qfex-timestamp'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BuilderWalletBody'
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BuilderWalletKey'
          description: Created
          headers:
            Cache-Control:
              schema:
                type: string
                const: no-store
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorModel'
          description: Error
      security:
        - HMACSignature: []
          Nonce: []
          PublicKey: []
          Timestamp: []
components:
  parameters:
    x-qfex-public-key:
      description: >-
        The public key associated with your API credentials. Used to identify
        the requester.
      in: header
      name: x-qfex-public-key
      required: true
      schema:
        type: string
    x-qfex-hmac-signature:
      description: >-
        HMAC-SHA256 signature for request validation, hex-encoded. Generated by
        computing HMAC-SHA256 of the string `${nonce}:${unix_ts}` using your
        secret key, then hex-encoding the result.
      in: header
      name: x-qfex-hmac-signature
      required: true
      schema:
        type: string
    x-qfex-nonce:
      description: >-
        A cryptographically secure random nonce (hex encoded, max 100
        characters). Used to prevent replay attacks. Must be unique within a 15
        minute window.
      in: header
      name: x-qfex-nonce
      required: true
      schema:
        type: string
    x-qfex-timestamp:
      description: >-
        Unix timestamp (in seconds) of when the request was created. Used for
        request validation and replay attack prevention. The timestamp should be
        within an acceptable time window (typically ±5 minutes).
      explode: false
      in: header
      name: x-qfex-timestamp
      required: true
      schema:
        type: string
  schemas:
    BuilderWalletBody:
      additionalProperties: false
      properties:
        message:
          description: >-
            The exact SIWE message returned by GET /builder/web3/message,
            unchanged.
          maxLength: 20480
          minLength: 64
          type: string
        signature:
          description: >-
            Wallet personal_sign signature for the message, encoded as 65 bytes
            of hexadecimal with a 0x prefix.
          pattern: ^0x[0-9a-fA-F]{130}$
          type: string
      required:
        - message
        - signature
      type: object
    BuilderWalletKey:
      additionalProperties: false
      properties:
        account_id:
          description: The wallet user's main account ID, equal to user_id.
          format: uuid
          type: string
        public_key:
          description: The wallet user's new API public key.
          type: string
        secret_key:
          description: >-
            The wallet user's new API secret. Store securely; do not log or
            cache it.
          type: string
        user_id:
          description: QFEX user associated with the signing wallet.
          format: uuid
          type: string
      required:
        - user_id
        - account_id
        - public_key
        - secret_key
      type: object
    ErrorModel:
      additionalProperties: false
      properties:
        $schema:
          description: A URL to the JSON Schema for this object.
          examples:
            - https://api.qfex.com/schemas/ErrorModel.json
          format: uri
          readOnly: true
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
  securitySchemes:
    HMACSignature:
      description: HMAC-SHA256 signature (hex-encoded).
      in: header
      name: x-qfex-hmac-signature
      type: apiKey
      x-stoplight:
        hideExamples: true
    Nonce:
      description: Unique request nonce (hex encoded, max 100 characters).
      in: header
      name: x-qfex-nonce
      type: apiKey
      x-stoplight:
        hideExamples: true
    PublicKey:
      description: >-
        QFEX API Authentication requires these headers:


        - **x-qfex-public-key**: Your public API key

        - **x-qfex-hmac-signature**: HMAC signature of the request (hex encoded)

        - **x-qfex-nonce**: Unique nonce for the request (hex encoded, max 100
        characters)

        - **x-qfex-timestamp**: Unix timestamp of the request


        These four are required. Optionally send **x-qfex-requested-account-id**
        (UUID) to act as a subaccount; see Signature Generation below.


        **Signature Generation:**


        1. Generate a cryptographically secure random nonce (hex encoded, max
        100 characters) and capture the current Unix timestamp.

        2. Build the string `${nonce}:${unix_ts}` and compute an HMAC-SHA256
        using your secret key.

        3. Hex-encode the HMAC result to get the signature.

        4. Send the required auth headers below. The nonce must be unique within
        a 15 minute window.


        **Important:** The signature itself must be hex-encoded before being
        sent in the `x-qfex-hmac-signature` header.


        **Optional header:** `x-qfex-requested-account-id` (UUID) selects a
        subaccount; omit it to use the primary account.
      in: header
      name: x-qfex-public-key
      type: apiKey
      x-stoplight:
        hideExamples: true
    Timestamp:
      description: Unix timestamp (seconds since epoch).
      in: header
      name: x-qfex-timestamp
      type: apiKey
      x-stoplight:
        hideExamples: true

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.