> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qfex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a crypto deposit address

> API keys require view_balance. Returns the existing deposit address or provisions one on the first call without rotating an existing address. ARBITRUM_ONE deposits USDC; TRON deposits USDT. POST /address/rotate requires deposit_withdraw.



## OpenAPI

````yaml /api-reference/openapi.yaml get /address
openapi: 3.1.0
info:
  contact:
    email: support@qfex.com
    name: QFEX Support
  description: REST API for QFEX
  license:
    name: QFEX License
    url: https://qfex.com/license
  title: QFEX REST API
  version: 0.1.0
servers:
  - description: Production server
    url: https://api.qfex.com
security: []
paths:
  /address:
    servers:
      - url: https://banker.qfex.com
        description: Production funding service
      - url: https://banker.qfex.io
        description: UAT funding service
    get:
      tags:
        - funding
      summary: Get a crypto deposit address
      description: >-
        API keys require view_balance. Returns the existing deposit address or
        provisions one on the first call without rotating an existing address.
        ARBITRUM_ONE deposits USDC; TRON deposits USDT. POST /address/rotate
        requires deposit_withdraw.
      operationId: get-deposit-address
      parameters:
        - name: network
          in: query
          schema:
            type: string
            enum:
              - ARBITRUM_ONE
              - TRON
            default: ARBITRUM_ONE
      responses:
        '200':
          description: Deposit address for the requested network.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FundingAddress'
        '401':
          description: Missing or invalid authentication, or terms not accepted.
        '403':
          description: Required permission is missing or the account cannot use funding.
        default:
          description: Funding request failed.
      security:
        - HMACSignature: []
          Nonce: []
          PublicKey: []
          Timestamp: []
        - FundingSession: []
components:
  schemas:
    FundingAddress:
      type: object
      properties:
        address:
          type: string
          description: Deposit address for the returned network and asset.
        network:
          type: string
          enum:
            - ARBITRUM_ONE
            - TRON
        asset:
          type: string
          enum:
            - USDC
            - USDT
      required:
        - address
        - network
        - asset
  securitySchemes:
    HMACSignature:
      description: HMAC-SHA256 signature (hex-encoded).
      in: header
      name: x-qfex-hmac-signature
      type: apiKey
      x-stoplight:
        hideExamples: true
    Nonce:
      description: Unique request nonce (hex encoded, max 100 characters).
      in: header
      name: x-qfex-nonce
      type: apiKey
      x-stoplight:
        hideExamples: true
    PublicKey:
      description: >-
        QFEX API Authentication requires these headers:


        - **x-qfex-public-key**: Your public API key

        - **x-qfex-hmac-signature**: HMAC signature of the request (hex encoded)

        - **x-qfex-nonce**: Unique nonce for the request (hex encoded, max 100
        characters)

        - **x-qfex-timestamp**: Unix timestamp of the request


        These four are required. Optionally send **x-qfex-requested-account-id**
        (UUID) to act as a subaccount; see Signature Generation below.


        **Signature Generation:**


        1. Generate a cryptographically secure random nonce (hex encoded, max
        100 characters) and capture the current Unix timestamp.

        2. Build the string `${nonce}:${unix_ts}` and compute an HMAC-SHA256
        using your secret key.

        3. Hex-encode the HMAC result to get the signature.

        4. Send the required auth headers below. The nonce must be unique within
        a 15 minute window.


        **Important:** The signature itself must be hex-encoded before being
        sent in the `x-qfex-hmac-signature` header.


        **Optional header:** `x-qfex-requested-account-id` (UUID) selects a
        subaccount; omit it to use the primary account.
      in: header
      name: x-qfex-public-key
      type: apiKey
      x-stoplight:
        hideExamples: true
    Timestamp:
      description: Unix timestamp (seconds since epoch).
      in: header
      name: x-qfex-timestamp
      type: apiKey
      x-stoplight:
        hideExamples: true
    FundingSession:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: QFEX user-session access token.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.