> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qfex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List registered crypto withdrawal addresses

> API keys require view_balance. Returns all crypto withdrawal addresses registered by the authenticated user across networks. The user is resolved from authentication; no user-ID query parameter is used. This endpoint does not register, change, or delete addresses.



## OpenAPI

````yaml /api-reference/openapi.yaml get /withdrawal-addresses
openapi: 3.1.0
info:
  contact:
    email: support@qfex.com
    name: QFEX Support
  description: REST API for QFEX
  license:
    name: QFEX License
    url: https://qfex.com/license
  title: QFEX REST API
  version: 0.1.0
servers:
  - description: Production server
    url: https://api.qfex.com
security: []
paths:
  /withdrawal-addresses:
    servers:
      - url: https://banker.qfex.com
        description: Production funding service
      - url: https://banker.qfex.io
        description: UAT funding service
    get:
      tags:
        - funding
      summary: List registered crypto withdrawal addresses
      description: >-
        API keys require view_balance. Returns all crypto withdrawal addresses
        registered by the authenticated user across networks. The user is
        resolved from authentication; no user-ID query parameter is used. This
        endpoint does not register, change, or delete addresses.
      operationId: list-withdrawal-addresses
      responses:
        '200':
          description: Registered addresses, or an empty addresses array.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RegisteredWithdrawalAddresses'
        '401':
          description: Missing or invalid authentication, or terms not accepted.
        '403':
          description: Required permission is missing or the account cannot use funding.
        default:
          description: Funding request failed.
      security:
        - HMACSignature: []
          Nonce: []
          PublicKey: []
          Timestamp: []
        - FundingSession: []
components:
  schemas:
    RegisteredWithdrawalAddresses:
      type: object
      properties:
        addresses:
          type: array
          description: >-
            All registered crypto withdrawal addresses for the authenticated
            user; empty if none exist.
          items:
            type: object
            properties:
              id:
                type: integer
                format: int64
              withdraw_address:
                type: string
              network:
                type: string
                enum:
                  - ARBITRUM_ONE
                  - TRON
              nickname:
                type:
                  - string
                  - 'null'
              created_at:
                type: string
                format: date-time
            required:
              - id
              - withdraw_address
              - network
              - nickname
              - created_at
      required:
        - addresses
  securitySchemes:
    HMACSignature:
      description: HMAC-SHA256 signature (hex-encoded).
      in: header
      name: x-qfex-hmac-signature
      type: apiKey
      x-stoplight:
        hideExamples: true
    Nonce:
      description: Unique request nonce (hex encoded, max 100 characters).
      in: header
      name: x-qfex-nonce
      type: apiKey
      x-stoplight:
        hideExamples: true
    PublicKey:
      description: >-
        QFEX API Authentication requires these headers:


        - **x-qfex-public-key**: Your public API key

        - **x-qfex-hmac-signature**: HMAC signature of the request (hex encoded)

        - **x-qfex-nonce**: Unique nonce for the request (hex encoded, max 100
        characters)

        - **x-qfex-timestamp**: Unix timestamp of the request


        These four are required. Optionally send **x-qfex-requested-account-id**
        (UUID) to act as a subaccount; see Signature Generation below.


        **Signature Generation:**


        1. Generate a cryptographically secure random nonce (hex encoded, max
        100 characters) and capture the current Unix timestamp.

        2. Build the string `${nonce}:${unix_ts}` and compute an HMAC-SHA256
        using your secret key.

        3. Hex-encode the HMAC result to get the signature.

        4. Send the required auth headers below. The nonce must be unique within
        a 15 minute window.


        **Important:** The signature itself must be hex-encoded before being
        sent in the `x-qfex-hmac-signature` header.


        **Optional header:** `x-qfex-requested-account-id` (UUID) selects a
        subaccount; omit it to use the primary account.
      in: header
      name: x-qfex-public-key
      type: apiKey
      x-stoplight:
        hideExamples: true
    Timestamp:
      description: Unix timestamp (seconds since epoch).
      in: header
      name: x-qfex-timestamp
      type: apiKey
      x-stoplight:
        hideExamples: true
    FundingSession:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: QFEX user-session access token.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.