> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qfex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Request a crypto withdrawal to a registered address

> Standard API keys require deposit_withdraw. Keys issued or replaced through POST /builder/web3/api-key also support crypto withdrawals to registered destinations when the user owns the selected account. This builder access is not selectable in Developer Settings. Every withdrawal, including all API keys and JWT sessions, must use a destination registered by the authenticated user on the requested network. Addresses are checked before debiting funds; Arbitrum matching is case-insensitive and TRON matching is exact. The user's primary account is debited. Requests are not idempotent; reconcile withdrawal history after a timeout before retrying.



## OpenAPI

````yaml /api-reference/openapi.yaml post /withdraw
openapi: 3.1.0
info:
  contact:
    email: support@qfex.com
    name: QFEX Support
  description: REST API for QFEX
  license:
    name: QFEX License
    url: https://qfex.com/license
  title: QFEX REST API
  version: 0.1.0
servers:
  - description: Production server
    url: https://api.qfex.com
security: []
paths:
  /withdraw:
    servers:
      - url: https://banker.qfex.com
        description: Production funding service
      - url: https://banker.qfex.io
        description: UAT funding service
    post:
      tags:
        - funding
      summary: Request a crypto withdrawal to a registered address
      description: >-
        Standard API keys require deposit_withdraw. Keys issued or replaced
        through POST /builder/web3/api-key also support crypto withdrawals to
        registered destinations when the user owns the selected account. This
        builder access is not selectable in Developer Settings. Every
        withdrawal, including all API keys and JWT sessions, must use a
        destination registered by the authenticated user on the requested
        network. Addresses are checked before debiting funds; Arbitrum matching
        is case-insensitive and TRON matching is exact. The user's primary
        account is debited. Requests are not idempotent; reconcile withdrawal
        history after a timeout before retrying.
      operationId: withdraw-crypto
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CryptoWithdrawalRequest'
      responses:
        '200':
          description: >-
            Withdrawal accepted and debited. The response body is empty;
            on-chain settlement may still be pending or require manual review.
        '400':
          description: >-
            Invalid address, network, amount, or insufficient withdrawable
            balance.
        '401':
          description: Missing or invalid authentication, or terms not accepted.
        '403':
          description: >-
            Required permission is missing, the account cannot use funding, or
            the destination is not registered for this user and network.
        default:
          description: >-
            Withdrawal request failed. If the result is uncertain, reconcile
            withdrawal history before retrying. Registered-address lookup errors
            reject the request before debiting funds.
      security:
        - HMACSignature: []
          Nonce: []
          PublicKey: []
          Timestamp: []
        - FundingSession: []
components:
  schemas:
    CryptoWithdrawalRequest:
      type: object
      properties:
        amount:
          type: number
          format: double
          minimum: 1
          description: Gross amount to debit; withdrawal fees are deducted before transfer.
        address:
          type: string
          description: >-
            Destination registered by the authenticated user on the requested
            network.
        network:
          type: string
          enum:
            - ARBITRUM_ONE
            - TRON
          default: ARBITRUM_ONE
      required:
        - amount
        - address
  securitySchemes:
    HMACSignature:
      description: HMAC-SHA256 signature (hex-encoded).
      in: header
      name: x-qfex-hmac-signature
      type: apiKey
      x-stoplight:
        hideExamples: true
    Nonce:
      description: Unique request nonce (hex encoded, max 100 characters).
      in: header
      name: x-qfex-nonce
      type: apiKey
      x-stoplight:
        hideExamples: true
    PublicKey:
      description: >-
        QFEX API Authentication requires these headers:


        - **x-qfex-public-key**: Your public API key

        - **x-qfex-hmac-signature**: HMAC signature of the request (hex encoded)

        - **x-qfex-nonce**: Unique nonce for the request (hex encoded, max 100
        characters)

        - **x-qfex-timestamp**: Unix timestamp of the request


        These four are required. Optionally send **x-qfex-requested-account-id**
        (UUID) to act as a subaccount; see Signature Generation below.


        **Signature Generation:**


        1. Generate a cryptographically secure random nonce (hex encoded, max
        100 characters) and capture the current Unix timestamp.

        2. Build the string `${nonce}:${unix_ts}` and compute an HMAC-SHA256
        using your secret key.

        3. Hex-encode the HMAC result to get the signature.

        4. Send the required auth headers below. The nonce must be unique within
        a 15 minute window.


        **Important:** The signature itself must be hex-encoded before being
        sent in the `x-qfex-hmac-signature` header.


        **Optional header:** `x-qfex-requested-account-id` (UUID) selects a
        subaccount; omit it to use the primary account.
      in: header
      name: x-qfex-public-key
      type: apiKey
      x-stoplight:
        hideExamples: true
    Timestamp:
      description: Unix timestamp (seconds since epoch).
      in: header
      name: x-qfex-timestamp
      type: apiKey
      x-stoplight:
        hideExamples: true
    FundingSession:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: QFEX user-session access token.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.