Skip to main content
POST
/
user
/
transfer
Transfer Balance
curl --request POST \
  --url https://api.qfex.com/user/transfer \
  --header 'Content-Type: application/json' \
  --header 'x-qfex-hmac-signature: <api-key>' \
  --header 'x-qfex-nonce: <api-key>' \
  --header 'x-qfex-public-key: <api-key>' \
  --header 'x-qfex-timestamp: <api-key>' \
  --data '{
  "amount": 123
}'
import requests

url = "https://api.qfex.com/user/transfer"

payload = { "amount": 123 }
headers = {
"x-qfex-hmac-signature": "<api-key>",
"x-qfex-nonce": "<api-key>",
"x-qfex-public-key": "<api-key>",
"x-qfex-timestamp": "<api-key>",
"Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.text)
const options = {
method: 'POST',
headers: {
'x-qfex-hmac-signature': '<api-key>',
'x-qfex-nonce': '<api-key>',
'x-qfex-public-key': '<api-key>',
'x-qfex-timestamp': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({amount: 123})
};

fetch('https://api.qfex.com/user/transfer', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));
<?php

$curl = curl_init();

curl_setopt_array($curl, [
CURLOPT_URL => "https://api.qfex.com/user/transfer",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'amount' => 123
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-qfex-hmac-signature: <api-key>",
"x-qfex-nonce: <api-key>",
"x-qfex-public-key: <api-key>",
"x-qfex-timestamp: <api-key>"
],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}
package main

import (
"fmt"
"strings"
"net/http"
"io"
)

func main() {

url := "https://api.qfex.com/user/transfer"

payload := strings.NewReader("{\n \"amount\": 123\n}")

req, _ := http.NewRequest("POST", url, payload)

req.Header.Add("x-qfex-hmac-signature", "<api-key>")
req.Header.Add("x-qfex-nonce", "<api-key>")
req.Header.Add("x-qfex-public-key", "<api-key>")
req.Header.Add("x-qfex-timestamp", "<api-key>")
req.Header.Add("Content-Type", "application/json")

res, _ := http.DefaultClient.Do(req)

defer res.Body.Close()
body, _ := io.ReadAll(res.Body)

fmt.Println(string(body))

}
HttpResponse<String> response = Unirest.post("https://api.qfex.com/user/transfer")
.header("x-qfex-hmac-signature", "<api-key>")
.header("x-qfex-nonce", "<api-key>")
.header("x-qfex-public-key", "<api-key>")
.header("x-qfex-timestamp", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"amount\": 123\n}")
.asString();
require 'uri'
require 'net/http'

url = URI("https://api.qfex.com/user/transfer")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["x-qfex-hmac-signature"] = '<api-key>'
request["x-qfex-nonce"] = '<api-key>'
request["x-qfex-public-key"] = '<api-key>'
request["x-qfex-timestamp"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"amount\": 123\n}"

response = http.request(request)
puts response.read_body
{
  "$schema": "<string>",
  "detail": "<string>",
  "errors": [
    {
      "location": "<string>",
      "message": "<string>",
      "value": "<unknown>"
    }
  ],
  "instance": "<string>",
  "status": 123,
  "title": "<string>",
  "type": "about:blank"
}

Authorizations

x-qfex-hmac-signature
string
header
required

HMAC-SHA256 signature (hex-encoded).

x-qfex-nonce
string
header
required

Unique request nonce (hex encoded, max 100 characters).

x-qfex-public-key
string
header
required

QFEX API Authentication requires these headers:

  • x-qfex-public-key: Your public API key
  • x-qfex-hmac-signature: HMAC signature of the request (hex encoded)
  • x-qfex-nonce: Unique nonce for the request (hex encoded, max 100 characters)
  • x-qfex-timestamp: Unix timestamp of the request

These four are required. Optionally send x-qfex-requested-account-id (UUID) to act as a subaccount; see Signature Generation below.

Signature Generation:

  1. Generate a cryptographically secure random nonce (hex encoded, max 100 characters) and capture the current Unix timestamp.
  2. Build the string ${nonce}:${unix_ts} and compute an HMAC-SHA256 using your secret key.
  3. Hex-encode the HMAC result to get the signature.
  4. Send the required auth headers below. The nonce must be unique within a 15 minute window.

Important: The signature itself must be hex-encoded before being sent in the x-qfex-hmac-signature header.

Optional header: x-qfex-requested-account-id (UUID) selects a subaccount; omit it to use the primary account.

x-qfex-timestamp
string
header
required

Unix timestamp (seconds since epoch).

Query Parameters

src_account_id
string
required
dst_account_id
string
required

Body

application/json
amount
number<double>
required

Response

No Content