Example of Interface
The interface below is the interface for obtaining server time. This interface
is used as an example to show the interface format, access link and parameter
description.
Check Server Time
GET https://openapi.oceanxz-au.com/sapi/v1/time
- 200: OK
- Responses
Document parameters specifications
The red * in the upper right corner of the input parameter name indicates
that the parameter must be inputted, otherwise it is not required.
The interface is case-sensitive to input parameter characters, which will be
clearly specified in the interface. If the currency pair name is in uppercase,
you need to enter BTCUSDT, but btcusdt is not allowed.
The input parameters in the document have clear type descriptions and need to
be entered according to the specified type. For example, the integer type can
only input numeric types. The input of 3 is correct, but the input of “3” is
not allowed.
Whether the interface requires signature verification?
Interface types are divided into: Public, Market, Trade, Account- The interfaces under the “Public” and “Market” categories can be accessed without API-Key or signature.
- “Trade” and “Account” security require API-Key and signature verification before access
- The signature content is related to the parameters. If the parameters are entered incorrectly, the parameter error or null value will be returned.
- For interfaces that require signature verification, X-CH-SIGN, X-CH-APIKEY, and X-CH-TS must be added to the header for signature verification. For signature rules and examples, please refer to : Signature (apiKey and secretKey in this document are virtual values. The real content needs to be obtained by the user in the API management of the front page)
Return code type
Please refer to the document: Return Code TypeAPI Basic Information
- baseurl
https://openapi.oceanxz-au.com - All endpoints return either a JSON object or array.
- Data is returned in Reverse order. newest first, oldest last.
- All time and timestamp related fields are in milliseconds.
HTTP Error Codes
- HTTP
4XXreturn codes are used for malformed requests; the issue is on the sender’s side. - HTTP
429return code is used when breaking a request rate limit. - HTTP
418return code is used when an IP has been auto-banned for continuing to send requests after receiving429codes. - HTTP
5XXreturn codes are used for internal errors - HTTP
504return code is used when the API successfully sent the message but not get a response within the timeout period. It is important to NOT treat this as a failure operation; the execution status is UNKNOWN and could have been a success. - All endpoints can possibly return an ERROR, the error payload is as follows:
General Information
- All requests are based on the Https protocol, and the
Content-Typein the request header information needs to be uniformly set to:'application/json' - For the interface of the
GETmethod, the parameters must be sent in thequery string - The interface of the
POSTmethod, the parameters must be sent in therequest body - Parameters may be sent in any order.
LIMITS
- There will be a limited frequency description below each interface.
- A 429 will be returned when either rate limit is violated.
- A 429 will be returned when either rate limit is violated.
Endpoint Security Type
- Each endpoint has a security type that determines the how you will interact with it.
- API-keys are passed into the Rest API via the
X-CH-APIKEYheader. - API-keys and secret-keys are case sensitive.
SIGNED (TRADE and USER_DATA) endpoint security
- When calling the
TRADEorUSER_DATAinterface, the signature parameter should be passed in theX-CH-SIGNfield in the HTTP header. - The signature uses the
HMAC SHA256algorithm. TheAPI-Secretcorresponding to the API-KEY is used as theHMAC SHA256key. - The request header of
X-CH-SIGNis based ontimestamp+method+requestPath+body string(+ means string connection) as the operation object - The value of
timestampis the same as theX-CH-TSrequest header,methodis the request method, and the letters are all uppercase:GET/POST requestPathis the request interface path For example:/sapi/v1/orderbodyis the string of the request body (post only)- The signature is not case sensitive.
Timing Security
- The signature interface needs to pass the timestamp in the
X-CH-TSfield in the HTTP header, and its value should be the unix timestamp of the request sending time e.g.1528394129373 - An additional parameter,
recvWindow, may be sent to specify the number of milliseconds aftertimestampthe request is valid for. IfrecvWindowis not sent, it defaults to 5000. - In addition, if the server calculates that the client’s timestamp is more than one second ‘in the future’ of the server’s time, it will also reject the request.
- The logic is as follows:
recvWindow, you can specify that the request must be processed within a certain number of milliseconds or be rejected by the server.
It recommended to use a small recvWindow of 5000 or less!
SIGNED Endpoint Examples for POST /sapi/v1/order
Here is a step-by-step example of how to send a vaild signed payload from the Linux command line usingecho, openssl, and curl.
Signature example
- body:
- HMAC SHA256 Signature:
- Curl command :

