> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kairos.trade/llms.txt
> Use this file to discover all available pages before exploring further.

# Fetch OHLCV candles for a single contract

> Returns OHLCV candle bars for one `(provider, contract_id, outcome)` series over `[start, end)`, bucketed at `timeframe_seconds`.

**Auth**: accepts an admin secret (`X-Admin-Secret`), an API key (`X-Client-Id` + `X-Api-Key` + `X-Api-Secret`), or a first-party JWT (`Authorization: Bearer` or `turnkey_session_jwt` cookie). No API-key scope is required for this endpoint — any valid credential can read candles.

**Cache / data source**: responses may be served from cache unless `rebuild=true`, which always bypasses the cache and reconstructs candles from the underlying trade/candle data, then repopulates the cache. `rebuild=true` is for callers that explicitly want fresh data regardless of what's cached.

**Validation** (all return 400): unknown `provider` (must exist in the live provider registry — currently includes `kalshi`, `polymarket`, `dome`, `opinion`); empty or >128-char `contract_id`; `timeframe_seconds` not one of the fixed allowed values; unparseable `start`/`end` (ISO 8601); or `end <= start`. An `outcome` index invalid for the given provider/contract (e.g. an out-of-range index on a binary market) also returns 400.




## OpenAPI

````yaml /openapi/data-api.yaml get /candles
openapi: 3.1.0
info:
  title: Kairos Data API
  version: 1.0.0
  summary: >-
    The full Kairos data plane — markets, candles, trades, search, discover,
    sports, trader analytics, and PnL.
  description: |
    The Kairos Data API at `data.kairos.trade` is the platform's primary data
    plane: market metadata and prices, OHLCV candles, live venue trade proxies,
    normalized trade history, full-text search, discovery feeds, the sports
    catalog, public trader analytics, and account PnL.

    ## Authentication

    Most endpoints accept a Kairos **API key** (`X-Client-Id` + `X-Api-Key` +
    `X-Api-Secret`, all three) or a first-party session JWT. Endpoints tagged
    `public` (trader analytics, provider configs, several sports feeds) need
    no credentials at all. Some endpoints additionally require an API-key
    **scope** (`trade:read`, `position:read`) — stated per operation.

    For high-volume market-data consumption (candles/trades/metadata at
    scale), prefer the dedicated **Market Data API** at `md.kairos.trade` —
    it has higher budgets, ETag caching, and a binary candle format.

    ## Rate limits

    Rate limits use a sliding window keyed on the authenticated user (JWT
    `sub`) or, for anonymous callers, the trusted client IP. Routes belong to
    a named **bucket** (`x-kairos-bucket`) whose per-minute budget is shared
    by every route in it; routes with no bucket run under the service default
    of 100/minute. `x-kairos-rate-limit` states the bucket's compile-time
    default — operators can raise or lower a bucket at runtime, so treat the
    documented number as the baseline, not a contract. 429 responses carry
    `Retry-After` and `X-RateLimit-*`.

    ## Conventions

    - Prices are on the **0–100 cents scale** unless a field says otherwise
      (trader-analytics position/trade prices use the 0–1 scale; each field's
      description states its scale).
    - Errors: `{"detail": "<message>"}` for handler errors; FastAPI's
      standard validation envelope for 422s. Errors surfaced from a venue
      adapter instead use `{"error", "provider", "operation", "message"}` —
      see `DataProviderError`. Unhandled failures always return the generic
      500 body; internal details are logged, never returned.
    - Every request body is capped at 8 MiB service-wide (413).
  contact:
    name: Kairos
    url: https://app.kairos.trade/docs/api-reference
  termsOfService: https://kairos.trade/terms
servers:
  - url: https://data.kairos.trade
    description: Production
  - url: https://staging-data.kairos.trade
    description: Staging
security:
  - apiKeyClientId: []
    apiKeyKey: []
    apiKeySecret: []
paths:
  /candles:
    get:
      tags:
        - Candles
      summary: Fetch OHLCV candles for a single contract
      description: >
        Returns OHLCV candle bars for one `(provider, contract_id, outcome)`
        series over `[start, end)`, bucketed at `timeframe_seconds`.


        **Auth**: accepts an admin secret (`X-Admin-Secret`), an API key
        (`X-Client-Id` + `X-Api-Key` + `X-Api-Secret`), or a first-party JWT
        (`Authorization: Bearer` or `turnkey_session_jwt` cookie). No API-key
        scope is required for this endpoint — any valid credential can read
        candles.


        **Cache / data source**: responses may be served from cache unless
        `rebuild=true`, which always bypasses the cache and reconstructs candles
        from the underlying trade/candle data, then repopulates the cache.
        `rebuild=true` is for callers that explicitly want fresh data regardless
        of what's cached.


        **Validation** (all return 400): unknown `provider` (must exist in the
        live provider registry — currently includes `kalshi`, `polymarket`,
        `dome`, `opinion`); empty or >128-char `contract_id`;
        `timeframe_seconds` not one of the fixed allowed values; unparseable
        `start`/`end` (ISO 8601); or `end <= start`. An `outcome` index invalid
        for the given provider/contract (e.g. an out-of-range index on a binary
        market) also returns 400.
      operationId: getCandles
      parameters:
        - name: provider
          in: query
          required: true
          schema:
            type: string
          description: >
            Venue identifier, matched case-insensitively against the live
            provider registry (e.g. `kalshi`, `polymarket`). Unknown providers
            return 400.
          example: kalshi
        - name: contract_id
          in: query
          required: true
          schema:
            type: string
            minLength: 1
            maxLength: 128
          description: >-
            Provider-specific contract/market/token identifier. Whitespace is
            trimmed; empty or >128 chars returns 400.
          example: KXPRESPOLAND-24-DT
        - name: timeframe_seconds
          in: query
          required: true
          schema:
            type: integer
            enum:
              - 1
              - 60
              - 300
              - 900
              - 3600
              - 14400
              - 86400
          description: >
            Candle bucket width in seconds. FastAPI first enforces `>= 1`; the
            handler then rejects any value not exactly one of `[1, 60, 300, 900,
            3600, 14400, 86400]` (1s, 1m, 5m, 15m, 1h, 4h, 1d) with 400.
          example: 60
        - name: start
          in: query
          required: true
          schema:
            type: string
            format: date-time
          description: >-
            Window start, ISO 8601 (any offset; normalized to UTC internally).
            Unparseable values return 400.
          example: '2026-07-21T00:00:00Z'
        - name: end
          in: query
          required: true
          schema:
            type: string
            format: date-time
          description: >-
            Window end, ISO 8601. Must be strictly after `start` (400
            otherwise).
          example: '2026-07-22T00:00:00Z'
        - name: outcome
          in: query
          required: false
          schema:
            type:
              - integer
              - 'null'
            minimum: 0
          description: >
            Zero-based outcome index for multi-outcome markets. Omitted/null is
            treated as `0` (the first/primary outcome). An index invalid for the
            contract's outcome count returns 400.
        - name: rebuild
          in: query
          required: false
          schema:
            type: boolean
            default: false
          description: When true, bypasses the cache and forces a fresh fetch/rebuild.
      responses:
        '200':
          description: OHLCV series for the requested window.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CandlesSeriesResponse'
        '400':
          description: >
            Invalid request — unknown provider, invalid/missing contract_id,
            disallowed timeframe_seconds, unparseable or out-of-order start/end,
            or an outcome index invalid for this contract.
          content:
            application/json:
              schema:
                type: object
                properties:
                  detail:
                    type: string
                    example: >-
                      Invalid timeframe. Must be one of: [1, 60, 300, 900, 3600,
                      14400, 86400]
        '401':
          $ref: '#/components/responses/DataUnauthorized'
        '403':
          $ref: '#/components/responses/DataForbidden'
        '422':
          $ref: '#/components/responses/DataValidationError'
        '429':
          $ref: '#/components/responses/DataRateLimited'
        '500':
          description: Candle fetch failed (cache or ClickHouse read error).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DataError'
components:
  schemas:
    CandlesSeriesResponse:
      type: object
      required:
        - candles
      properties:
        candles:
          type: array
          items:
            $ref: '#/components/schemas/CandlesCandle'
    DataError:
      type: object
      description: Handler error envelope (FastAPI HTTPException).
      required:
        - detail
      properties:
        detail:
          type: string
          description: Human-readable error message.
          example: Invalid provider
    CandlesCandle:
      type: object
      description: >-
        One OHLCV bar. `token_id` is only present (never emitted as null) when
        the underlying series is keyed by an outcome token rather than a plain
        contract id.
      required:
        - contract_id
        - timeframe_seconds
        - bucket_start
        - open
        - high
        - low
        - close
        - volume
      properties:
        contract_id:
          type: string
          description: Contract/market identifier this bar belongs to.
          example: KXPRESPOLAND-24-DT
        timeframe_seconds:
          type: integer
          description: Bucket width in seconds.
          example: 60
        bucket_start:
          type: string
          format: date-time
          description: Bucket start time, ISO 8601 UTC.
          example: '2026-07-21T14:32:00+00:00'
        open:
          type: number
          description: Opening price, 0-100 cents scale.
          example: 63.5
        high:
          type: number
          description: High price in the bucket, 0-100 cents scale.
          example: 64
        low:
          type: number
          description: Low price in the bucket, 0-100 cents scale.
          example: 63
        close:
          type: number
          description: Closing price, 0-100 cents scale.
          example: 63.8
        volume:
          type: integer
          description: Traded size (contracts/shares) within the bucket.
          example: 1250
        token_id:
          type: string
          description: >-
            Outcome token identifier, present only when this series is
            token-scoped (e.g. multi-outcome Polymarket markets).
          example: >-
            71321045679252212594626385532706912750332728571942532289631379312455583992563
  responses:
    DataUnauthorized:
      description: >
        No valid credential presented — missing/invalid API-key headers, or an
        invalid/expired session token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/DataError'
          example:
            detail: Not authenticated
    DataForbidden:
      description: >
        Authenticated but not permitted. Three distinct causes: the session user
        is not invited

        (`Invite required`), the API key lacks the operation's scope, or API-key
        access to the

        requested venue is switched off (`API access is disabled for
        <provider>`). Admin and API-key

        callers bypass the invite check; session and admin callers bypass scope
        and venue checks.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/DataError'
          example:
            detail: Invite required
    DataValidationError:
      description: Request failed FastAPI parameter validation.
      content:
        application/json:
          schema:
            type: object
            required:
              - detail
            properties:
              detail:
                type: array
                description: >-
                  One entry per failed field, with location, message, and error
                  type.
                items:
                  type: object
                  additionalProperties: true
    DataRateLimited:
      description: >
        Rate limit exceeded for this route's sliding window, keyed on the
        session `sub` when

        authenticated and on the trusted client IP otherwise. Honor
        `Retry-After`. A per-API-key

        data ceiling (set per credential) rejects with `{"detail": "API key data
        rate limit

        exceeded"}` instead of the `error` envelope below.
      headers:
        Retry-After:
          schema:
            type: integer
        X-RateLimit-Limit:
          schema:
            type: integer
        X-RateLimit-Remaining:
          schema:
            type: integer
        X-RateLimit-Reset:
          schema:
            type: integer
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                example: 'Rate limit exceeded: 100 per 1 minute'
  securitySchemes:
    apiKeyClientId:
      type: apiKey
      in: header
      name: X-Client-Id
      description: >-
        Credential client id (`kairos_ck_...`). Must be sent together with
        X-Api-Key and X-Api-Secret.
    apiKeyKey:
      type: apiKey
      in: header
      name: X-Api-Key
      description: 64-char hex API key.
    apiKeySecret:
      type: apiKey
      in: header
      name: X-Api-Secret
      description: 64-char hex API secret.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.