Skip to main content
Most Kairos APIs require credentials, but you can start exploring immediately without them. The Market Data API is completely open — no account or key required. The Data API, Execution API, and Agora Auction API require either an API key triple (three headers) for programmatic access or a session JWT for first-party apps. This page covers both.

Which APIs require authentication?

In the API reference, endpoints marked free work without a key even when they belong to an otherwise-authenticated API. The entire Market Data API is free regardless of that label.

Get your API key

You need an account at app.kairos.trade to create an API key. The process takes under a minute.
1

Create an account

Go to app.kairos.trade and sign up with your email address.
2

Open API Key settings

After logging in, click your avatar in the top-right corner and go to Settings → API Keys.
3

Create a new key

Click Create API Key, enter a descriptive name (e.g. my-trading-bot), and choose the scopes your application needs. Then click Create.
4

Copy your key

Your key is displayed once. Copy it and save it somewhere safe — a password manager, secrets manager, or environment variable. You cannot retrieve it again after closing the dialog.
Never embed your API key in client-side code, commit it to a public repository, or share it in logs. If a key is compromised, revoke it immediately from the API Keys settings page and generate a new one.

Pass your key in every request

For programmatic access, send all three credential headers together on every authenticated request:
All three belong to the same key — a partial set fails with 401. Here is how that looks in practice:

The session JWT (first-party apps only)

The web app authenticates with a short-lived session JWT instead of the triple:
JWTs are minted by the Kairos login flow and are not issued to API consumers. Use the header triple for integrations; the JWT exists so the app can call the same APIs. For a full comparison, see API Key Auth.

API key scopes

When you create a key, you assign it one or more scopes that control which operations it can perform. Granting only the scopes your application needs limits the blast radius if a key is ever leaked.
For a read-only analytics integration, issue a key with trade:read and position:read. For a trading bot, add trade:execute. Reserve auction:* for institutional workflows.

Rate limits

All authenticated APIs enforce per-key rate limits. When you exceed the limit, the API returns 429 Too Many Requests. The response includes headers that tell you how to recover:
Apply exponential backoff with jitter when you receive a 429:
The Market Data API also has rate limits, but they are more generous for unauthenticated use. Authenticated callers on all APIs get higher throughput allowances.

Common authentication errors

Cause: The Authorization header is absent, empty, or not in Bearer <token> format.Response body:
Fix: Ensure every request to an authenticated endpoint includes:
Double-check there are no extra spaces, missing Bearer prefix, or accidental newlines in the header value.
Cause: The API key has been revoked, deleted, or has reached its expiry date.Response body:
Fix: Go to Settings → API Keys in app.kairos.trade, confirm the key is still active, and generate a new one if needed.
Cause: Your API key does not have the scope required by the endpoint you called. For example, calling POST /orders with a key that only has data:read.Response body:
Fix: Edit the key in Settings → API Keys to add the missing scope, or create a new key with the correct scopes for your use case.
Cause: Your key has sent more requests than its rate-limit window allows.Response body:
Fix: Read the Retry-After header and wait at least that many seconds before retrying. Implement exponential backoff with jitter (see the code examples above) to avoid hammering the API in tight loops.
Cause: Your account has IP allowlisting enabled and the request originated from an address not on the list.Response body:
Fix: Add your current IP address to the allowlist under Settings → Security, or disable IP restrictions if you’re testing from a dynamic address.

Revoking a key

If you suspect a key has been compromised, revoke it immediately:
  1. Go to Settings → API Keys in app.kairos.trade.
  2. Find the key in the list and click Revoke.
  3. Confirm revocation — this is immediate and cannot be undone.
  4. Generate a new key and update your application configuration.
Revoked keys return 401 Unauthorized on all future requests.

Next steps

Quickstart

Follow a step-by-step guide to your first authenticated API call.

Execution API

Submit orders and manage positions across all supported venues.