Which APIs require authentication?
In the API reference, endpoints marked free work without a key even when they belong to an otherwise-authenticated API. The entire Market Data API is free regardless of that label.
Get your API key
You need an account at app.kairos.trade to create an API key. The process takes under a minute.1
Create an account
Go to app.kairos.trade and sign up with your email address.
2
Open API Key settings
After logging in, click your avatar in the top-right corner and go to Settings → API Keys.
3
Create a new key
Click Create API Key, enter a descriptive name (e.g.
my-trading-bot), and choose the scopes your application needs. Then click Create.4
Copy your key
Your key is displayed once. Copy it and save it somewhere safe — a password manager, secrets manager, or environment variable. You cannot retrieve it again after closing the dialog.
Pass your key in every request
For programmatic access, send all three credential headers together on every authenticated request:401. Here is how that looks in practice:
- curl
- Python
- JavaScript
The session JWT (first-party apps only)
The web app authenticates with a short-lived session JWT instead of the triple:API key scopes
When you create a key, you assign it one or more scopes that control which operations it can perform. Granting only the scopes your application needs limits the blast radius if a key is ever leaked.Rate limits
All authenticated APIs enforce per-key rate limits. When you exceed the limit, the API returns429 Too Many Requests.
The response includes headers that tell you how to recover:
- Python
- JavaScript
The Market Data API also has rate limits, but they are more generous for unauthenticated use. Authenticated callers on all APIs get higher throughput allowances.
Common authentication errors
403 Forbidden — Insufficient scope
403 Forbidden — Insufficient scope
Cause: Your API key does not have the scope required by the endpoint you called. For example, calling Fix: Edit the key in Settings → API Keys to add the missing scope, or create a new key with the correct scopes for your use case.
POST /orders with a key that only has data:read.Response body:429 Too Many Requests — Rate limit exceeded
429 Too Many Requests — Rate limit exceeded
Cause: Your key has sent more requests than its rate-limit window allows.Response body:Fix: Read the
Retry-After header and wait at least that many seconds before retrying. Implement exponential backoff with jitter (see the code examples above) to avoid hammering the API in tight loops.403 Forbidden — IP not allowlisted
403 Forbidden — IP not allowlisted
Cause: Your account has IP allowlisting enabled and the request originated from an address not on the list.Response body:Fix: Add your current IP address to the allowlist under Settings → Security, or disable IP restrictions if you’re testing from a dynamic address.
Revoking a key
If you suspect a key has been compromised, revoke it immediately:- Go to Settings → API Keys in app.kairos.trade.
- Find the key in the list and click Revoke.
- Confirm revocation — this is immediate and cannot be undone.
- Generate a new key and update your application configuration.
401 Unauthorized on all future requests.
Next steps
Quickstart
Follow a step-by-step guide to your first authenticated API call.
Execution API
Submit orders and manage positions across all supported venues.

