Base URL
Authentication
/api/v1 requires a JWT bearer token, except the
public dsl/validate, dsl/evaluate, and market-data endpoints noted in
their pages.
The token is the same JWT issued by your Kairos session — pass it as-is.
Krisis does not issue tokens itself; there is no login endpoint.
The token’s sub claim is the user UUID. Every request is scoped to that
user — you can only read and mutate your own strategies, funds, orders, and
positions.
Conventions
Gotcha: Polymarket needs two extra fields. Polymarket orders additionally requiretoken_idandoutcome. A Polymarket request without both is rejected400.
Gotcha:"kalshi_offchain"is a deprecated alias. It still comes back on strategies armed before the on-chain Kalshi removal, so your parser must tolerate it on reads. Send"kalshi"for anything new.
Error responses
Errors return a JSON body with a singleerror field:
Gotcha: not every rejection is an HTTP error.
POST /api/v1/dsl/validate answers a bad expression with 200 and
valid: false. A strategy that can’t fire for want of a fund or credentials
records a skip_reason on its execution rather than failing a request — see
Funds & Credentials.
A 200 and a healthy-looking strategy do not mean the engine is trading.Tier limits
Your account carries a Krisis tier that caps how much of the engine you can use. A create call that would exceed a cap fails400 — e.g.
{ "error": "Strategy limit reached for your tier" }. The tier carries:
Tiers are administered by Kairos; there is no public endpoint to read or
change your own.
Rate limiting
The API enforces a global request-rate limit. When exceeded, requests get429 with:
What’s in this chapter
Most integrations start with Conditional Orders — the
dedicated stop-loss, bracket, TWAP, and market-maker endpoints — and only drop
down to Strategies & DSL for custom conditions.

