Skip to main content
Customer methods are commands in one signed protocol, not independent REST JSON routes. Use PrivateClient.request or subscribe after verified connection. The SDK handles canonical binary encoding, Ed25519 signing, encryption and typed replies. POST carriers use application/octet-stream; private account IDs, commands and signatures never belong in URLs/headers. Authorization/Cookie and compressed private ingress are refused. Browser access uses one exact configured origin and no cookies. HTTPS/WSS is required outside loopback tests. There is no bearer-token login, plain JSON exchange, automatic native signature forwarding or trusted server-side decrypting proxy. No public base URL is supplied. See availability. Eight original commands plus versioned read reach the same authorization, reservations and journal. HTTP and WebSocket are transport choices, not different financial engines. WebSocket adds private replacement-page updates, not public chart/orderbook data.