> ## Documentation Index
> Fetch the complete documentation index at: https://docs.arena-predictions.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create API key

> Mint a key. The plaintext token is returned once, in this response, and never again. Not idempotent: every call mints a new key. At most 20 keys (created or rotated) per account in any 24 hours.



## OpenAPI

````yaml /openapi.json post /api_keys
openapi: 3.1.0
info:
  title: Arena API
  version: 1.7.0
  summary: >-
    Arena Predictions paper trading with an API key: read, and place paper
    orders with trade:write. Arena-owned data only.
  description: >-
    Arena Predictions (arena-predictions.com) is a sandbox for paper trading
    prediction markets at live prices. Every endpoint here serves Arena's
    sandbox, where every trade is a paper trade (mode "paper"); routing to live
    trading is coming. Keys are read-only and reach Arena-owned data only: the
    key's own identity and account, the leaderboards and published trader
    records with their resets and settled picks. Keys are managed with the
    signed-in browser session, never with a key. No exchange ticker, market
    title, entry price or venue price appears in any keyed response; the owner's
    own portfolio carries the owner's own paper numbers (a resting order's
    limitCents, a position's costDollars and contracts). Balances carry over:
    every account starts with 100,000 paper dollars, and a reset (at most one
    every 30 days, shown on a public profile) starts a new run. 1.2.0: seasons
    removed (no season field anywhere), leaderboard windows and kinds, trader
    resets, GET /account. 1.3.0: accounts are private by default. A private
    trader answers private: true with every P&L and rank null (resets and busts
    0) and an empty pick list; a public trader whose earlier trades are still
    hidden has numbersShown: false and no P&L or rank. The key owner reads their
    own picks (each with placedPrivate and shown) and their own eval rows (GET
    /me/eval) with portfolio:read. No key can make an account public. 1.4.0:
    keys are managed by a person's session, on the website or as a signed-in
    CLI's session token (arena keys), never by a key; keys rotate with a grace
    period; every keyed answer carries the plan and its counts (RateLimit-*,
    Arena-Quota-*, Arena-Plan) and GET /usage says where the account stands; a
    new scope, markets:read, reads instruments, games and quotes; GET /portfolio
    and /portfolio/trades read the owner's positions, orders and trades. Venue
    references and venue prices are served only while the venue-data switch is
    on (it ships off): until then the quotes routes answer 403 venue_data_off
    and nothing keyed names a ticker or a venue's price. 1.5.0: GET /eval, the
    public eval board (records:read), each row with 95% intervals clustered by
    game. 1.6.0: GET /traders/{traderId}/track-record, a trader's Ed25519-signed
    90-day record exactly as Arena signed it (records:read; it names Kalshi
    series inside its signed bytes, so it is served only while the venue-data
    switch is on), and tiedWithAbove on each eval row (null while this row's or
    the row above's interval is unknown). 1.7.0: a key created with trade:write
    (only when asked for by name: the Settings checkbox, arena keys create
    --trade, or scopes in the body) places paper orders with POST
    /portfolio/orders and cancels them with DELETE /portfolio/orders/{orderId},
    at Kalshi's paths. Market and limit orders, buys by instrument or ticker and
    sells of a whole position, each with an idempotencyKey: the same key again
    answers the stored order with replayed: true and places nothing. Hard trade
    limits are always enforced: per key 10 new orders a minute and 50 a day, and
    20 sells and cancels a minute; per account, across every key and connected
    app, 20 new orders a minute, 100 a day, and 40 sells and cancels a minute.
    The keyless website routes (/api/quotes/{instrumentId}, /api/quotes/batch,
    /api/gaps, /api/gaps/{instrumentId}) are described in their own document,
    /openapi-public.json.
  termsOfService: https://arena-predictions.com/terms
  contact:
    name: Arena
    email: support@zbgcllc.com
    url: https://arena-predictions.com/support
servers:
  - url: https://arena-predictions.com/api/v1
    description: >-
      The Arena API. Every account on it trades in the sandbox (paper trading);
      routing to live trading is coming.
security: []
tags:
  - name: Status
    description: Is the API up.
  - name: Identity
    description: Whose account a key acts for, and what it may do.
  - name: API keys
    description: >-
      Create, list, rotate and revoke keys, at the same path Kalshi uses. A
      person's session only (the website, or a signed-in CLI's session token): a
      key can never mint, rotate or revoke a key.
  - name: Records
    description: >-
      Arena's public records: the leaderboards, trader records with their
      resets, and settled picks. Scope records:read. Arena-owned data only: no
      exchange tickers, market titles, entry prices or live prices. Points equal
      paper dollars 1:1.
  - name: Portfolio
    description: >-
      The key owner's own paper account, positions, orders and trades. Scope
      portfolio:read. Arena-owned data only while the venue-data switch is off.
  - name: Markets
    description: >-
      Arena's instruments and games, and venue quotes. Scope markets:read. Venue
      references and prices only while the venue-data switch is on.
  - name: Trading
    description: >-
      Place and cancel paper orders for the key owner. Scope trade:write, which
      a key carries only when its creator asked for it. Paper only: nothing is
      sent to any venue.
  - name: Usage
    description: >-
      Where the key's account stands against its plan. Any valid key; never
      counted.
externalDocs:
  description: Arena API docs
  url: https://docs.arena-predictions.com
paths:
  /api_keys:
    post:
      tags:
        - API keys
      summary: Create API key
      description: >-
        Mint a key. The plaintext token is returned once, in this response, and
        never again. Not idempotent: every call mints a new key. At most 20 keys
        (created or rotated) per account in any 24 hours.
      operationId: createApiKey
      requestBody:
        required: false
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/KeyCreateRequest'
      responses:
        '201':
          description: Created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KeyCreateResponse'
        '400':
          description: >-
            invalid_request: a cookie-session request that is not same-origin
            (Sec-Fetch-Site must be same-origin, or Origin must equal this
            site), Content-Type is not application/json, the body is not an
            object, label is not a string, scopes is malformed or names an
            unknown scope, or expiresInDays is out of 1..365.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: >-
            unauthorized (not signed in) or session_required (an API key was
            presented).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            guest_account (anonymous session), or scope_not_available
            (trade:write requested while trading with keys is switched off).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: 'key_limit_reached: ten active keys already. Revoke one first.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: >-
            key_creation_limited: 20 keys made in the last 24 hours. Retry-After
            says when the oldest turns a day old.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          headers:
            Retry-After:
              $ref: '#/components/headers/Retry-After'
        '500':
          description: Could not create the key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - session: []
        - sessionBearer: []
components:
  schemas:
    KeyCreateRequest:
      type: object
      properties:
        label:
          type: string
          maxLength: 64
          description: Trimmed; an empty label becomes "Untitled key".
        scopes:
          type: array
          minItems: 1
          items:
            type: string
            enum:
              - records:read
              - portfolio:read
              - markets:read
              - trade:write
          description: >-
            Defaults to records:read, portfolio:read and markets:read.
            trade:write is never a default: name it to place and cancel paper
            orders. While trading with keys is switched off it is refused (403
            scope_not_available).
        expiresInDays:
          type: integer
          minimum: 1
          maximum: 365
          description: Omit for a key that never expires.
    KeyCreateResponse:
      type: object
      required:
        - key
        - token
        - warning
      properties:
        key:
          $ref: '#/components/schemas/KeyView'
        token:
          type: string
          description: The plaintext key. Shown once; only its hash is stored.
        warning:
          type: string
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              description: Stable machine token. Branch on this, never on message.
              enum:
                - invalid_request
                - unauthorized
                - invalid_token
                - insufficient_scope
                - guest_account
                - scope_not_available
                - key_limit_reached
                - key_not_found
                - trader_not_found
                - account_not_found
                - route_not_found
                - method_not_allowed
                - internal_error
                - session_required
                - key_creation_limited
                - rate_limited
                - quota_exceeded
                - venue_data_off
                - instrument_not_found
                - game_not_found
                - membership_required
                - trading_off
                - idempotency_key_reused
                - insufficient_balance
                - market_not_found
                - no_tradable_listing
                - market_not_open
                - market_resolved
                - no_liquidity
                - price_moved
                - trade_not_found
                - already_closed
                - order_not_found
            message:
              type: string
              description: Human sentence. May change.
            retryAfterSeconds:
              type: integer
              minimum: 1
              description: 'On every 429: the same number as the Retry-After header.'
    KeyView:
      type: object
      required:
        - id
        - label
        - tokenPrefix
        - scopes
        - status
        - createdAt
        - lastUsedAt
        - expiresAt
        - revokedAt
        - createdVia
        - rotatedFrom
        - rotatedAt
        - requestsThisMonth
      properties:
        id:
          type: string
          format: uuid
        label:
          type: string
          maxLength: 64
        tokenPrefix:
          type: string
          description: >-
            First 16 characters of the token, for matching a row to a key. Never
            the token.
        scopes:
          type: array
          items:
            type: string
            enum:
              - records:read
              - portfolio:read
              - markets:read
              - trade:write
        status:
          type: string
          enum:
            - active
            - rotating
            - revoked
            - expired
          description: >-
            rotating: replaced by a rotation and still inside its grace period
            (it works until expiresAt).
        createdAt:
          type: string
          format: date-time
        lastUsedAt:
          type:
            - string
            - 'null'
          format: date-time
          description: Updated at most once an hour.
        expiresAt:
          type:
            - string
            - 'null'
          format: date-time
        revokedAt:
          type:
            - string
            - 'null'
          format: date-time
        createdVia:
          type: string
          enum:
            - web
            - cli
          description: 'web: Settings. cli: arena keys.'
        rotatedFrom:
          type:
            - string
            - 'null'
          format: uuid
          description: The key this one replaced by rotation.
        rotatedAt:
          type:
            - string
            - 'null'
          format: date-time
          description: When this key was rotated.
        requestsThisMonth:
          type: integer
          minimum: 0
          description: Keyed requests counted against this key this month (UTC).
  headers:
    Retry-After:
      description: Seconds to wait before trying again.
      schema:
        type: integer
  securitySchemes:
    session:
      type: apiKey
      in: cookie
      name: sb-access-token
      description: >-
        The signed-in browser session (Google or Apple). Used only for key
        management, same-origin JSON requests only. An API key presented here is
        refused (401 session_required).
    sessionBearer:
      type: http
      scheme: bearer
      bearerFormat: Supabase access token (JWT) of a signed-in person
      description: >-
        A signed-in CLI's session token (arena login, then arena keys), checked
        with the auth server. Used only for key management; JSON bodies
        required. Never an arena_sk_ key (401 session_required), never a guest
        session (403 guest_account).

````