- Keys are managed by a person’s session: the website, or a signed-in CLI’s session token (
arena keys). Never by a key. POST /api_keys/{id}/rotate: rotate with a grace period.- Every keyed response carries
RateLimit-*,Arena-Quota-*andArena-Plan. NewGET /usage. - New scope
markets:read:GET /instruments,/instruments/search,/instruments/{ref},/games,/games/{ref}, and the quotes routes. - New
GET /portfolioandGET /portfolio/tradesunderportfolio:read. - Venue references and prices are served only while the venue-data switch is on. It ships off: quotes routes answer
403 venue_data_off.
- Accounts are private by default. A private trader answers
private: truewith every numbernulland an empty pick list. - A public trader whose earlier trades are still hidden has
numbersShown: false. - The key owner reads their own picks (with
placedPrivateandshown) andGET /me/evalunderportfolio:read.
- Seasons removed: no
seasonfield anywhere. - Leaderboard
windowandkind, trader resets, andGET /account.