Menu
Authentication
Public price and volume endpoints need no credentials. Other endpoints list the authentication methods they accept.
API keys
Use an API key to access your own account. Send the complete key in
x-bb-api-key. Keys can have trading and bitcoin withdrawal permissions and IP
restrictions.
Order creation, cancellation, and bitcoin withdrawals require a nonce and signature in addition to the API key. See API keys and signing.
OAuth
Use OAuth for supported third-party access. The endpoint lists the scopes that
its access token needs. Send the token as
Authorization: Bearer <access token>.
OAuth is available only on the operations that list it. An API-key permission is not an OAuth scope. See the OAuth guide.
Selecting an authentication method
Where an endpoint accepts alternatives, use one complete method. Do not combine bearer-token and API-key headers. Switching the method in the reference changes the corresponding request example.