A GraphQL API for the exchange: market data, account balances, orders, conversions, and withdrawals. It’s the same API the RandCrypto app itself trades on.
Two ways to authenticate
1. A user session token — obtained by logging in to the RandCrypto app. Required to create or manage API keys.
2. An API key — created with an explicit set of permissions, then exchanged for a short-lived session JWT via Authenticate with API Key. This is the credential an integration should hold day to day; it can do exactly what its permissions allow, nothing more.