FAQ

Common questions from partners integrating PAX. If your question is not here, email Request access.

Access & onboarding

How do I get an API key?

For a sandbox key: hit POST /v1/sandbox-keys — anonymous self-serve, returns an sk_live_ bearer tagged tier=self_serve with $10 per-order + $100 daily caps. See the Sandbox page for the curl. For an org-tagged key with attribution wired in, submit an application via POST /v1/apply — 18 tracks (app / agent / data / distribution / market / liquidity / oracle / reviewer / operator / self_serve + 8× rfb-*) auto-provision a live sk_live_* in seconds. genesis (10× rate multiplier) and institutional (SLA) tracks route to human review for elevated capabilities. Higher tiers (trade_capped, trade_full) are reached via tier upgrade after integration.

How much does the API cost?

Read endpoints (/v1/markets, /v1/portfolio, market data) are free at every tier. CLOB writes use the PAX Adaptive Fee Curve (PAF): taker fee follows clamp(PAF_BASE × 4 × p × (1−p), PAF_FLOOR, PAF_CEILING). With defaults PAF_BASE_BPS = 20, PAF_FLOOR_BPS = 8, PAF_CEILING_BPS = 25, the effective per-fill range is 8–20 bps — peaking at 20 bps at 50/50 uncertainty (raw curve maxes at PAF_BASE because 4·p·(1−p) ≤ 1), flooring at 8 bps near 0¢/100¢. The 25 bps ceiling is a configurable safety cap that is dormant unless PAF_BASE is raised above 20. Maker rebate is quality-scaled 3-8 bps via the LQF score. Auto-tier 7-way split at PAF centre (each actor's absolute bps scales proportionally with the effective clamped fee): acquisition_builder 3 / execution_builder 3 / operator 2 / market_creator 3 / mm_stipend_pool 5 / lp 2 / platform_net 2. Progressive tier bumps builder share at trade_full (8 bps combined at centre, 40% of PAF_BASE) and genesis/partner (10 bps combined, 50%) — auto-graduated by 30d attributed volume for the first two tier steps. No monthly subscription. Attribution is written to financial_event on every fill (idempotent via unique key) — builders earn their share automatically on volume they route. The mm_stipend_pool bucket funds per-market daily payouts to MMs via the Liquidity Quality Framework (LQF) — a proximity² × balance × continuity score computed every 60 s. AMM fast-round markets carry a house edge + spread (~5% effective round-trip) as market-making risk buffer. See Fee Architecture for the full model.

When can I use sandbox?

Right now, no waiting. Sandbox is a per-key tier on the production API host. Mint a sandbox key at POST /v1/sandbox-keys — the response includes your key, tier caps, and expiry (30 days). Fills are simulated at mid-price so you never wait for order-book depth or oracle resolution. See Sandbox for the full flow.

Geographic restrictions?

PAX API is available worldwide except in jurisdictions where prediction markets are restricted by local law. Partners are responsible for validating their end-users' compliance with local rules.

Authentication

Which auth scheme should I use?

Why does my key start with pax_ instead of sk_live_?

pax_* is the original prefix (still valid — grandfathered forever). New keys use sk_live_*. Sandbox and production keys share the same prefix and host — capability is differentiated by the tier flag on the key (self_serve for sandbox with $10/$100 caps, read_live / trade_capped / trade_full / genesis / partner for production). This lets you promote a sandbox integration to production by upgrading the key's tier — no code changes, no host switch.

How do I rotate a leaked key?

Mint a new key, deploy it to your infra, then DELETE /api/v1/keys/{key_id} the old one. Revocation propagates cluster-wide within 5 seconds. See Auth guide → Revoking.

How much clock skew does HMAC tolerate?

±300 seconds (5 minutes) from server time, and the presented value is a UNIX seconds epoch — not milliseconds. Sync your machine's clock via NTP. Outside the window returns 401 TIMESTAMP_SKEW. Nonces are cached 600s to guard against replay (401 NONCE_REUSED). Reminder: HMAC verification is enterprise / ops-provisioned; standard integrations use Bearer.

Trading

AMM or CLOB — which engine runs my order?

You don't need to know — response's top-level fields are engine-agnostic. If you're curious, check meta.fill_venue in the order response: amm, clob, or hybrid. Design principle: never leak venue in top-level.

How do I safely retry a failed order?

Always send client_order_id (unique per intent, e.g., UUID). PAX guarantees idempotency for 24 hours — retrying with the same ID returns the original order rather than creating a duplicate.

Can I guess a market ID?

No. IDs are m_<sha256[0:16]> where the sha256 input includes a server-side pepper. Even knowing (template, params, creator) you cannot pre-compute the ID. Use GET /v1/markets to enumerate.

What's the min/max bet?

Per template. Fetch GET /v1/markets/templates and check each template's min_bet / max_bet fields. Typical: 1 USDT min, 10,000 USDT max.

Rate limits & support

I hit 429 — what do I do?

Respect the Retry-After response header (seconds until your quota resets). Standard exponential backoff otherwise. See Rate limits → Backoff code. If you need higher throughput, request a partner tier — see Rate limits → Upgrade.

Why 503 READ_ONLY_MODE?

Ops team has temporarily gated write endpoints for safety (e.g., during release / incident). Reads and WebSocket subscriptions remain available. If persistent (>30 minutes), email Request access.

Where do I check for incidents?

Public status dashboard live at status.predictasiax.com (uptime, 24h fills, active builders, latest Merkle audit anchor, DB + Redis health). Backed by GET /v1/status — machine-readable form (returns 24h fills, active builders, latest Merkle batch, DB/worker health). For historical outages, follow the Changelog, or email Request access with your request_id from meta.

Is there an SLA?

Best-effort during early access. Post-GA partners on a signed agreement get 99.9% monthly uptime SLA with credits. Not on GA yet — this doc will be updated when SLA terms are formalized.

Data & retention

How far back does trade / candle history go?

Trade tape: 30 days rolling. Candles (1m/5m/15m/30m/1h/4h/1d): 90 days rolling. Fast-round history: 30 days on-line + long-term cold storage on request. Older data via CSV export upon request.

Do you return my counterparty's email / wallet?

No. External-facing responses strip PII (email, phone, IP) by default. Self-view paths (/v1/account, /v1/account/*) return only YOUR PII. The X-PII-Redacted response header always tells you whether redaction was applied.

SDKs & languages

When are Python / TypeScript SDKs coming?

when v1.1 ships (coming). Meanwhile codegen from the OpenAPI spec — see Downloads. openapi-generator supports 50+ target languages with production-quality clients out of the box.

Can I reuse HMAC-based exchange API code?

Not directly on the live surface. Standard PAX integrations use Bearer sk_live_*, so any bot that speaks Authorization: Bearer ports over without rewriting a signer. Enterprise partners with dedicated ops provisioning can wire up the PAX-ADDRESS / PAX-TIMESTAMP / PAX-NONCE / PAX-SIGNATURE path — see Auth → HMAC for the exact signing string and headers.

Contact

Partners team: Request access · Twitter: the Changelog