Agent API keys
Agent keys let a bot, a script or an AI agent use your Chartist account without your password or any private key. Each key does only what you scope it to, and you can revoke it in one click.
- Agent API keysLiveScoped read or trade keys for bots and AI agents, with an optional hourly cap and webhooks.
- API platform, SDK and MCP serverPlannedEverything in Chartist over an API, with an OpenAPI spec, a TypeScript SDK and agent tools.
Creating a key
- Signed in, open Wallets → Agent keys. Keys can only be created there, by you.
- Pick a scope. Read covers market data and your wallets and positions. Trade adds buying, selling, orders and moving funds between your own wallets, with the same checks as the terminal.
- Set an hourly SOL cap. It is optional, but you should set one.
- The key is shown once. Chartist stores only a hash of it.
What a key can never do
- Export a private key.
- Withdraw to an address outside your account.
- Create, import or delete wallets.
Those actions need you, signed in, and the key is refused at each of them.
A trade key can still spend your SOL
A trade key cannot take funds out of your account, but it can buy and sell with them. Without an hourly cap, a leaked trade key could spend a wallet’s SOL buying whatever coin its holder picks. Set a cap, use read-only keys wherever you can, and revoke a key the moment you think it has leaked.
Using a key
- Send it as
Authorization: Bearer chartist_sk_…. - Amounts are whole lamports (or token base units) as decimal strings, never floating-point numbers.
- The machine-readable contract (every endpoint, scope and error) is at
https://chartist.cc/api/agent/manifest.
Webhooks
Attach an HTTPS endpoint to a key to be told about its fills and stopped campaigns. Each delivery carries a timestamp and an HMAC-SHA256 signature in the chartist-signature header; check both before you trust it.