> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mob.exchange/llms.txt
> Use this file to discover all available pages before exploring further.

# Delta Neutral API

> Authenticate, make your first request, and manage paired positions across venues.

The MöB API lets you open, monitor, resize, and close paired positions through your wallet’s bound venue accounts. API keys are scoped to venues and a maximum USD size per leg. They cannot withdraw funds.

<Warning>
  Local and demo deployments can execute real trades. The checks below are read-only.
</Warning>

## Make your first request

<Steps>
  <Step title="Create a key">
    Open [API keys on app.mob.exchange](https://app.mob.exchange/?nav=api). Connect your wallet, bind at least two venues, and create a key that grants both. Choose a maximum USD size per leg and save the full secret when shown—it appears only once.
  </Step>

  <Step title="Set your environment">
    Use the production API URL with a key created on [app.mob.exchange](https://app.mob.exchange/?nav=api):

    ```bash Production API theme={null}
    export MOBIUS_API_BASE_URL="https://api.mob.exchange"
    ```

    For demo or local development, copy **Base URL** from that app’s Quick start and create a key in the same environment. Keys, venue bindings, and tasks are environment-specific.

    In Bash or Zsh, run this command and paste your key at the hidden prompt. The secret is not entered into shell history.

    ```bash API key theme={null}
    printf 'Paste API key (hidden): '
    read -rs MOBIUS_API_KEY; printf '\n'
    export MOBIUS_API_KEY
    : "${MOBIUS_API_KEY:?API key is required}"
    ```

    Run subsequent commands in this terminal. A running coding agent does not inherit a later export: restart it from this terminal if it needs access to the variable. Never paste the key into agent chat, source control, or logs.
  </Step>

  <Step title="Check the service">
    ```bash Request theme={null}
    curl -i "$MOBIUS_API_BASE_URL/health"
    ```

    ```http Expected response · 200 OK theme={null}
    HTTP/1.1 200 OK
    Content-Type: application/json

    {"ok": true}
    ```

    Health is public. It confirms service availability, not key validity or venue readiness.
  </Step>

  <Step title="Check your key">
    ```bash Request theme={null}
    curl -i "$MOBIUS_API_BASE_URL/v1/delta-neutral/tasks?limit=5" \
      -H "Authorization: Bearer $MOBIUS_API_KEY"
    ```

    ```http Expected response · 200 OK theme={null}
    HTTP/1.1 200 OK
    Content-Type: application/json

    {
      "tasks": [],
      "nextCursor": null
    }
    ```

    An empty list is valid. Existing tasks appear only when both venues are allowed by the key. A `401` means the key is missing, invalid, or revoked; check that it was created in this environment.
  </Step>
</Steps>

## Authentication

Every `/v1` request requires:

```http theme={null}
Authorization: Bearer mobius_<uuid>.<secret>
```

The UUID identifies the key; the secret authenticates it. Revocation takes effect immediately. `GET /health` and `GET /openapi.json` are public.

## Before placing a trade

* Use two different venues, both bound to the wallet and granted to the key.
* `sizeUsd` is **USD per leg**, at least \$10 and within the key’s limit and venue minimums.
* Configure leverage and margin mode on the venue accounts. The API does not set them.
* Persist an `Idempotency-Key` for each intended mutation before sending it. Reuse the same key and body for uncertain retries.

<Note>
  `202 Accepted` acknowledges a command, not a filled order. Poll the task to observe the worker’s result.
</Note>

<CardGroup cols={2}>
  <Card title="Create a task" icon="plus" href="/api-reference/create-task">Request fields, limits, and examples.</Card>
  <Card title="Monitor tasks" icon="list" href="/api-reference/list-tasks">Pagination and status filtering.</Card>
  <Card title="Venues and markets" icon="arrows-left-right" href="/api-reference/venues">Use the correct IDs for each leg.</Card>
  <Card title="Retries and errors" icon="rotate" href="/api-reference/errors">Idempotency, rate limits, and recovery.</Card>
</CardGroup>

## Use with a coding agent

Copy the **Coding agent** prompt from [Quick start](https://app.mob.exchange/?nav=api#api-quick-start). It includes your environment’s API URL and checks for a key before authenticated requests. For local development, run the agent on the same computer as the API.

The machine-readable contract is available from `GET /openapi.json` on your API deployment. Runnable Bun examples are in the [API demo directory](https://github.com/lu-bann/mobius/tree/codex/api-key-management/api-server/demo).
