Backpack Withdrawal Delays API

Withdrawal delays.

Documentation

Specifications

Schemas & Data

Other Resources

OpenAPI Specification

backpack-withdrawal-delays-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  title: Backpack Exchange Account Withdrawal Delays API
  description: "\n# Introduction\n\nWelcome to the Backpack Exchange API. This API is for programmatic trade execution. All of the endpoints require requests to be signed with an ED25519 keypair for authentication.\n\nThe API is hosted at `https://api.backpack.exchange/` and the WS API is hosted at `wss://ws.backpack.exchange/`.\n\n# Authentication\n\n\n## Signing requests\n\nSigned requests are required for any API calls that mutate state. Additionally, some read only requests can be performed by signing or via session authentication.\n\nSigned requests require the following additional headers:\n\n- `X-Timestamp` - Unix time in milliseconds that the request was sent.\n- `X-Window` - Time window in milliseconds that the request is valid for, default is `5000` and maximum is `60000`.\n- `X-API-Key` - Base64 encoded verifying key of the ED25519 keypair.\n- `X-Signature` - Base64 encoded signature generated according to the instructions below.\n\n### Generate ED25519 Keys\n\nYou can generate a private/public ED25519 keypair using this Python one-liner:\n\n```python\npython3 -c \"from cryptography.hazmat.primitives.asymmetric import ed25519; import base64; key = ed25519.Ed25519PrivateKey.generate(); seed = key.private_bytes_raw(); pub = key.public_key().public_bytes_raw(); print(f'Seed: {base64.b64encode(seed).decode()}\\nPublic Key: {base64.b64encode(pub).decode()}')\"\n```\n\nThis will output your base64-encoded private key (seed) and public key that can be used for API authentication.\n\n### Signature Generation\n\nTo generate a signature perform the following:\n\n1) The key/values of the request body or query parameters should be ordered alphabetically and then turned into query string format.\n\n2) Append the header values for the timestamp and receive window to the above generated string in the format `&timestamp=<timestamp>&window=<window>`. If no `X-Window` header is passed the default value of `5000` still needs to be added to the signing string.\n\nEach request also has an instruction type, valid instructions are:\n\n```\naccountQuery\nbalanceQuery\nborrowLendExecute\nborrowHistoryQueryAll\ncollateralQuery\ndepositAddressQuery\ndepositQueryAll\nfillHistoryQueryAll\nfundingHistoryQueryAll\ninterestHistoryQueryAll\norderCancel\norderCancelAll\norderExecute\norderHistoryQueryAll\norderQuery\norderQueryAll\npnlHistoryQueryAll\npositionHistoryQueryAll\npositionQuery\nquoteSubmit\nstrategyCancel\nstrategyCancelAll\nstrategyCreate\nstrategyHistoryQueryAll\nstrategyQuery\nstrategyQueryAll\nwithdraw\nwithdrawalQueryAll\n```\n\nThe correct instruction type should be prefixed to the signing string. The instruction types for each request are documented alongside the request.\n\nFor example, an API request to cancel an order with the following body:\n\n```json\n{\n    \"orderId\": 28\n    \"symbol\": \"BTC_USDT\",\n}\n```\n\nWould require the following to be signed:\n\n```text\ninstruction=orderCancel&orderId=28&symbol=BTC_USDT&timestamp=1614550000000&window=5000\n```\n\nRegarding batch order execution (`POST /orders`), for each order in the batch, the order parameters should be ordered alphabetically and then turned into query string format. The orderExecute instruction should then be prefixed to that string.\nThe query strings for the orders should be concatenated with `&` and the timestamp and window appended at the end.\n\nFor example, an API request for an order execution batch with the following body:\n\n```json\n[\n    {\n        \"symbol\": \"SOL_USDC_PERP\",\n        \"side\": \"Bid\",\n        \"orderType\": \"Limit\",\n        \"price\": \"141\",\n        \"quantity\": \"12\"\n    },\n    {\n        \"symbol\": \"SOL_USDC_PERP\",\n        \"side\": \"Bid\",\n        \"orderType\": \"Limit\",\n        \"price\": \"140\",\n        \"quantity\": \"11\"\n    }\n]\n```\n\nWould require the following to be signed:\n\n```text\ninstruction=orderExecute&orderType=Limit&price=141&quantity=12&side=Bid&symbol=SOL_USDC_PERP&instruction=orderExecute&orderType=Limit&price=140&quantity=11&side=Bid&symbol=SOL_USDC_PERP&timestamp=1750793021519&window=5000\n```\n\nIf the API endpoint requires query parameters instead of a request body, the same procedure should be used on the query parameters. If the API endpoint does not have a request body or query parameters, only the timestamp and receive window need to be signed.\n\nThis message should be signed using the private key of the ED25519 keypair that corresponds to the public key in the `X-API-Key` header. The signature should then be base64 encoded and submitted in the `X-Signature` header.\n\n\n<br /><br />\n\n---\n\n\n# Infrastructure\n\nOrders are processed through a single linear command stream. All orders from all API instances feed into one stream, which is consumed by the matching engine sequentially.\n\n## Architecture\n\n```mermaid\nflowchart TB\n    subgraph Client[\"Client\"]\n        direction LR\n        REST[\"REST API Client\"]\n        WSC[\"WebSocket Client\"]\n    end\n\n    subgraph Edge[\"Edge\"]\n        direction LR\n        WAF[\"WAF\"]\n        CDN[\"CDN\"]\n    end\n\n    ALB[\"Load Balancer\"]\n    API[\"API<br/><i>N pods, Pre-validation</i>\"]\n    BUS[\"Message Bus\"]\n\n    subgraph Engine[\"Matching Engine\"]\n        direction LR\n        CLEARING[\"Clearing\"]\n        OB[\"Order Book\"]\n        SETTLE[\"Settlement\"]\n    end\n\n    WSLB[\"WebSocket LB\"]\n    APIWS[\"WebSocket API<br/><i>N pods</i>\"]\n\n    subgraph Persistence[\"Persistence\"]\n        direction LR\n        DB[\"Database\"]\n        SNAP[\"Snapshots\"]\n    end\n\n    REST <-->|\"Order / Execution Response\"| WAF\n    WAF <--> CDN\n    CDN <--> ALB\n    ALB <--> API\n    API <--> BUS\n    BUS <--> Engine\n\n    CLEARING --> OB\n    OB --> SETTLE\n\n    Engine --> WSLB\n    WSLB --> APIWS\n    APIWS -->|\"Order Updates / Depth / Trades\"| WSC\n\n    Engine -.-> Persistence\n\n    classDef hotpath fill:#ff6b6b,stroke:#c0392b,color:#fff\n    classDef bus fill:#f39c12,stroke:#e67e22,color:#fff\n    classDef client fill:#3498db,stroke:#2980b9,color:#fff\n    classDef persist fill:#95a5a6,stroke:#7f8c8d,color:#fff\n    classDef edge fill:#1abc9c,stroke:#16a085,color:#fff\n\n    class REST,WSC client\n    class WAF,CDN,ALB,WSLB edge\n    class API,APIWS,CLEARING,OB,SETTLE hotpath\n    class BUS bus\n    class DB,SNAP persist\n```\n\n## Order Lifecycle\n\n```mermaid\n%%{init: {'theme': 'neutral', 'themeVariables': {'fontSize': '12px'}}}%%\nsequenceDiagram\n    participant Client as Client\n    participant API as API\n    participant Engine as Matching Engine\n    participant WS as WebSocket API\n    Client->>+API: POST /api/v1/order (signed)\n    API->>+Engine: Order command\n    Note over Engine: Clear → Match → Settle\n    Engine-->>-API: Execution response\n    API->>-Client: HTTP 200 — Order result\n    Engine->>WS: Engine events\n    WS->>Client: Order updates / Depth / Trades\n```\n\n\n\n<br /><br />\n\n---\n\n# Changelog\n\n## 2025-11-12\n\n- Backstop liquidation fills now include a non-zero `tradeId` field on an on-going basis. Previously such fills had a\n  zero `tradeId`. This applies to the `/fills` endpoint as well as the trade stream.\n\n## 2025-11-10\n\n- Add a specific error message for withdrawal attempts to non-2FA exempt withdrawal addresses.\n- Set a default limit of `1000` levels each side of the book for `/depth` endpoint.\n\n## 2025-10-23\n\n- Add `j` and `k` fields to the order update stream (take profit limit price and stop loss limit price).\n\n## 2025-09-02\n\n- The `/depth` endpoint now returns a limit of 5,000 price levels on each side of the book.\n\n## 2025-09-01\n\n- The `cumulativeInterest` response field is being removed from the `/position`endpoint.\n- Estimated liquidation price or `l` is being removed from the position update stream. It will remain as a placeholder\n  and be set to 0. It will be removed in the future, so client's should not rely on its presence.\n- Liquidation price can be queried for a single position using the Positions API `/position` for example\n  `/position?symbol=BTC_USDC_PERP`.\n\n## 2025-08-07\n\n- `/history/pnl` has been removed.\n\n## 2025-06-08\n\n- The order id format is changing, it is no longer a byte shifted timestamp. It is no longer possible to derive the\n  order timestamp from the order id. This change will take place at Monday June 9th, 01:00 UTC.\n\n## 2025-04-22\n\n- The `/fills` endpoint now returns all fills for the account, including fills from system orders as well as client\n  orders. System orders include liquidations, ADLs and collateral conversions. Previously, by default, it only returned\n  fills from client orders. This behavior can be achieved by setting the `fillType` parameter to `User`.\n\n## 2025-04-08\n\n- Added funding rate lower and upper bounds to `/markets` and `/market` endpoints.\n\n## 2025-03-26\n\n- Add open interest stream `openInterest.<symbol>`.\n- Added the option to query `/history/borrowLend/positions` with a signed request using the instruction\n  `borrowPositionHistoryQueryAll`.\n\n## 2025-03-19\n\n- The leverage filter has been removed from `/markets` and `/market` endpoints.\n- Added `/openInterest` now takes `symbol` as an optional parameter. When not set, all markets are returned.\n- `/openInterests` has been deprecated.\n- Add stop loss and take profit fields to `/orders/execute`.\n- Add `I` field to the order update stream (related order id).\n- Add `a` and `b` fields to the order update stream (take profit trigger price and stop loss trigger price).\n\n## 2025-02-28\n\n- Added `clientId` to fill history.\n\n## 2025-02-11\n\n- An `O` field has been added to the order update stream. It denotes the origin of the update. The possible values are:\n    - `USER`: The origin of the update was due to order entry by the user.\n    - `LIQUIDATION_AUTOCLOSE`: The origin of the update was due to a liquidation by the liquidation engine.\n    - `ADL_AUTOCLOSE`: The origin of the update was due to an ADL (auto-deleveraging) event.\n    - `COLLATERAL_CONVERSION`: The origin of the update was due to a collateral conversion to settle debt on the\n      account.\n    - `SETTLEMENT_AUTOCLOSE`: The origin of the update was due to the settlement of a position on a dated market.\n    - `BACKSTOP_LIQUIDITY_PROVIDER`: The origin of the update was due to a backstop liquidity provider facilitating a\n      liquidation.\n\n## 2025-02-07\n\n- Added `r` to denote a reduce only order on the order updates stream.\n- Added `reduceOnly` to the get orders endpoint.\n\n## 2025-02-03\n\n- Added `openInterestLimit` to the markets endpoint. Applicable to futures markets only.\n- Added `orderModified` event to the order update stream. A resting reduce only order's quantity can be decreased in\n  order to prevent position side reversal.\n\n## 2025-01-09\n\n- Added `marketType` to the markets endpoint.\n- Added an optional `marketType` filter to the fills and the orders endpoints.\n\n## 2024-12-03\n\n- Add order expiry reason to order update stream.\n- Add `cumulativeInterest` to borrow lend position.\n\n## 2024-12-02\n\n- Add borrow lend history per position endpoint.\n\n## 2024-11-10\n\n- Add `timestamp` field denoting the system time in unix-epoch microseconds to the depth endpoint.\n\n## 2024-10-15\n\n- Convert all error responses to JSON and add a error code.\n\n## 2024-05-14\n\n- Add `executedQuantity` and `executedQuoteQuantity` to order history endpoint.\n\n## 2024-05-03\n\n- Add single market order update stream `account.orderUpdate.<symbol>`.\n\n## 2024-05-02\n\n- Add optional `from` and `to` timestamp to get withdrawals endpoint.\n\n## 2024-05-01\n\n- Add optional `from` and `to` timestamp to get deposits endpoint.\n\n## 2024-03-14\n\n- Add optional `orderId` filter to order history endpoint.\n- Add optional `from` and `to` timestamp to order fills endpoint.\n\n## 2024-02-28\n\n- Return the withdrawal in request withdrawal response.\n\n## 2024-02-24\n\n- An additional field `t` was added to the private order update stream. It is the `trade_id` of the fill that generated\n  the order update.\n- Added a maximum value for the `X-Window` header of `60000`.\n\n## 2024-01-16\n\n### Breaking\n\n- A new websocket API is available at `wss://ws.backpack.exchange`. Please see the documentation. The previous API\n  remains on the same endpoint and will be deprecated after a migration period. The new API changes the following:\n    - Subscription endpoint is now `wss://ws.backpack.exchange` instead of `wss://ws.backpack.exchange/stream`.\n    - Can subscribe and unsubscribe to/from multiple streams by passing more than one in the `params` field.\n    - Signature should now be sent in a separate `signature` field.\n    - Signature instruction changed from `accountQuery` to `subscribe`.\n    - Event and engine timestamps are now in `microseconds` instead of `milliseconds`.\n    - Add engine timestamp to `bookTicker`, `depth`, and `order` streams.\n    - Add quote asset volume to ticker stream.\n    - Add sequential trade id to trade stream.\n    - Rename the event type in the depth stream from `depthEvent` to `depth`.\n    - Change the format of streams from `<symbol>@<type>` to `<type>.<symbol>` or `kline.<interval>.<symbol>` for\n      K-lines.\n    - Flatten the K-Line in the K-line stream so its not nested.\n\n## 2024-01-11\n\n### Breaking\n\n- Replaced `identifier` field on deposits with `transaction_hash` and `provider_id`.\n  This aims to provide clearer representation of the field, particularly for fiat deposits.\n- Removed duplicate `pending` values from the `WithdrawalStatus` and `DepositStatus` spec enum.\n\n\n<br /><br />\n\n---\n    "
  version: '1.0'
  x-logo:
    url: https://cdn.prod.website-files.com/66830ad123bea7f626bcf58f/68eccb03852237fd98ffad9b_Backpack-Icon-Color.svg
    altText: Backpack Exchange
  contact:
    name: Backpack Exchange Support
    url: https://support.backpack.exchange/
  license:
    name: Proprietary
servers:
- url: https://api.backpack.exchange
tags:
- name: Withdrawal Delays
  description: Withdrawal delays.
paths:
  /wapi/v1/capital/withdrawals/delay:
    get:
      tags:
      - Withdrawal Delays
      summary: Get withdrawal delay.
      description: 'Retrieves the configured hourly delay for withdrawals to non-whitelisted

        addresses. This security feature adds a time delay before withdrawals are

        processed, allowing time to cancel unauthorized withdrawals.'
      responses:
        '200':
          description: Success.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/WithdrawalDelay'
        '204':
          description: No content.
        '401':
          description: Unauthorized.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      operationId: get_withdrawal_delay
    post:
      tags:
      - Withdrawal Delays
      summary: Create withdrawal delay.
      description: 'Enables a configurable hourly delay for withdrawals to non-whitelisted

        addresses. This security feature helps protect the account by adding a

        time buffer before withdrawals are processed. Requires 2FA verification.'
      requestBody:
        content:
          application/json; charset=utf-8:
            schema:
              $ref: '#/components/schemas/CreateWithdrawalDelayRequest'
        required: true
      responses:
        '200':
          description: Success.
        '400':
          description: Bad request.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '409':
          description: Withdrawal delay already exists.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      operationId: create_withdrawal_delay
    patch:
      tags:
      - Withdrawal Delays
      summary: Update withdrawal delay.
      description: 'Updates the hourly delay for withdrawals to non-whitelisted addresses.

        Changes will take effect after the current delay period ends. Requires

        2FA verification.'
      requestBody:
        content:
          application/json; charset=utf-8:
            schema:
              $ref: '#/components/schemas/UpdateWithdrawalDelayRequest'
        required: true
      responses:
        '200':
          description: Success.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/WithdrawalDelay'
        '400':
          description: Bad request.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '404':
          description: ''
        '500':
          description: Internal Server Error.
          content:
            application/json; charset=utf-8:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      operationId: update_withdrawal_delay
components:
  schemas:
    ApiErrorResponse:
      type: object
      title: ApiErrorResponse
      required:
      - code
      - message
      properties:
        code:
          $ref: '#/components/schemas/ApiErrorCode'
        message:
          type: string
    CreateWithdrawalDelayRequest:
      type: object
      title: CreateWithdrawalDelayRequest
      required:
      - withdrawalDelayHours
      - twoFactorToken
      properties:
        withdrawalDelayHours:
          type: integer
          format: uint32
          description: The delay applied to withdrawals being processed, in hours.
        twoFactorToken:
          type: string
          description: Issued two factor token.
    UpdateWithdrawalDelayRequest:
      type: object
      title: UpdateWithdrawalDelayRequest
      required:
      - withdrawalDelayHours
      - twoFactorToken
      properties:
        withdrawalDelayHours:
          type: integer
          format: uint32
          description: The delay applied to withdrawals being processed, in hours.
        twoFactorToken:
          type: string
          description: Issued two factor token.
    WithdrawalDelay:
      type: object
      title: WithdrawalDelay
      properties:
        currentWithdrawalDelayHours:
          type: integer
          format: int32
          description: The delay applied to withdrawals being processed.
        pendingWithdrawalDelayHours:
          type: integer
          format: int32
          description: 'The delay that will be applied to withdrawals once the update to the

            setting is enabled.'
        pendingWithdrawalDelayHoursEnabledAt:
          type: string
          format: naive-date-time
          description: 'The time when the update to the withdrawal delay setting will be

            applied.'
    ApiErrorCode:
      type: string
      enum:
      - ACCOUNT_DEACTIVATED
      - ACCOUNT_LIQUIDATING
      - BORROW_LIMIT
      - BORROW_REQUIRES_LEND_REDEEM
      - FORBIDDEN
      - INSUFFICIENT_FUNDS
      - INSUFFICIENT_MARGIN
      - INSUFFICIENT_SUPPLY
      - INVALID_ASSET
      - INVALID_CLIENT_REQUEST
      - INVALID_MARKET
      - INVALID_ORDER
      - INVALID_PRICE
      - INVALID_POSITION_ID
      - INVALID_QUANTITY
      - INVALID_RANGE
      - INVALID_SIGNATURE
      - INVALID_SOURCE
      - INVALID_SYMBOL
      - INVALID_TWO_FACTOR_CODE
      - LEND_LIMIT
      - LEND_REQUIRES_BORROW_REPAY
      - MAINTENANCE
      - MAX_LEVERAGE_REACHED
      - NOT_IMPLEMENTED
      - ORDER_LIMIT
      - POSITION_LIMIT
      - PRECONDITION_FAILED
      - RESOURCE_NOT_FOUND
      - SERVER_ERROR
      - TIMEOUT
      - TOO_EARLY
      - TOO_MANY_REQUESTS
      - TRADING_PAUSED
      - UNAUTHORIZED
x-tagGroups:
- name: Public Endpoints
  tags:
  - Assets
  - Borrow Lend Markets
  - Markets
  - System
  - Trades
- name: Authenticated Endpoints
  tags:
  - Account
  - Borrow Lend
  - Capital
  - Order
  - Position
  - RFQ
  - Strategy
- name: Websocket
  tags:
  - Streams