OpenAPI Specification
openapi: 3.0.3
info:
title: SynFutures RWA Trading Cash Portfolio API
version: v1
description: RESTful API for SynFutures tokenized stock (Real-World Asset) trading. Covers market data, portfolio, order placement (calldata build + One Click delegated send), cash and stock deposits/withdrawals, and One Click (1CT) delegation management. All /api/v1 endpoints require HMAC-SHA256 request authentication with an IP-whitelisted partner API key.
contact:
name: SynFutures
url: https://docs.synfutures.com/rwa-trading-apis/readme
x-logo:
url: https://www.synfutures.com/assets/trade_every_asset.png
servers:
- url: https://base-api.synfutures.com/rwa/trading
description: RWA Trading API (base path /api/v1)
security:
- ApiKeyAuth: []
ApiTimestamp: []
ApiNonce: []
ApiSignature: []
ApiChainId: []
ApiProduct: []
tags:
- name: Portfolio
description: User info, balances, and positions
paths:
/api/v1/users/{userId}:
get:
operationId: getUser
tags:
- Portfolio
summary: User info
parameters:
- $ref: '#/components/parameters/UserId'
responses:
'200':
$ref: '#/components/responses/Envelope'
'401':
$ref: '#/components/responses/Unauthorized'
/api/v1/users/{userId}/balance:
get:
operationId: getUserBalance
tags:
- Portfolio
summary: Balances
parameters:
- $ref: '#/components/parameters/UserId'
responses:
'200':
$ref: '#/components/responses/Envelope'
'401':
$ref: '#/components/responses/Unauthorized'
/api/v1/users/{userId}/positions:
get:
operationId: getUserPositions
tags:
- Portfolio
summary: Positions
parameters:
- $ref: '#/components/parameters/UserId'
responses:
'200':
$ref: '#/components/responses/Envelope'
'401':
$ref: '#/components/responses/Unauthorized'
components:
responses:
Unauthorized:
description: Authentication failed (invalid key, signature, drift, or empty IP whitelist)
content:
application/json:
schema:
$ref: '#/components/schemas/Envelope'
Envelope:
description: Standard response envelope
content:
application/json:
schema:
$ref: '#/components/schemas/Envelope'
schemas:
Envelope:
type: object
description: All responses share this envelope.
properties:
code:
type: integer
description: 200 on success; error code otherwise.
example: 200
errMsg:
type: string
description: Empty on success; descriptive message on error.
data:
description: Response payload (shape varies per endpoint).
uuid:
type: string
nullable: true
description: Request/trace identifier (null when not applicable).
t:
type: integer
nullable: true
description: Server timestamp (null when not applicable).
parameters:
UserId:
name: userId
in: path
required: true
schema:
type: string
securitySchemes:
ApiKeyAuth:
type: apiKey
in: header
name: x-api-key
description: Partner API key (must be active, unexpired, and IP-whitelisted).
ApiTimestamp:
type: apiKey
in: header
name: x-api-ts
description: Unix millisecond timestamp; must be within 45s drift tolerance.
ApiNonce:
type: apiKey
in: header
name: x-api-nonce
description: Unique replay-prevention nonce per key within the 45s window (UUID recommended).
ApiSignature:
type: apiKey
in: header
name: x-api-sign
description: HMAC-SHA256 signature over the canonical request, hex-encoded (case-insensitive).
ApiChainId:
type: apiKey
in: header
name: x-api-chain-id
description: Chain identifier (e.g. 8453 Base, 1 Ethereum, 143 Monad).
ApiProduct:
type: apiKey
in: header
name: x-api-p
description: Product type; use "Synfutures".