Gemini Trust Company · Authentication Profile
Gemini Trust Authentication
Authentication
Gemini Trust Company secures its APIs with apiKey, oauth2, and openIdConnect across 3 declared security schemes, as derived from its OpenAPI definitions.
CompanyCryptocurrencyExchangeTradingMarket DataOrder ManagementClearingCustodyFinancial ServicesPrediction MarketsStakingDerivativesWebSocketFIXReal-TimeA2A
Methods: apiKey, oauth2, openIdConnect
Schemes: 3
OAuth flows:
API key in: header
Security Schemes
apiKey apiKey
· in: header (X-GEMINI-APIKEY)
payloadAuth apiKey
· in: header (X-GEMINI-PAYLOAD)
signatureAuth apiKey
· in: header (X-GEMINI-SIGNATURE)
Source
Authentication Profile
generated: '2026-09-18'
method: searched
source: https://developer.gemini.com/authentication/api-key, https://developer.gemini.com/authentication/oauth, https://api.gemini.com/.well-known/oauth-authorization-server,
plus openapi/gemini-trust-rest-openapi.yml and openapi/gemini-trust-prediction-markets-openapi.yml securitySchemes
summary:
types:
- apiKey
- oauth2
- openIdConnect
api_key_in:
- header
note: The two OpenAPIs declare ONLY the three apiKey header schemes. OAuth 2.0 and the SSO OIDC surface are real
and fully documented but are absent from both specs - a machine reading the contract alone would never discover
the delegated-access model or its 33 scopes.
schemes:
- name: apiKey
type: apiKey
in: header
parameter: X-GEMINI-APIKEY
description: Gemini API key with appropriate permissions
sources:
- openapi/gemini-trust-prediction-markets-openapi.yml
- openapi/gemini-trust-rest-openapi.yml
- name: payloadAuth
type: apiKey
in: header
parameter: X-GEMINI-PAYLOAD
description: Base64-encoded private REST payload. See Gemini private REST authentication.
sources:
- openapi/gemini-trust-prediction-markets-openapi.yml
- openapi/gemini-trust-rest-openapi.yml
- name: signatureAuth
type: apiKey
in: header
parameter: X-GEMINI-SIGNATURE
description: Hex HMAC-SHA384 signature of the payload using the API secret.
sources:
- openapi/gemini-trust-prediction-markets-openapi.yml
- openapi/gemini-trust-rest-openapi.yml
docs:
- https://developer.gemini.com/authentication/api-key
- https://developer.gemini.com/authentication/oauth
- https://developer.gemini.com/roles
models:
- name: API key (HMAC-SHA384)
primary: true
in_spec: true
headers:
- X-GEMINI-APIKEY
- X-GEMINI-PAYLOAD
- X-GEMINI-SIGNATURE
- 'Content-Length: 0'
- 'Content-Type: text/plain'
- 'Cache-Control: no-cache'
transport_note: 'Unusual and easy to get wrong: private REST requests send an EMPTY HTTP body. The JSON payload
is base64-encoded into X-GEMINI-PAYLOAD, and X-GEMINI-SIGNATURE is hex(HMAC_SHA384(base64(payload), key=api_secret)).
Gemini warns explicitly that generic OpenAPI-generated clients do not implement this signing transport.'
key_prefixes:
account-: account-scoped key
master-: master key spanning sub-accounts; requires an account parameter
replay_protection:
field: nonce
modes:
- name: time-based (recommended)
rule: Unix epoch seconds, validated within +/- 30 seconds of server time
- name: incremental
rule: strictly increasing per API session key
error: InvalidNonce
sessions: Each API key is an independent session with its own nonce sequence; Cancel-on-Disconnect ties open orders
to a session heartbeat.
provision: https://exchange.gemini.com/settings/api
- name: OAuth 2.0 authorization code
primary: false
in_spec: false
grants:
- authorization_code
- refresh_token
pkce: S256; REQUIRED for public clients (SPA, mobile, desktop). Client type is permanent at app creation.
client_types:
- confidential (client_id + client_secret)
- public (client_id only, PKCE)
token_lifetime:
access_token: 24 hours
refresh_token: non-expiring
review: Gemini reviews registered applications before production activation; sandbox registration is immediate.
scopes: 33 published - see scopes/gemini-trust-scopes.yml
revocation:
- https://exchange.gemini.com/auth/token/revoke
- REST operation revokeOAuthToken (POST /v1/oauth/revokeByToken)
metadata: https://api.gemini.com/.well-known/oauth-authorization-server (RFC 8414)
- name: OpenID Connect (SSO)
primary: false
in_spec: false
scope: Exchange SSO only, not the trading API
issuer: https://exchange.gemini.com
signing: RS256
client_auth: private_key_jwt
scopes:
- openid
- email
metadata: https://api.gemini.com/.well-known/openid-configuration
- name: WebSocket authentication
primary: false
in_spec: asyncapi
methods:
- X-GEMINI-APIKEY + X-GEMINI-NONCE + X-GEMINI-PAYLOAD + X-GEMINI-SIGNATURE on the connection upgrade
- 'Authorization: Bearer <OAuth token>'
docs: https://developer.gemini.com/websocket/authentication
authorization:
model: role-based access control per API key
roles:
- Administrator (Master keys only - create and view accounts in the Master Group)
- Trader (assigned by default)
- Fund Manager
- Auditor
failure: HTTP 403 with reason MissingRole
docs: https://developer.gemini.com/roles
ip_allowlist: Group-level IP allowlisting is enforced; a request from an off-list address returns reason RemoteAddressForbidden.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/gemini-trust-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.