Authentication
URL — No public environment serves this socket yet.
Credentials
ticket
Sent as query parameter ticket
The browser’s credential: a short-lived, single-use ticket from trading-gateway’s POST /v1/ws-tickets, on the handshake URL. One of the two schemes, never both.
bearer
Sent as header Authorization: Bearer … (JWT)
Every other client’s credential: the access token as Authorization: Bearer … on the handshake, stating an expiry. One of the two schemes, never both.
Create a WebSocket ticket
REST API POST /v1/ws-tickets
Exchanges your bearer token for a ticket that opens the trading WebSocket once: pass it as ?ticket= on the WebSocket URL before expiresAtNs. It carries your identity and never outlives your token; never cache or log it. No Idempotency-Key: every call mints a new ticket. The guide.
Request parameters
Response parameters
Refusals
The session is open and authenticated
The first frame of every session, sent before the client says anything — unless access was revoked between the handshake and this frame, when the first frame is sessionClosing (PRINCIPAL_REVOKED, 4003, not retryable) instead. The session was authenticated on its handshake, so there is no auth to ack, and this carries what the ack carries — the grant, never the grantee. Subscribe straight away. To renew the credential before expiresAtNs, re-auth over the open socket with op: auth, for the same principal; its answer is authAck.
Re-authenticate the session
Op auth
The in-band re-auth: a session is authenticated on its handshake (a ticket or a bearer token), and this op renews its credential over the open socket — answer the sessionExpiring hint with it, or schedule it off expiresAtNs. It is never the way in: from 1.4.0 a handshake without a credential is refused, so no session ever owes it. The answer carries the GRANT, not the grantee — what this session may do and until when, with no identifier in it, because the client presented the token and already knows who it is.
A session may re-auth with a fresh credential for the SAME principal, which renews its lease. A credential naming a different principal is refused FORBIDDEN_PRINCIPAL and the session keeps the one it was opened with: the identity is immutable for the life of the socket.
Request parameters
Response parameters
The grant, never the grantee. capabilities are the register row’s bits — not token claims, so they reflect what an administrator has granted rather than what was true when the token was issued — read at admission and fixed for the session. An administrator clearing one does not change an open session’s grant: re-auth over the socket to pick up the new set. expiresAtNs is when the session closes; schedule a re-auth off it rather than decoding the token.
Refusal parameters
This session’s credential lapses soon
Sent once per credential, one lead time before the lapse. Re-auth over the open socket with a fresh credential for the same principal and keep your subscriptions; renewing re-arms the hint. It exists because a client that schedules its own refresh may simply not be running when its timer fires — a throttled background tab — where an inbound frame is something the browser will deliver.