Sign in, discover a Deribit trading account and keep credentials and tokens out of browsers, logs and repositories.
Updated Oct 5, 2026official-api
1. Sign in
Request
URL
Required body
POST
https://auth.greeks.live/api/v1/auth/sign_in
email, pwd; code_2fa when enabled
Optional documented fields are device_id and affiliate_code. A successful response contains the token used in the Authorization header for protected calls.
2. List trading accounts
Request
URL
Recommended body
POST
https://auth.greeks.live/api/v1/account/list
exchange: deribit; source: adv_tools
Use the returned id as account_id. Select only records whose status is 1 and verify exchange is deribit. auth_type may be api or oauth; other returned metadata is not a stable integration contract. Authentication and account discovery use https://auth.greeks.live and the full URLs above. Subsequent Stable tool requests use https://tools.greeks.live/api as their base: for example, POST https://tools.greeks.live/api/user/get_environment. Send Authorization as an HTTP header, not a JSON body field. The environment-read endpoint has no body parameters; it does not switch environments or start trading.
3. Send protected requests
Header
Use
Content-Type: application/json
Required for documented POST bodies.
Authorization
Token returned by sign-in. Confirm the exact prefix with the API owner before production.
Minimum security controls
Store the password and token in a secret manager; never commit them to source control.
Redact Authorization, pwd, code_2fa, cookies and complete account identifiers from logs and support screenshots.
Use a dedicated automation account with the minimum Deribit permissions and no withdrawal permission.
Separate production and test secrets and restrict outbound hosts to Greeks.live and the required exchange endpoints.
Fail closed when authentication is uncertain; do not repeatedly retry a password or 2FA request.
Create an operational procedure to revoke access and stop strategies if a token or host is compromised.