1. Sign in

RequestURLRequired body
POSThttps://auth.greeks.live/api/v1/auth/sign_inemail, pwd; code_2fa when enabled

Optional documented fields are device_id and affiliate_code. A successful response contains the token used in the Authorization header for protected calls.

2. List trading accounts

RequestURLRecommended body
POSThttps://auth.greeks.live/api/v1/account/listexchange: deribit; source: adv_tools

Use the returned id as account_id. Select only records whose status is 1 and verify exchange is deribit. auth_type may be api or oauth; other returned metadata is not a stable integration contract. Authentication and account discovery use https://auth.greeks.live and the full URLs above. Subsequent Stable tool requests use https://tools.greeks.live/api as their base: for example, POST https://tools.greeks.live/api/user/get_environment. Send Authorization as an HTTP header, not a JSON body field. The environment-read endpoint has no body parameters; it does not switch environments or start trading.

3. Send protected requests

HeaderUse
Content-Type: application/jsonRequired for documented POST bodies.
AuthorizationToken returned by sign-in. Confirm the exact prefix with the API owner before production.

Minimum security controls

  • Store the password and token in a secret manager; never commit them to source control.
  • Redact Authorization, pwd, code_2fa, cookies and complete account identifiers from logs and support screenshots.
  • Use a dedicated automation account with the minimum Deribit permissions and no withdrawal permission.
  • Separate production and test secrets and restrict outbound hosts to Greeks.live and the required exchange endpoints.
  • Fail closed when authentication is uncertain; do not repeatedly retry a password or 2FA request.
  • Create an operational procedure to revoke access and stop strategies if a token or host is compromised.
Current Stable source referenceOfficial Notion API document retained for field-level verification.