Skip to main content
Create a public key and secret in Console. Set BRAVADO_API_KEY and BRAVADO_API_SECRET on your server. Keep the secret out of frontend code. These helpers sign the exact body sent and canonicalize query parameters. Every call, including a retry, receives a fresh timestamp and signature. Keep the same idempotency key when retrying the same intended write. Do not reuse signed headers across different requests.

Python

Install requests and save the following as bravado_auth.py beside your script. It signs the prepared request after JSON serialization and query encoding. Redirects are disabled; repeated query keys and streaming bodies are rejected.
For a master or per-user credential, pass auth=BravadoAuth(public_key, matching_secret) to the request. Never pair one user’s public key with another user’s secret.

Node.js

Save this as bravado-auth.mjs and import bravadoFetch in your server code. Serialize JSON once with JSON.stringify and pass that string as body.

cURL and HTTP reference examples

Reference pages show the three required headers using placeholders. Replace the timestamp and signature for each individual request using the signing contract, or use a runnable example above. Include the final query and exact body bytes in the signature; do not copy a signature from a different endpoint. MCP uses OAuth. Market-data feeds have their own authentication contracts; these HTTP helpers do not replace them.