Are you an LLM? Read llms.txt for a summary of the docs, or llms-full.txt for the full context.
Skip to content

Authentication

Parcl offers two paths for programmatic access:

  • Agent keys: a keypair that stays in your infrastructure and signs locally. Use this path for market making, venue adapters, autonomous trading agents, and latency-sensitive bots.
  • API keys: a token you add to requests. Your hosted signing key signs authorized transactions inside a secure enclave. Use this path for simpler integrations that do not sign locally.

Neither agent keys nor API keys can request an off-platform bridge withdrawal. Hosted withdrawals require an authenticated owner session. An owner who signs locally can submit a withdrawal directly to the validator; see the bridge guide.

Browser sign-in

Password and Google sign-in for the same verified email open the same Parcl wallet. The first successful sign-in method creates the wallet; using the other method later links it to that wallet.

If two existing Parcl profiles already claim the same verified email, the app does not create or select another wallet. It locks wallet actions and directs the user to account recovery.

Two-step verification and recovery

An authenticator app is optional for password sign-in. If the user loses that authenticator but still controls the verified email, the email recovery flow can remove the lost sign-in factor and restore account access.

Signing-key export uses a separate export check:

  • With no export authenticator enrolled, each export requires a fresh code sent to the verified email.
  • With an export authenticator enrolled, each export requires a current code from that authenticator.

Email account recovery does not remove an enrolled export authenticator. A user who recovers sign-in access can continue using the account, but cannot export the private key without the enrolled export authenticator.

Hosted signing key

The hosted signing key is encrypted at rest and decrypted only inside an attested secure enclave. The plaintext key is not returned to application servers. The enclave returns a signature for an authorized request.

You can export the signing key through an authenticated browser session after the fresh export check above. API keys and agent keys cannot export it.

Hosted access restrictions also block key export, withdrawals, account recovery, and other authenticated features. Key confidentiality does not guarantee access to the hosted service. A key already exported remains usable with the protocol.

API keys

Generate and manage API keys on the Profile → Keys page:

The key appears once. Copy it when generated. Its format is prcl_sk_<64 hex characters>.

Scope

An API key can submit owner transactions except the actions listed as blocked below. Treat it as broad account access.

AllowedBlocked
Trading, including placing, changing, and cancelling ordersOff-platform bridge withdrawals
Transfers within an account family and subaccount managementAgent-key approval and revocation
Community-vault deposits, share withdrawals, and configurationDeposit and withdrawal history
Public state and most owned-account historySigning-key export

Submitting a blocked transaction returns HTTP 403. Restricted read endpoints also return 403.

Use an API key

Authenticated endpoints use the REST API host. Public live-state endpoints use the validator host.

EnvironmentREST APIValidator API
Mainnethttps://api.v4.parcl.cohttps://validator.v4.parcl.co
Devnethttps://v4-rest-api.dev.parcllabs.comhttps://v4-api.dev.parcllabs.com

Include the X-API-Key header on each authenticated request:

curl -H "X-API-Key: prcl_sk_abc123..." \
  https://v4-rest-api.dev.parcllabs.com/auth/profile

Send unsigned transaction bodies to POST /tx/sign-and-submit. See the quickstart order for a complete example.

Rotate or revoke a key

Generating a new API key immediately invalidates the previous key. Revoking the key on the Profile → Keys page invalidates it without creating another one. Only one API key can be valid for an account at a time.

If a key leaks, revoke it from the mainnet or devnet keys page immediately.

Request limits

API requests and on-chain transactions have separate throttles. See Request limits for response handling and the live per-account budget endpoint.