Authentication
Parcl offers two paths for programmatic access:
- Agent keys: a keypair that stays in your infrastructure and signs locally. Use this path for market making, venue adapters, autonomous trading agents, and latency-sensitive bots.
- API keys: a token you add to requests. Your hosted signing key signs authorized transactions inside a secure enclave. Use this path for simpler integrations that do not sign locally.
Neither agent keys nor API keys can request an off-platform bridge withdrawal. Hosted withdrawals require an authenticated owner session. An owner who signs locally can submit a withdrawal directly to the validator; see the bridge guide.
Browser sign-in
Password and Google sign-in for the same verified email open the same Parcl wallet. The first successful sign-in method creates the wallet; using the other method later links it to that wallet.
If two existing Parcl profiles already claim the same verified email, the app does not create or select another wallet. It locks wallet actions and directs the user to account recovery.
Two-step verification and recovery
An authenticator app is optional for password sign-in. If the user loses that authenticator but still controls the verified email, the email recovery flow can remove the lost sign-in factor and restore account access.
Signing-key export uses a separate export check:
- With no export authenticator enrolled, each export requires a fresh code sent to the verified email.
- With an export authenticator enrolled, each export requires a current code from that authenticator.
Email account recovery does not remove an enrolled export authenticator. A user who recovers sign-in access can continue using the account, but cannot export the private key without the enrolled export authenticator.
Hosted signing key
The hosted signing key is encrypted at rest and decrypted only inside an attested secure enclave. The plaintext key is not returned to application servers. The enclave returns a signature for an authorized request.
You can export the signing key through an authenticated browser session after the fresh export check above. API keys and agent keys cannot export it.
Hosted access restrictions also block key export, withdrawals, account recovery, and other authenticated features. Key confidentiality does not guarantee access to the hosted service. A key already exported remains usable with the protocol.
API keys
Generate and manage API keys on the Profile → Keys page:
The key appears once. Copy it when generated. Its format is
prcl_sk_<64 hex characters>.
Scope
An API key can submit owner transactions except the actions listed as blocked below. Treat it as broad account access.
| Allowed | Blocked |
|---|---|
| Trading, including placing, changing, and cancelling orders | Off-platform bridge withdrawals |
| Transfers within an account family and subaccount management | Agent-key approval and revocation |
| Community-vault deposits, share withdrawals, and configuration | Deposit and withdrawal history |
| Public state and most owned-account history | Signing-key export |
Submitting a blocked transaction returns HTTP 403. Restricted read endpoints
also return 403.
Use an API key
Authenticated endpoints use the REST API host. Public live-state endpoints use the validator host.
| Environment | REST API | Validator API |
|---|---|---|
| Mainnet | https://api.v4.parcl.co | https://validator.v4.parcl.co |
| Devnet | https://v4-rest-api.dev.parcllabs.com | https://v4-api.dev.parcllabs.com |
Include the X-API-Key header on each authenticated request:
curl -H "X-API-Key: prcl_sk_abc123..." \
https://v4-rest-api.dev.parcllabs.com/auth/profileSend unsigned transaction bodies to POST /tx/sign-and-submit. See the
quickstart order for a complete example.
Rotate or revoke a key
Generating a new API key immediately invalidates the previous key. Revoking the key on the Profile → Keys page invalidates it without creating another one. Only one API key can be valid for an account at a time.
If a key leaks, revoke it from the mainnet or devnet keys page immediately.
Request limits
API requests and on-chain transactions have separate throttles. See Request limits for response handling and the live per-account budget endpoint.