Access and authority
Establish who may read an account separately from who may authorize an economic action.
Environments#
| Environment | What these docs establish |
|---|---|
| Hosted sandbox | A verified base URL and credential setup are not supplied. |
| Production | A verified base URL, released authentication and signing contract are not supplied. |
The request examples are synthetic target contracts. No live endpoint is supplied for submitting them.
Account selection is not authentication#
Private requests require current authorized account access. X-Omega-Account-Id selects an account context and does not prove the caller's identity. Knowing an order or operation ID does not grant permission to read it.
Spending authority is separate#
API access permission does not authorize a trade or movement. Economic authority must bind the exact account, action, asset identities, quantities, fees, destinations and applicable limits. The final owner-signing envelope, replay/nonce rules and credential lifecycle remain unresolved.
The illustrative payloads do not establish production cryptographic verification. Use the released signing contract before submitting an economic instruction.
Before using a live host#
Obtain the environment's released credential setup, verified base URL, signing format and replay policy. Confirm the permissions for the selected account. There is no assumed Bearer-token or API-key scheme in this specification.