List Sub-Account API Keys
curl --request POST \
--url https://whitebit.com/api/v4/sub-account/api-key/list \
--header 'Content-Type: application/json' \
--header 'X-TXC-APIKEY: <api-key>' \
--header 'X-TXC-PAYLOAD: <api-key>' \
--header 'X-TXC-SIGNATURE: <api-key>' \
--data '
{
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"limit": 100,
"offset": 0
}
'import requests
url = "https://whitebit.com/api/v4/sub-account/api-key/list"
payload = {
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"limit": 100,
"offset": 0
}
headers = {
"X-TXC-APIKEY": "<api-key>",
"X-TXC-PAYLOAD": "<api-key>",
"X-TXC-SIGNATURE": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-TXC-APIKEY': '<api-key>',
'X-TXC-PAYLOAD': '<api-key>',
'X-TXC-SIGNATURE': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({subAccountId: '8e667b4a-0b71-4988-8af5-9474dbfaeb51', limit: 100, offset: 0})
};
fetch('https://whitebit.com/api/v4/sub-account/api-key/list', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://whitebit.com/api/v4/sub-account/api-key/list",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'subAccountId' => '8e667b4a-0b71-4988-8af5-9474dbfaeb51',
'limit' => 100,
'offset' => 0
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-TXC-APIKEY: <api-key>",
"X-TXC-PAYLOAD: <api-key>",
"X-TXC-SIGNATURE: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://whitebit.com/api/v4/sub-account/api-key/list"
payload := strings.NewReader("{\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"limit\": 100,\n \"offset\": 0\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-TXC-APIKEY", "<api-key>")
req.Header.Add("X-TXC-PAYLOAD", "<api-key>")
req.Header.Add("X-TXC-SIGNATURE", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://whitebit.com/api/v4/sub-account/api-key/list")
.header("X-TXC-APIKEY", "<api-key>")
.header("X-TXC-PAYLOAD", "<api-key>")
.header("X-TXC-SIGNATURE", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"limit\": 100,\n \"offset\": 0\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://whitebit.com/api/v4/sub-account/api-key/list")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-TXC-APIKEY"] = '<api-key>'
request["X-TXC-PAYLOAD"] = '<api-key>'
request["X-TXC-SIGNATURE"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"limit\": 100,\n \"offset\": 0\n}"
response = http.request(request)
puts response.read_body{
"limit": 123,
"offset": 123,
"data": [
{
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"title": "Trading Bot Key",
"isEnabled": true,
"apiKey": "pub-key-abc123",
"apiSecret": "",
"type": "1",
"lastActivity": 1641081600,
"restrictAccess": false,
"accessEndpoints": [
{
"name": "withdraw",
"title": "Withdraw",
"urls": [
{
"url": "/api/v4/main-account/withdraw",
"enable": false
}
]
}
]
}
]
}{
"code": 0,
"message": "Validation failed",
"errors": {
"limit": [
"validation.integer"
],
"offset": [
"validation.integer"
]
}
}List Sub-Account API Keys
The endpoint retrieves a list of API keys for a sub-account. Note: For security reasons, the apiSecret field returns an empty string.
Rate limit: 1000 requests/10 sec.
The API does not cache the response.
Results are sorted by api-key id descending (newest key first). The response is a plain array with no total, has_more, or cursor — a returned count below limit marks the last page (an empty array means no further records).
List Sub-Account API Keys
curl --request POST \
--url https://whitebit.com/api/v4/sub-account/api-key/list \
--header 'Content-Type: application/json' \
--header 'X-TXC-APIKEY: <api-key>' \
--header 'X-TXC-PAYLOAD: <api-key>' \
--header 'X-TXC-SIGNATURE: <api-key>' \
--data '
{
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"limit": 100,
"offset": 0
}
'import requests
url = "https://whitebit.com/api/v4/sub-account/api-key/list"
payload = {
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"limit": 100,
"offset": 0
}
headers = {
"X-TXC-APIKEY": "<api-key>",
"X-TXC-PAYLOAD": "<api-key>",
"X-TXC-SIGNATURE": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-TXC-APIKEY': '<api-key>',
'X-TXC-PAYLOAD': '<api-key>',
'X-TXC-SIGNATURE': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({subAccountId: '8e667b4a-0b71-4988-8af5-9474dbfaeb51', limit: 100, offset: 0})
};
fetch('https://whitebit.com/api/v4/sub-account/api-key/list', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://whitebit.com/api/v4/sub-account/api-key/list",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'subAccountId' => '8e667b4a-0b71-4988-8af5-9474dbfaeb51',
'limit' => 100,
'offset' => 0
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-TXC-APIKEY: <api-key>",
"X-TXC-PAYLOAD: <api-key>",
"X-TXC-SIGNATURE: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://whitebit.com/api/v4/sub-account/api-key/list"
payload := strings.NewReader("{\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"limit\": 100,\n \"offset\": 0\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-TXC-APIKEY", "<api-key>")
req.Header.Add("X-TXC-PAYLOAD", "<api-key>")
req.Header.Add("X-TXC-SIGNATURE", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://whitebit.com/api/v4/sub-account/api-key/list")
.header("X-TXC-APIKEY", "<api-key>")
.header("X-TXC-PAYLOAD", "<api-key>")
.header("X-TXC-SIGNATURE", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"limit\": 100,\n \"offset\": 0\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://whitebit.com/api/v4/sub-account/api-key/list")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-TXC-APIKEY"] = '<api-key>'
request["X-TXC-PAYLOAD"] = '<api-key>'
request["X-TXC-SIGNATURE"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"limit\": 100,\n \"offset\": 0\n}"
response = http.request(request)
puts response.read_body{
"limit": 123,
"offset": 123,
"data": [
{
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"title": "Trading Bot Key",
"isEnabled": true,
"apiKey": "pub-key-abc123",
"apiSecret": "",
"type": "1",
"lastActivity": 1641081600,
"restrictAccess": false,
"accessEndpoints": [
{
"name": "withdraw",
"title": "Withdraw",
"urls": [
{
"url": "/api/v4/main-account/withdraw",
"enable": false
}
]
}
]
}
]
}{
"code": 0,
"message": "Validation failed",
"errors": {
"limit": [
"validation.integer"
],
"offset": [
"validation.integer"
]
}
}For security reasons, the
apiSecret field returns an empty string in the response. The API secret is only displayed once during the initial API key creation.Authorizations
The public WhiteBIT API key.
Base64-encoded JSON request body.
HMAC-SHA512 signature of the payload, hex-encoded. Computed as hex(HMAC-SHA512(payload, api_secret)).
Body
application/json
Was this page helpful?