Documentation Index
Fetch the complete documentation index at: https://docs.whitebit.com/llms.txt
Use this file to discover all available pages before exploring further.
Introduction
WhiteBIT OAuth 2.0 implementation uses the standard Authorization Code Grant flow. This flow is suitable for server-side applications where the client secret can be securely stored. The OAuth 2.0 endpoints documented on this page cover the Authorization Code Grant flow for read access to account data. For partner-issued API keys, a separate OAuth API key flow uses Authorization Code with PKCE (S256), a 4-hour access token, and no refresh token. See the Fast API Key integration guide for the full integration.Scopes
Available Scopes (requested during client setup):general: General API accessshow.userinfo: Access to basic user informationusers.read: Read user datausers.email.read: Read user email informationusers.kyc.read: Information about whether a user has passed KYC verificationorders.read: Read trading ordersorders.create: Create trading ordersorders.delete: Delete trading ordersbalances.read: Read account balancesmarkets.read: Read market informationdeals.read: Read trading dealsorders_history.read: Read order historyusers.transactions.read: Read user transactionsusers.converts.read: Read currency conversion historyusers.balances.read: Read user account balancesusers.orders.read: Read user ordersusers.deals.read: Read user dealsapikeys.create: Issue an OAuth-bound API key during the consent flowapikeys.read: Read OAuth-issued API key state and retrieve its secret onceapikeys.delete: Delete an OAuth-issued API key owned by the OAuth2 client