Authentication
Market data needs nothing. Trading uses each venue's own credentials, on your machine. Synpath's hosted data takes an API key.
Hosts
Synpath serves two hostnames.
api.synpath.dev: cross-venue market and event matching (/match/*).api2.synpath.dev: tick-level historical order books and trades (/v1/*).
The same Synpath API key authenticates against both; there are no separate credentials.
Trading is self-hosted: orders go from your own machine straight to the venues, and need no Synpath API key.
Synpath API key
1. Sign in
synpath login opens Google sign-in in your browser and returns to the terminal. It saves a short-lived session for managing data API keys; signing in does not create a key.
synpath loginWhile Google sign-in is in testing, your Google account must be in the OAuth test-user audience.
2. Create a data API key
Give the key a label for the device or application that will use it. The CLI saves the latest key to ~/.config/synpath/credentials.json, readable only by you, and prints the secret once. Keep it private, or add --no-print-key to save it without showing it.
synpath keys create my-laptopThe Python client reads the saved key automatically. SYNPATH_API_KEY, or api_key= on a call, overrides it. For direct HTTP requests, send the key as Authorization: Bearer <key>. The library sends it to Synpath's services only, never to a venue.
synpath.match_market("kalshi:KXFEDDECISION-26OCT-C25") # uses the saved key
synpath.fetch_order_book_at("kalshi:KXQUANTUM-30", as_of_ms=1789509599000,
api_key="spk_...") # an explicit key winsManage your keys
synpath keys list
synpath keys revoke <key-id>
synpath logoutlogout ends the key-management session. It does not revoke an issued API key. The CLI supports --help on each command for options, including synpath keys create --help.
Set up venue credentials
To trade, synpath uses your own API keys at each venue. They stay on your machine, in a file or in environment variables, and are never sent to Synpath. You only need keys for the venues you trade on; market data needs none.
1. Create your keys at each venue
Kalshi
- Sign in at kalshi.com and open Profile Settings → API Keys.
- Click Create New API Key. Copy the Key ID, and save the private key file it downloads, for example to
~/.kalshi/kalshi.pem. Kalshi shows the private key only once. - To practise first, create a key the same way on demo.kalshi.co and set
KALSHI_ENV=demo.
Polymarket
- Export the private key of the wallet you sign in with: on polymarket.com, Settings → Private Key → Start Export. If you sign in with a browser wallet such as MetaMask, export it from that wallet.
- Copy your trading wallet address, shown under your profile menu on polymarket.com. This is the funder.
- Set the signature type:
3for accounts created since May 2026,1or2for older proxy or Safe wallets.
Polymarket US
- Complete identity verification in the Polymarket US app.
- Create an API key at polymarket.us/developer and copy the key ID and the secret.
2. Save them in a .env file
synpath reads your keys from a file named .env in the folder you run it from, so they stay on your machine and out of your code. The easiest way to create it:
synpath init # asks for each venue's keys and writes .env, readable by you onlyOr write it yourself, one setting per line, leaving out the venues you do not use:
KALSHI_KEY_ID=a1b2c3d4-...
KALSHI_PRIVATE_KEY_PATH=/Users/you/.kalshi/kalshi.pem
KALSHI_ENV=prod # or demo for Kalshi's practice exchange
POLYMARKET_PRIVATE_KEY=0x...
POLYMARKET_FUNDER=0x... # your trading wallet address
POLYMARKET_SIGNATURE_TYPE=3
POLYMARKET_US_KEY_ID=...
POLYMARKET_US_SECRET_KEY=...Access token
Your self-hosted server (synpath serve) only accepts trading calls that carry its access token.
- Same machine: nothing to do. The server saves its token on first start, and your scripts on the same machine use it automatically.
- Another machine, such as a VPS: copy the token the server printed when it started, and pass it as
SYNPATH_ACCESS_TOKEN.
client = synpath.Client(server="http://127.0.0.1:8000") # same machine
client = synpath.Client(server="https://trading.example.com") # elsewhere: reads SYNPATH_ACCESS_TOKENErrors
| Status | Meaning | SDK exception |
|---|---|---|
401 | No token or key, or an unknown one | AuthenticationError |
403 | The token lacks the permission the route needs; the message names it | AuthenticationError |
venue 401 | The venue refused your credentials | AuthenticationError from that venue's adapter |

