Authentication
Which streams need credentials, where they come from, and how the engine socket takes an access token.
SDK streams
The SDK streams connect to each venue directly, so they authenticate the way the venue does. Credentials are read from the environment or a .env file with load_credentials() and never leave your process.
| Stream | Credentials | Carries |
|---|---|---|
PolymarketMarketStream | None | Books, quotes, trades, new markets and resolutions |
PolymarketUserStream | CLOB API credentials, or a PolymarketTrading to derive them from the wallet key | Orders, fills with settlement state |
KalshiStream | Kalshi key, even for market data: the venue signs the handshake | Books, quotes, trades, lifecycle; orders, fills, positions |
PolymarketUSMarketStream | Retail API key | Books, quotes, trades, market state |
PolymarketUSPrivateStream | Retail API key | Orders, fills, positions, balances |
from synpath import KalshiStream, PolymarketUserStream, PolymarketTrading, load_credentials, require
creds = load_credentials() # KALSHI_*, POLYMARKET_* from .env
kalshi = KalshiStream(require("kalshi", creds))
poly = PolymarketUserStream(trading=PolymarketTrading(require("polymarket", creds)))The variables each venue needs are listed on the REST Authentication page. A stream the venue refuses for good, such as a private channel without permission, ends with StreamStatusEvent(state="failed").
Engine events socket
The socket is served by your self-hosted server (synpath serve) and takes the same access token as its /trading routes, with view permission. Browsers cannot set headers on a WebSocket handshake, so the token is accepted as a query parameter; a bearer header works where one can be set.
websocat "ws://127.0.0.1:8000/trading/ws/events?key=$SYNPATH_ACCESS_TOKEN&since=0&kinds=order.accepted,fill.booked"A missing or invalid token closes the connection with code 4401. Events are filtered to the accounts the token may see.

