Synpath
Overview

Authentication

Which streams need credentials, where they come from, and how the engine socket takes an access token.

SDK streams

The SDK streams connect to each venue directly, so they authenticate the way the venue does. Credentials are read from the environment or a .env file with load_credentials() and never leave your process.

StreamCredentialsCarries
PolymarketMarketStreamNoneBooks, quotes, trades, new markets and resolutions
PolymarketUserStreamCLOB API credentials, or a PolymarketTrading to derive them from the wallet keyOrders, fills with settlement state
KalshiStreamKalshi key, even for market data: the venue signs the handshakeBooks, quotes, trades, lifecycle; orders, fills, positions
PolymarketUSMarketStreamRetail API keyBooks, quotes, trades, market state
PolymarketUSPrivateStreamRetail API keyOrders, fills, positions, balances
from synpath import KalshiStream, PolymarketUserStream, PolymarketTrading, load_credentials, require

creds = load_credentials()                       # KALSHI_*, POLYMARKET_* from .env
kalshi = KalshiStream(require("kalshi", creds))
poly = PolymarketUserStream(trading=PolymarketTrading(require("polymarket", creds)))

The variables each venue needs are listed on the REST Authentication page. A stream the venue refuses for good, such as a private channel without permission, ends with StreamStatusEvent(state="failed").

Engine events socket

The socket is served by your self-hosted server (synpath serve) and takes the same access token as its /trading routes, with view permission. Browsers cannot set headers on a WebSocket handshake, so the token is accepted as a query parameter; a bearer header works where one can be set.

websocat "ws://127.0.0.1:8000/trading/ws/events?key=$SYNPATH_ACCESS_TOKEN&since=0&kinds=order.accepted,fill.booked"

A missing or invalid token closes the connection with code 4401. Events are filtered to the accounts the token may see.

A token in a query string is written to intermediaries' request logs. Prefer the bearer header from server-side code, and issue a view-only token for anything that streams.