Prerequisites: an active VOOI API token. See API Tokens to obtain one, then include it as
Authorization: Bearer <token> on every request below.Hyperliquid
Prefer to skip the Hyperliquid UI? Register on Hyperliquid lets VOOI provision an agent wallet for you.
- Go to Hyperliquid API Management.
- Generate an API wallet. This is a separate key from your main wallet — it is what VOOI will use for trading, and keeping it separate limits risk if the key is ever compromised.
-
Send the credentials to
POST /user-exchange/hyperliquid:
Aster
Prefer to skip the signing flow? Register on Aster lets VOOI provision an agent for you.
privateKey), that agent’s address (signer), and your main wallet address (user). Most callers should use the registration flow instead, which provisions an approved agent for you.
Send the credentials to POST /user-exchange/aster:
Lighter
Prefer to skip the Lighter UI? Register on Lighter lets VOOI provision a key for you.
- Go to Lighter API Keys.
- Create an API key.
-
Find your Lighter account index:
-
Send the credentials to
POST /user-exchange/lighter:
Robinhood
Robinhood runs on Lighter’s infrastructure, so it uses the same credential shape as Lighter. Prefer to skip the UI? Register on Robinhood lets VOOI provision a key for you.
accountIndex), an API key slot (apiKeyIndex), and that key’s private key (privateKey). Send them to POST /user-exchange/robinhood:
Extended
Prefer to skip handling Stark keys? Register on Extended lets VOOI provision the L2 keypair and API key for you, and is the recommended path.
accountId (your Extended account, a positive integer), apiKey, the L2 keypair (l2PrivateKey and l2PublicKey, hex), and vaultId (a positive-integer string). Most callers should use the registration flow instead, which provisions all of these for you.
Send the credentials to POST /user-exchange/extended:
Binance
Binance is a centralized venue, so its credentials are a standard Binance USDⓈ-M futures API key and secret — not a wallet key. Create the key in your Binance account with futures trading enabled, then send it toPOST /user-exchange/binance:
Binance has no VOOI-managed registration flow — connecting your own API key is the only path. VOOI also does not expose deposits, withdrawals, or transfers for Binance; move funds through Binance directly.
Bybit
Bybit credentials are a standard API key and secret. The account must be a Unified Trading Account — a classic account is rejected — and the key must carry derivatives trading permission and must not be read-only or expired. Send them toPOST /user-exchange/bybit:
Bybit requires a one-time trading agreement before it accepts any order on a traditional-asset market. See Bybit trading agreements.
MEXC
MEXC credentials are a standard API key and secret. The key needs three futures permissions — View Account Details, View Order Details, and Order Placing. A key missing any of them is rejected on connect with a400 naming the ones to turn on. Send the credentials to POST /user-exchange/mexc:
Ondo
Ondo credentials are an API key id and secret (apiKeyId, not apiKey). Send them to POST /user-exchange/ondo:
Ondo also supports a VOOI-managed registration flow, which signs a challenge with your wallet and provisions the API key for you — see Registration flows.
Registration flows
Several venues let VOOI provision credentials for you instead of you pasting your own. Those flows share one pair of endpoints,POST /user-exchange/{exchange}/register/prepare and POST /user-exchange/{exchange}/register/execute, and are available on Aster, Hyperliquid, Lighter, Robinhood, Extended, and Ondo. Binance, Bybit, and MEXC are API-key only.
The prepare call accepts an optional referralCode that is bound to the new account at registration; omit it and the VOOI code is applied. See the per-venue guides (Hyperliquid, Lighter, Aster, Extended, Robinhood) for the signing steps.
Verify and disconnect
GET /user-exchange— list the exchanges currently connected to your VOOI account. Each row carries avalidflag (see below).DELETE /user-exchange/{exchange}— remove a connection.
Credential validity
Every connect endpoint above performs a live check against the venue before returning, and there are two distinct failure paths:- Malformed body — a bad key format, an invalid wallet address, or a missing field is rejected with
400 Bad Requestduring validation. Nothing is stored. - Venue-rejected credentials — a well-formed body whose credentials the venue itself rejects returns
401 Unauthorized. In this case the connection is recorded, withvalid: false, so it shows up on/user-exchangeuntil you re-connect or remove it.
valid: true until VOOI sees the venue reject those credentials at trade or read time (key revoked, agent expired, account closed). At that point valid flips to false and the connection is silently excluded from the accounts, positions, orders, and trades endpoints and the SSE updates stream — as if that exchange were not connected. The entry still appears on GET /user-exchange with valid: false, so a UI can prompt the user to re-connect.
To recover, call the connect endpoint again with fresh credentials, or DELETE /user-exchange/{exchange} and start over.
Next steps
Place your first trade
Orders, cancels, and bracket TP/SL
Broker API
Register users and pull their trading statistics