Skip to main content
POST

Authorizations

Authorization
string
header
required

User JWT access token issued by POST /api/auth/verify or POST /api/auth/social/verify. Routes that accept both auth modes declare api-key and bearer-jwt security schemes.

Headers

x-signature
string
required

Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.

x-timestamp
string
required

Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.

Path Parameters

agentId
string
required

Body

application/json
amountUsd
number
required

USD amount to withdraw from unused allocation (Hyperliquid REAL is also capped by live free collateral)

Required range: x >= 0.01

Response

200 - application/json

Withdraw result.

success
boolean
required
Example:

true

data
object
required

Endpoint-specific payload