curl --request POST \
--url https://mcp.echozero.app/api/v1/wallet/withdraw \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '{
"amount": 25
}'{
"success": true,
"data": {
"success": true,
"transactionId": "<string>",
"amount": 123,
"tokenSymbol": "<string>",
"message": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"tradeId": "<string>",
"openTradeUpdatePending": true
}
}Withdraw funds
Mirrors GraphQL withdrawFunds. Requires HMAC signing. Withdrawals that require MFA return MFA_VERIFICATION_REQUIRED — complete MFA in the main app, then retry. API-key sessions cannot satisfy withdrawal MFA. Concurrent withdraws of the same wallet + mint fail with WITHDRAWAL_IN_PROGRESS even without Idempotency-Key; SOL and USDC may run in parallel. Frozen wallets return WALLET_FROZEN / HTTP 403.
curl --request POST \
--url https://mcp.echozero.app/api/v1/wallet/withdraw \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '{
"amount": 25
}'{
"success": true,
"data": {
"success": true,
"transactionId": "<string>",
"amount": 123,
"tokenSymbol": "<string>",
"message": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"tradeId": "<string>",
"openTradeUpdatePending": true
}
}Authorizations
Headers
Optional. Replaying the same key for the same user returns the cached result without a second withdrawal.
Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.
Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.
Body
OpenAPI: McpWalletOperationBodyDto. toAddress is required for withdrawal.