REST API for st0x orderbook operations. Built with Rocket, backed by SQLite, and authenticated via API keys using HTTP Basic auth.
git clone <repo-url>
cd st0x-rest-api
git submodule update --init --recursivenix develop -c bash prep.shThis writes COMMIT_SHA to .env and bootstraps the orderbook submodule.
The binary has two subcommands:
st0x_rest_api serve Start the API server
st0x_rest_api keys Manage API keys
nix develop -c cargo run serveThe server starts on http://localhost:8000 by default. Swagger UI is available
at /swagger.
All API routes (except /health) require HTTP Basic authentication. Use the
keys subcommand to manage credentials.
nix develop -c cargo run keys create --label "partner-x" --owner "contact@example.com"Output:
API key created successfully
Key ID: <uuid>
Secret: <base64-encoded-secret>
Label: partner-x
Owner: contact@example.com
IMPORTANT: Store the secret securely. It will not be shown again.
The secret is hashed with Argon2 before storage. There is no way to recover it.
nix develop -c cargo run keys listShows all keys with their ID, label, owner, active status, rate-limit override, and timestamps.
nix develop -c cargo run -- keys --config config/prod.toml set-rate-limit <KEY_ID> 300Sets a requests-per-minute override for one API key. The override is read on each authenticated request, so restarting the server is not required. Clear it to return the key to the configured default:
nix develop -c cargo run -- keys --config config/prod.toml clear-rate-limit <KEY_ID>nix develop -c cargo run keys revoke <KEY_ID>Sets the key to inactive. Revoked keys are rejected at authentication.
nix develop -c cargo run keys delete <KEY_ID>Permanently removes the key from the database.
Use HTTP Basic auth with the key ID as the username and the secret as the password:
curl -u "<KEY_ID>:<SECRET>" http://localhost:8000/v1/tokensOr with an explicit header:
curl -H "Authorization: Basic $(echo -n '<KEY_ID>:<SECRET>' | base64)" http://localhost:8000/v1/tokensnix develop -c cargo fmt
nix develop -c rainix-rs-static
nix develop -c cargo test