← Polymarket Tool Guides

Polymarket API Authentication: Public Data and Trading Keys

There is no single Polymarket key for every task. The official API overview describes public Gamma market data without credentials, a separate Data API for positions and activity, and the CLOB for order books and private order management. This guide is a source-based decision path, not an authenticated integration test.

Start with the information you need

If you only need public market metadata, read the Gamma API's documented public request before handling any wallet credentials. Position and activity data belong to the Data API; the CLOB is a different integration surface. Confirm the exact endpoint and whether it is public in current official documentation rather than creating a trading key for a read-only task.

Private CLOB requests have two signing layers

For private CLOB access, the provider documents an L1 wallet-controlled EIP-712 signature to create or derive API credentials, followed by L2 HMAC-SHA256 request signing with those credentials. Order placement also needs a wallet signature authorizing the order. Do not paste private keys, API secrets, passphrases or signatures into this directory or a contribution form.

What remains unverified here

Polytoolhub did not sign a message, create a credential, make an authenticated request, place an order, or establish current account eligibility. The operator must check the official authentication documentation, current access restrictions, safe storage and revocation procedure before attempting a private integration; this article does not verify those steps.

Before you start

  • A defined read-only dataset or a specific private CLOB action, not a request for a generic trading key.
  • The current official API overview and an operator-controlled wallet only if private access is actually required.
  • A plan to keep wallet and API secrets out of this directory, public logs and issue reports.

Follow the steps

  1. Decide whether a key is needed

    Input: The intended dataset and whether the action is a public read or a private order/account operation.

    Action: Compare Gamma, Data API and CLOB responsibilities in the official integration overview without generating credentials.

    Expected result: A selected documented API surface and a list of any outstanding access questions; public Gamma market metadata does not itself require a trading key.

    Choose another tool from Polymarket APIs and Data Providers

    Check the result

    • Record the chosen host and whether the documented action requires credentials.

    Limitations

    • This is a documentation decision, not a successful public API request.
  2. Identify the CLOB L1 prerequisite

    Input: A private CLOB task, the official ClobAuth EIP-712 specification and a wallet controlled by its actual operator.

    Action: Read the documented signer address, current timestamp, nonce and wallet signature requirements; do not sign a message for this guide.

    Expected result: The credential-creation prerequisites and the distinction between provider instructions and an untested local account.

    Choose another tool from Polymarket APIs and Data Providers

    Check the result

    • Distinguish the L1 signed message from a reusable API credential without producing either one.

    Limitations

    • Reading signing parameters does not establish access or authorize this directory to handle a wallet.
  3. Plan private request signing without exposing secrets

    Input: The provider's L2 HMAC description and the chosen private CLOB endpoint.

    Action: Identify the five required request headers, exact body serialization and separate order-authorization signature in the official docs; plan secure storage and revocation checks outside this site.

    Expected result: A checklist for an operator-controlled integration, not a generated key, authenticated response or tested trade.

    Choose another tool from Polymarket APIs and Data Providers

    Check the result

    • List the L2 header names and identify the separate order signature; flag revocation as a provider check, not a completed step.

    Limitations

    • This article did not create, rotate or revoke a credential or send an authenticated request.

Check the result

  • Name the exact public or private API surface and why a credential is or is not needed.
  • For a private request, identify L1 wallet signing separately from L2 HMAC request headers and signed orders.
  • Before any real credential is created, obtain current provider-owned storage, revocation and eligibility instructions; this guide does not complete those checks.

Limitations

  • No wallet, credential creation, authenticated request or revocation was tested by Polytoolhub.
  • The overview establishes the two signing layers, not account eligibility or a verified rotation procedure.
  • A published API endpoint does not prove service uptime, latency or permission to place orders.

Continue with official documentation

Continue researching

  • Polymarket Data API · context: Read-only positions and activity are a separate data task from authenticated CLOB trading.
  • Polymarket CLOB API · next: Order-book reads and private order management have distinct authentication requirements.