> ## Documentation Index
> Fetch the complete documentation index at: https://docs.services.payward.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create quote

> Creates an account-funded swap quote that locks a price for ~2 minutes.

Account-funded swap quotes must be executed before `expires_at` via `POST /v1/accounts/{account_id}/quotes/{quote_id}/execute`, otherwise they transition to `expired` and are no longer usable.

Exactly one of `from.amount` or `to.amount` must be set; the server calculates the other side. Setting both or neither is rejected with `400 Bad Request`.



## OpenAPI

````yaml /api-reference/openapi_v3_pws.json post /v1/accounts/{account_id}/quotes
openapi: 3.1.0
info:
  title: Payward Services API
  description: >-
    The Payward Services (PWS) public API.


    PWS exposes Swaps (institutional FX-style trading), Conversions (rule-driven
    and one-shot fiat ↔ crypto value movement), retail-style Quotes and Price
    Trigger Swaps, end-user Users / Verifications, Funds (deposits, withdrawals,
    addresses, transactions), Portfolio, Earn, Reports, Webhooks, and Ramp
    (hosted fiat-to-crypto on-ramp checkout).


    All requests must be authenticated. All monetary values are decimal strings;
    all timestamps are ISO 8601 UTC. List endpoints are cursor-paginated. Errors
    follow a uniform shape (see `*ErrorResponse` schemas).
  version: v1
  contact:
    name: Payward Services API Support
    url: https://docs.payward.com
    email: api-support@payward.com
servers:
  - url: https://api.services.payward.com
    description: Production
security:
  - ApiKey: []
    ApiNonce: []
    ApiSign: []
tags:
  - name: Users
    description: >-
      Users and headless-user onboarding flows that the partner manages.


      - **Create User** provisions a user with full identity verification fields
      collected up front.

      - **Create Headless User** provisions a lightweight user when your
      licensing agreement allows you to manage KYC data outside Payward.

      - **Get User** retrieves the user's profile, verification status, and
      required actions.

      - **Update User** updates user profile fields and may re-trigger
      verification.


      Use the returned user `id` for calls that require the user's identifier.
  - name: Assets
    description: >-
      Catalog of assets available on the platform with retail-display metadata
      (logos, market data, descriptions).
  - name: Conversions
    description: >-
      Rule-driven and one-shot fiat ↔ crypto value movement, including
      conversion rules, deposits, and whitelisted wallets.
  - name: Earn
    description: >-
      Manage auto-earn preferences and retrieve allocation and reward
      information.
  - name: Funds
    description: >-
      Deposits, withdrawals, addresses, methods, and the consolidated
      funding-transactions ledger.
  - name: Portfolio
    description: End-user portfolio summary, history, and transaction views.
  - name: Price Trigger Swaps
    description: Limit-style orders that execute when a configured price trigger is met.
  - name: On-chain Swaps
    description: >-
      Wallet-funded onchain quote trading for xStock and USDC pairs. On-chain
      quotes settle on-chain through the Payward on-chain proxy contract.
  - name: Ramp
    description: >-
      Hosted fiat-to-crypto on-ramp checkout: country / fiat / payment-method /
      cryptocurrency-asset discovery, transaction limits and prospective quotes,
      and the hosted checkout URL.
  - name: Reports
    description: Settlement and reconciliation reports for the partner.
  - name: Swaps
    description: >-
      Direct partner-to-Payward swap quotes and executions (institutional
      FX-style trading).
  - name: Verifications
    description: Identity verification (KYC) submission and status for end users.
  - name: Webhooks
    description: Manage webhook subscriptions for asynchronous event delivery.
paths:
  /v1/accounts/{account_id}/quotes:
    post:
      tags:
        - Swaps
      summary: Create quote
      description: >-
        Creates an account-funded swap quote that locks a price for ~2 minutes.


        Account-funded swap quotes must be executed before `expires_at` via
        `POST /v1/accounts/{account_id}/quotes/{quote_id}/execute`, otherwise
        they transition to `expired` and are no longer usable.


        Exactly one of `from.amount` or `to.amount` must be set; the server
        calculates the other side. Setting both or neither is rejected with `400
        Bad Request`.
      operationId: createQuote
      parameters:
        - $ref: '#/components/parameters/AccountIdPath'
      requestBody:
        content:
          application/json:
            schema:
              description: |-
                Request to create a new quote.

                Exactly one of `from.amount` or `to.amount` must be provided to
                indicate which side of the trade is fixed. The server calculates
                the other side. Requests that set both amounts or omit both are
                rejected with a 400 Bad Request.
              type: object
              properties:
                from:
                  description: Source asset and amount for the trade.
                  type: object
                  properties:
                    symbol:
                      description: Asset ticker symbol (e.g. "USD"). Required.
                      type: string
                      minLength: 1
                      maxLength: 10
                    type:
                      description: Classification of the asset. Required.
                      type: string
                      enum:
                        - fiat
                        - crypto
                        - stablecoin
                        - xstock
                    amount:
                      description: >-
                        Amount to spend. Set this to fix the source side of the
                        quote.


                        Exactly one of `from.amount` or `to.amount` must be set.
                        Setting

                        both or neither is rejected with a 400 Bad Request. The
                        cross-field

                        check is enforced by the server; the validator below
                        only enforces

                        the format when the field is set, so `ignore_empty:
                        true` is required.
                      type: string
                      pattern: ^-?[0-9]+(\.[0-9]+)?$
                      maxLength: 32
                to:
                  description: Destination asset and amount for the trade.
                  type: object
                  properties:
                    symbol:
                      description: Asset ticker symbol (e.g. "BTC"). Required.
                      type: string
                      minLength: 1
                      maxLength: 10
                    type:
                      description: Classification of the asset. Required.
                      type: string
                      enum:
                        - fiat
                        - crypto
                        - stablecoin
                        - xstock
                    amount:
                      description: >-
                        Amount to receive. Set this to fix the destination side
                        of the quote.


                        Exactly one of `from.amount` or `to.amount` must be set.
                        Setting

                        both or neither is rejected with a 400 Bad Request. The
                        cross-field

                        check is enforced by the server; the validator below
                        only enforces

                        the format when the field is set, so `ignore_empty:
                        true` is required.
                      type: string
                      pattern: ^-?[0-9]+(\.[0-9]+)?$
                      maxLength: 32
                fee:
                  $ref: '#/components/schemas/PartnerFee'
              required:
                - from
                - to
            examples:
              swap-x-btc-for-usd:
                summary: Swap a fixed amount of BTC for USD
                value:
                  from:
                    symbol: BTC
                    type: crypto
                    amount: '0.5'
                  to:
                    symbol: USD
                    type: fiat
                  fee:
                    bps: 50
              swap-btc-for-x-usd:
                summary: Swap BTC for a fixed amount of USD
                value:
                  from:
                    symbol: BTC
                    type: crypto
                  to:
                    symbol: USD
                    type: fiat
                    amount: '5000'
                  fee:
                    bps: 50
        required: true
      responses:
        '201':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/Quote'
              examples:
                swap-x-btc-for-usd:
                  summary: Swap a fixed amount of BTC for USD
                  value:
                    data:
                      id: Q-BTC2USD-1
                      status: offered
                      expires_at: '2026-04-23T16:00:30Z'
                      from:
                        symbol: BTC
                        name: Bitcoin
                        type: crypto
                        amount: '0.5'
                      to:
                        symbol: USD
                        name: US Dollar
                        type: fiat
                        amount: '31495.50'
                      fees:
                        trade:
                          symbol: USD
                          name: US Dollar
                          type: fiat
                          amount: '150.00'
                      rate:
                        base:
                          symbol: BTC
                          name: Bitcoin
                          type: crypto
                        quote:
                          symbol: USD
                          name: US Dollar
                          type: fiat
                        price: '63291.00'
                swap-btc-for-x-usd:
                  summary: Swap BTC for a fixed amount of USD
                  value:
                    data:
                      id: Q-BTC2USD-2
                      status: offered
                      expires_at: '2026-04-23T16:00:30Z'
                      from:
                        symbol: BTC
                        name: Bitcoin
                        type: crypto
                        amount: '0.07939896'
                      to:
                        symbol: USD
                        name: US Dollar
                        type: fiat
                        amount: '5000.00'
                      fees:
                        trade:
                          symbol: USD
                          name: US Dollar
                          type: fiat
                          amount: '25.00'
                      rate:
                        base:
                          symbol: BTC
                          name: Bitcoin
                          type: crypto
                        quote:
                          symbol: USD
                          name: US Dollar
                          type: fiat
                        price: '63291.00'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationErrorResponse'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthenticatedErrorResponse'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/ForbiddenErrorResponse'
                  - $ref: '#/components/schemas/TradeLockedErrorResponse'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '429':
          description: Rate limit exceeded
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RateLimitErrorResponse'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InternalErrorResponse'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '503':
          description: Service unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceUnavailableErrorResponse'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '504':
          description: Deadline exceeded
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DeadlineExceededErrorResponse'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
      security:
        - ApiKey: []
          ApiNonce: []
          ApiSign: []
      x-codeSamples:
        - lang: bash
          label: curl
          source: >-
            curl -X POST
            "https://api.services.payward.com/v1/accounts/W4BE9868GY65TB6523/quotes"
            \
              -H "API-Key: $PWS_API_KEY" \
              -H "API-Nonce: $PWS_API_NONCE" \
              -H "API-Sign: $PWS_API_SIGN" \
              -H "Content-Type: application/json" \
              -d '{
                "from": {
                  "symbol": "BTC",
                  "type": "crypto",
                  "amount": "0.5"
                },
                "to": {
                  "symbol": "USD",
                  "type": "fiat"
                },
                "fee": {
                  "bps": 50
                }
              }'
components:
  parameters:
    AccountIdPath:
      in: path
      name: account_id
      required: true
      description: >-
        ID of the account the request applies to. This refers to one of the
        accounts held by the user the request is acting on behalf of (typically
        the user's main account, but any of the user's accounts is accepted).
        Routes the request to that specific account container.
      schema:
        $ref: '#/components/schemas/AccountId'
      example: W4BE9868GY65TB6523
  schemas:
    PartnerFee:
      description: >-
        Partner-configured fee applied on top of the underlying execution price.
        Request-only — never returned in response payloads.
      type: object
      properties:
        bps:
          description: Fee in basis points (1 bps = 0.01%).
          type: integer
          minimum: 0
          maximum: 10000
          example: 50
      required:
        - bps
    Quote:
      description: A swap quote.
      type: object
      properties:
        id:
          description: Unique identifier for this quote.
          type: string
        status:
          description: Current lifecycle status of the quote.
          type: string
          enum:
            - offered
            - executing
            - executed
            - expired
            - failed
            - pending
        expires_at:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
        from:
          description: Source asset and amount for the trade.
          allOf:
            - $ref: '#/components/schemas/AssetAmountResponse'
        to:
          description: Destination asset and amount for the trade.
          allOf:
            - $ref: '#/components/schemas/AssetAmountResponse'
        fees:
          $ref: '#/components/schemas/Fees'
        rate:
          $ref: '#/components/schemas/Rate'
    ValidationErrorResponse:
      description: The request was rejected because the client supplied invalid input.
      type: object
      properties:
        error:
          description: Error details.
          type: object
          properties:
            type:
              type: string
            status:
              type: integer
              format: int32
              enum:
                - 400
            instance:
              type: string
            code:
              type: string
              enum:
                - bad_request
            doc_url:
              type: string
              format: uri
            causes:
              type: array
              items:
                $ref: '#/components/schemas/ValidationCause'
          required:
            - type
            - status
            - instance
            - code
      required:
        - error
    UnauthenticatedErrorResponse:
      description: Authentication credentials were missing or invalid.
      type: object
      properties:
        error:
          description: Error details.
          type: object
          properties:
            type:
              type: string
            status:
              type: integer
              format: int32
              enum:
                - 401
            instance:
              type: string
            code:
              type: string
              enum:
                - unauthenticated
            doc_url:
              type: string
              format: uri
            causes:
              type: array
              items:
                type: object
                additionalProperties: true
          required:
            - type
            - status
            - instance
            - code
      required:
        - error
    ForbiddenErrorResponse:
      description: The caller is authenticated but is not allowed to perform this action.
      type: object
      properties:
        error:
          description: Error details.
          type: object
          properties:
            type:
              type: string
            status:
              type: integer
              format: int32
              enum:
                - 403
            instance:
              type: string
            code:
              type: string
              enum:
                - forbidden
            doc_url:
              type: string
              format: uri
            causes:
              type: array
              items:
                type: object
                additionalProperties: true
          required:
            - type
            - status
            - instance
            - code
      required:
        - error
    TradeLockedErrorResponse:
      description: Trading is locked for the user or account, so a quote cannot be created.
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - quote_error
            status:
              type: integer
              format: uint16
              enum:
                - 403
            instance:
              type: string
            code:
              type: string
              enum:
                - trade_locked
            doc_url:
              type:
                - string
                - 'null'
          required:
            - type
            - status
            - instance
            - code
      required:
        - error
    RateLimitErrorResponse:
      description: The request rate limit was exceeded.
      type: object
      properties:
        error:
          description: Error details.
          type: object
          properties:
            type:
              type: string
            status:
              type: integer
              format: int32
              enum:
                - 429
            instance:
              type: string
            code:
              type: string
              enum:
                - resource_exhausted
            doc_url:
              type: string
              format: uri
            causes:
              type: array
              items:
                type: object
                additionalProperties: true
          required:
            - type
            - status
            - instance
            - code
      required:
        - error
    InternalErrorResponse:
      description: An internal server error occurred.
      type: object
      properties:
        error:
          description: Error details.
          type: object
          properties:
            type:
              type: string
            status:
              type: integer
              format: int32
              enum:
                - 500
            instance:
              type: string
            code:
              type: string
              enum:
                - internal
            doc_url:
              type: string
              format: uri
            causes:
              type: array
              items:
                type: object
                additionalProperties: true
          required:
            - type
            - status
            - instance
            - code
      required:
        - error
    ServiceUnavailableErrorResponse:
      description: The service is temporarily unavailable.
      type: object
      properties:
        error:
          description: Error details.
          type: object
          properties:
            type:
              type: string
            status:
              type: integer
              format: int32
              enum:
                - 503
            instance:
              type: string
            code:
              type: string
              enum:
                - unavailable
            doc_url:
              type: string
              format: uri
            causes:
              type: array
              items:
                type: object
                additionalProperties: true
          required:
            - type
            - status
            - instance
            - code
      required:
        - error
    DeadlineExceededErrorResponse:
      description: The upstream request deadline was exceeded.
      type: object
      properties:
        error:
          description: Error details.
          type: object
          properties:
            type:
              type: string
            status:
              type: integer
              format: int32
              enum:
                - 504
            instance:
              type: string
            code:
              type: string
              enum:
                - deadline_exceeded
            doc_url:
              type: string
              format: uri
            causes:
              type: array
              items:
                type: object
                additionalProperties: true
          required:
            - type
            - status
            - instance
            - code
      required:
        - error
    AccountId:
      type: string
      description: Canonical identifier for an account in the Payward public API.
      minLength: 14
      maxLength: 42
    google.protobuf.Timestamp:
      description: RFC 3339 timestamp.
      type: string
      format: date-time
    AssetAmountResponse:
      description: >-
        An asset and an amount denominated in that asset, as returned in
        responses. Includes the human-readable asset `name`.
      type: object
      properties:
        symbol:
          description: Asset ticker symbol (e.g. "BTC", "USD", "TSLAx").
          type: string
        name:
          description: >-
            Human-readable name of the asset (e.g. "Bitcoin" for BTC). Populated
            by the server in responses.
          type:
            - string
            - 'null'
        type:
          description: Classification of the asset.
          type: string
          enum:
            - fiat
            - crypto
            - stablecoin
            - xstock
        amount:
          description: Decimal amount as a string to preserve precision.
          type: string
          format: decimal128
      required:
        - symbol
        - type
    Fees:
      description: Breakdown of all fees charged for a quote.
      type: object
      properties:
        trade:
          $ref: '#/components/schemas/Fee'
    Rate:
      description: Exchange rate applied to a quote.
      type: object
      properties:
        base:
          description: Base asset of the rate pair.
          allOf:
            - $ref: '#/components/schemas/AssetRefResponse'
        quote:
          description: Quote asset of the rate pair.
          allOf:
            - $ref: '#/components/schemas/AssetRefResponse'
        price:
          description: Price of one unit of the base asset denominated in the quote asset.
          type: string
          format: decimal128
      required:
        - base
        - quote
        - price
    ValidationCause:
      description: One failed field-level validation rule.
      type: object
      properties:
        field:
          description: Dot-notation path to the offending request field.
          type: string
        message:
          description: Human-readable explanation of the failed validation rule.
          type: string
      required:
        - field
        - message
    Fee:
      description: A single fee charged against a quote.
      type: object
      properties:
        symbol:
          description: Asset ticker the fee is denominated in (e.g. "USD").
          type: string
        name:
          description: >-
            Human-readable name of the asset (e.g. "Bitcoin" for BTC). Populated
            by the server in responses.
          type:
            - string
            - 'null'
        type:
          description: Classification of the fee asset.
          type: string
          enum:
            - fiat
            - crypto
            - stablecoin
            - xstock
        amount:
          description: Fee amount as a decimal string.
          type: string
          format: decimal128
      required:
        - symbol
        - type
        - amount
    AssetRefResponse:
      description: >-
        Reference to an asset by its ticker symbol and classification, as
        returned in responses. Includes the human-readable asset `name`.
      type: object
      properties:
        symbol:
          description: Asset ticker symbol (e.g. "BTC", "USD", "TSLAx").
          type: string
        name:
          description: >-
            Human-readable name of the asset (e.g. "Bitcoin" for BTC). Populated
            by the server in responses.
          type:
            - string
            - 'null'
        type:
          description: Classification of the asset.
          type: string
          enum:
            - fiat
            - crypto
            - stablecoin
            - equity
            - xstock
      required:
        - symbol
        - type
  headers:
    RequestId:
      description: >-
        Unique identifier for tracing this request across services. Include in
        support tickets.
      schema:
        type: string
        format: uuid
        example: 5f4d2a8e-91a4-4d6c-8a17-9b1e2c3f4a5b
    RateLimitLimit:
      description: Total requests allowed in the current window.
      schema:
        type: integer
        example: 1000
    RateLimitRemaining:
      description: Requests remaining in the current window.
      schema:
        type: integer
        example: 955
    RateLimitReset:
      description: Unix timestamp (seconds) when the rate-limit window resets.
      schema:
        type: integer
        format: int64
        example: 1713182400
    StrictTransportSecurity:
      description: >-
        Enforces HTTPS for the configured period. Always `max-age=63072000;
        includeSubDomains; preload`.
      schema:
        type: string
        example: max-age=63072000; includeSubDomains; preload
    XContentTypeOptions:
      description: Disables MIME sniffing. Always `nosniff`.
      schema:
        type: string
        enum:
          - nosniff
        example: nosniff
    ContentSecurityPolicy:
      description: >-
        Prevents embedding and resource loading. Always `default-src 'none';
        frame-ancestors 'none'`.
      schema:
        type: string
        example: default-src 'none'; frame-ancestors 'none'
    CacheControl:
      description: Prevents caching of sensitive financial data. Always `no-store`.
      schema:
        type: string
        enum:
          - no-store
        example: no-store
    RetryAfter:
      description: Seconds the client should wait before retrying.
      schema:
        type: integer
        example: 30
  securitySchemes:
    ApiKey:
      type: apiKey
      name: API-Key
      in: header
      description: Your public API key. Identifies the partner making the request.
    ApiNonce:
      type: apiKey
      name: API-Nonce
      in: header
      description: Monotonically increasing nonce included in the request signature.
    ApiSign:
      type: apiKey
      name: API-Sign
      in: header
      description: HMAC signature over the request, computed with your private key.

````