Header
Authorization may send x-arena-key: arena_sk_… instead. HTTPS only.
Scopes
GET /me, GET /usage and GET /organizations accept any valid key. GET /status needs none.
Organization sandbox
GET /portfolio, GET /portfolio/trades, POST /portfolio/orders and DELETE /portfolio/orders/{orderId} take an optional header:
portfolio:read or trade:write). GET /portfolio returns that sandbox’s cash, positions and resting orders, and organization.slug. GET /portfolio/trades returns that sandbox’s trades, not the personal trade list, and organization.slug when the sandbox named one. Neither read returns the personal account. Order routes include organization (id, and slug when set). Without the header, the call uses the key owner’s personal paper account and organization is absent. GET /account is the personal account.
GET /organizations lists the organizations this personal key belongs to. Any valid key, no particular scope. Each id is the value X-Arena-Org takes. The list ignores X-Arena-Org. A 2xx body has mode paper. GET takes no query parameters; every other method answers 405 method_not_allowed.
The header does not select a Combine evaluation account. Paper only.
Sessions
Key management uses a person’s session instead of a key: the website’s cookie, or a signed-in CLI’s session token as the bearer. There is no guest or anonymous access.The playground in the API reference sends requests through Mintlify’s proxy. Use a key you can revoke, with only the scopes you need.