arena command is paper trading from a terminal. Node.js 20 or newer. One login covers the CLI, the MCP server and the website.
arena login opens a browser. Google is the default. arena login --provider apple uses Apple. There is no guest sign-in.
npx arena-prediction-cli@0.6.0 login runs the same binary without adding arena to PATH. An agent should use the global install, because prompts and hooks call arena.
A machine with no browser
Sign in on a machine that has a browser, into a file:chmod 600), and set ARENA_CREDENTIALS_FILE to that path. One host per file: a refresh replaces the stored token, so two hosts sharing it sign each other out.
Signed out
These work beforearena login:
Store
ins_ ids. Tickers change per game.
API keys
arena keys ships in 0.6.0. It uses your login, not a key. See API keys.
Route
--venue chooses where a paper ticket is priced. Pass an instrument id, not a venue ticker.
The CLI prints each leg: size, price, and venue. On the HTTP order result the same split is
fills (see Conventions). fillVenue is the first leg.
Live orders
Live submission is off until Arena turns it on. You can save credentials in Settings before that. A saved key does not send an order. Arena’s switchesARENA_KALSHI_LIVE_TRADE and ARENA_POLY_INTL_LIVE_TRADE stay off by default.
--live is Kalshi. --poly-intl is Polymarket International. Passing both is refused. Neither flag is on unless you set it.
Arena lists Polymarket International. It does not list Polymarket US.
A visitor in the US, or in PR, GU, VI, AS, MP, or UM, cannot trade Polymarket International. Arena reads CF-IPCountry and refuses the order with us_not_eligible. Settings hides the form when this account is ineligible.
Polymarket International credentials are your API key, secret, passphrase, signer address, and signer private key. Arena stores them envelope-encrypted. The secret, passphrase, and signer private key are not shown again. The website calls GET, PUT, and DELETE /api/account/poly-intl-trading with your session. That path is not under /api/v1. Signed out, it answers 401 unauthorized.
Kalshi uses the same pattern at /api/account/kalshi-trading: a key id and a private key, stored envelope-encrypted.
execution on POST /portfolio/orders is paper unless you send kalshi or poly-intl.