# curl examples — run one request at a time

Server-to-server only. Set baseUrl, clientId, clientSecret and externalUserId=exemplo in your shell (tenantId is optional: one contract per partner). Never paste secrets into browser JS. Secrets in shell environment remain sensitive; use a secret manager. No real provider in safe smoke; skip POSITIONS until authorized.

## AUTH

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/tenants" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

## CLIENT CREATE

```bash
curl --fail-with-body -sS -X POST "${baseUrl}/v1/users" --user "$clientId:$clientSecret" -H 'Content-Type: application/json' -H "Idempotency-Key: $requestKey" --data '{"externalUserId":"{{externalUserId}}"}'
```

## CLIENT GET

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/users/${externalUserId}" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

## RISK PREVIEW

```bash
curl --fail-with-body -sS -X POST "${baseUrl}/v1/users/${externalUserId}/setup/preview" --user "$clientId:$clientSecret" -H 'Content-Type: application/json' -H "Idempotency-Key: $requestKey" --data '{"providerId":"BINANCE","mode":"REAL","enabled":false,"leverage":2,"orderSizeUsd":10,"maxConcurrentTrades":1,"maxMarginPerTradeUsd":10,"maxDailyLossUsd":5,"capitalBase":100,"maxLossPerTrade":2,"entryTimeoutMinutes":30}'
```

## RISK UPDATE

```bash
curl --fail-with-body -sS -X PUT "${baseUrl}/v1/users/${externalUserId}/risk" --user "$clientId:$clientSecret" -H 'Content-Type: application/json' -H "Idempotency-Key: $requestKey" --data '{"providerId":"BINANCE","maxConcurrentTrades":1,"maxMarginPerTradeUsd":10,"maxDailyLossUsd":5}'
```

## STRATEGY

```bash
curl --fail-with-body -sS -X PUT "${baseUrl}/v1/users/${externalUserId}/strategies" --user "$clientId:$clientSecret" -H 'Content-Type: application/json' -H "Idempotency-Key: $requestKey" --data '{"strategyIds":["FUTURES_MAIN_V1"]}'
```

## PROVIDERS

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/users/${externalUserId}/providers" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

## CONNECT SESSION

```bash
curl --fail-with-body -sS -X POST "${baseUrl}/v1/users/${externalUserId}/connect-sessions" --user "$clientId:$clientSecret" -H 'Content-Type: application/json' -H "Idempotency-Key: $requestKey" --data '{"providerId":"BINANCE"}'
```

## CONNECT STATUS

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/users/${externalUserId}/connect-sessions/${sessionId}" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

## AUTOMATION OFF

```bash
curl --fail-with-body -sS -X PUT "${baseUrl}/v1/users/${externalUserId}/automation" --user "$clientId:$clientSecret" -H 'Content-Type: application/json' -H "Idempotency-Key: $requestKey" --data '{"providerId":"BINANCE","strategyId":"FUTURES_MAIN_V1","enabled":false,"risk":{"leverage":2,"maxMarginPerTradeUsd":10,"maxConcurrentTrades":1,"maxDailyLossUsd":5}}'
```

## AUTOMATION GET

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/users/${externalUserId}/automation" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

## PERFORMANCE

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/users/${externalUserId}/performance" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

## BILLING

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/users/${externalUserId}/billing" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

## OBLIGATIONS

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/users/${externalUserId}/obligations" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

## EVENTS

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/events" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

## POSITIONS - PROVIDER READ, NOT IN SAFE SMOKE

```bash
curl --fail-with-body -sS -X GET "${baseUrl}/v1/users/${externalUserId}/positions?providerId=BINANCE" --user "$clientId:$clientSecret" -H 'Content-Type: application/json'
```

In CLIENT CREATE replace the {{externalUserId}} marker in JSON with your synthetic externalUserId. For CONNECT STATUS set sessionId from the previous response. connectUrl contains a bearer token: hand it to the end user, never log/share as proof. Choose a unique requestKey per operation and keep it for retries.
