Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk4 min

How to Authenticate and Sign Polymarket API Requests

Polymarket CLOB authentication separates wallet-based credential setup (L1), HMAC-SHA256 private-request authentication (L2), and order-payload signing.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Polymarket CLOB authentication has two distinct stages: a wallet signs an EIP-712 message to create or derive API credentials (L1), then those credentials authenticate private API requests with an HMAC-SHA256 signature (L2). Neither stage replaces signing an order payload when you create an order.

How Polymarket CLOB authentication works

The distinction is what each signature proves. L1 uses your wallet to establish control and obtain CLOB API credentials. L2 uses those credentials to authenticate private requests. An order-creation operation has a further requirement: the user must sign the order payload.

Layer What it authenticates Signing method or material
L1 Wallet control and credential setup EIP-712 ClobAuth message signed by the wallet
L2 Private CLOB API request HMAC-SHA256 signature made with the API secret; API key and passphrase are also sent
Order signature The order payload User signature required for order creation, separate from L2 request authentication

This guide concerns Polymarket’s Central Limit Order Book (CLOB) API. It does not establish behavior for every Polymarket API, wallet setup, or client-library version.

Set up API credentials with L1 wallet authentication

For L1, your wallet signs an EIP-712 message in the ClobAuthDomain. Polymarket’s example domain has version 1 and includes the chain ID; its example uses Polygon chain ID 137. The example ClobAuth typed data includes the signing address, a timestamp string, a uint256 nonce, and a message. Its message field reads: “This message attests that I control the given wallet.” See Polymarket’s authentication guide for the documented typed-data structure and current requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For direct REST authentication, the documented L1 headers are:

  • POLY_ADDRESS: the signer address.
  • POLY_SIGNATURE: the CLOB EIP-712 signature.
  • POLY_TIMESTAMP: a Unix timestamp.
  • POLY_NONCE: a nonce, defaulting to 0 in the guide.

Polymarket documents two credential routes. Use the create route when generating credentials, or the derive route to derive them:

Purpose Method and route
Create API credentials POST {clob-endpoint}/auth/api-key
Derive API credentials GET {clob-endpoint}/auth/derive-api-key

Both routes are documented with L1 authentication. The resulting credential set contains an API key, a secret, and a passphrase. Keep all three available for L2 authentication; the secret is used to generate the request signature, while the API key and passphrase are sent in headers. The routes and header requirements are listed in the official CLOB authentication documentation.

Authenticate private requests with L2

L2 uses the credentials obtained through L1 to authenticate private CLOB operations, such as posting, viewing, or cancelling orders and retrieving trades. The API secret is used to create an HMAC-SHA256 signature for the request. The API key and passphrase are included as headers, along with the signer address and timestamp.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The documented L2 headers are:

  • POLY_ADDRESS
  • POLY_SIGNATURE
  • POLY_TIMESTAMP
  • POLY_API_KEY
  • POLY_PASSPHRASE

For the precise signature construction and request details, follow the current Polymarket authentication guide. An HMAC signature authenticates the API request using the credential secret; it is not the wallet’s EIP-712 signature and does not itself authorize the contents of an order.

Order signing is separate from request authentication

When a request creates a user order, L2 headers alone are not enough: the user must also sign the order payload. Think of the flow as two separate checks on a private order-creation operation: L2 authenticates the request to the API, while the order signature is required for the order itself. Polymarket’s CLOB authentication guide explicitly distinguishes the order-signing requirement.

Rank #4
API Security in Action
  • API Security in Action
  • Manning Publications
  • ABIS BOOK
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose a client library or direct REST

Polymarket recommends using its Python or TypeScript CLOB clients for signing and authentication. Direct REST requests are also documented for developers who want to construct the headers and signing logic themselves. The available sources do not establish that either approach is faster, safer, or more reliable; those qualities should not be assumed.

Approach What it means Considerations
Python or TypeScript CLOB client Use Polymarket’s client for authentication and signing Less signing code for you to maintain; check the chosen client version and its current documentation.
Direct REST Build requests and authentication handling yourself Gives you control over request construction, while leaving you responsible for keeping the implementation aligned with current API requirements.

These are implementation trade-offs, not comparative test results. The official CLOB clients documentation is the starting point for the supported client options.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect the wallet key and API credentials

Your wallet private key is used for L1 signing and must remain secret. Polymarket’s developer documentation warns, “Never commit private keys to version control,” and recommends environment variables or secure key-management systems. Do not put real private keys, API secrets, or passphrases in source code, logs, screenshots, or repository snippets. See the authentication guide for Polymarket’s security guidance.

The cited guidance does not establish that a particular hardware wallet or key-storage device is required or compatible with unattended API signing. Select key handling appropriate to your application, and verify the requirements of your chosen client and wallet configuration.

Check the implementation against current documentation

Before relying on an integration, confirm the current authentication guide and the version of the Python or TypeScript client you use. The documented flow here covers CLOB request authentication and order signing; it does not guarantee identical behavior across all API surfaces, accounts, wallets, or client releases.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.