Recommended Free Tools
Polymarket CLOB authentication has two distinct stages: a wallet signs an EIP-712 message to create or derive API credentials (L1), then those credentials authenticate private API requests with an HMAC-SHA256 signature (L2). Neither stage replaces signing an order payload when you create an order.
How Polymarket CLOB authentication works
The distinction is what each signature proves. L1 uses your wallet to establish control and obtain CLOB API credentials. L2 uses those credentials to authenticate private requests. An order-creation operation has a further requirement: the user must sign the order payload.
| Layer | What it authenticates | Signing method or material |
|---|---|---|
| L1 | Wallet control and credential setup | EIP-712 ClobAuth message signed by the wallet |
| L2 | Private CLOB API request | HMAC-SHA256 signature made with the API secret; API key and passphrase are also sent |
| Order signature | The order payload | User signature required for order creation, separate from L2 request authentication |
This guide concerns Polymarket’s Central Limit Order Book (CLOB) API. It does not establish behavior for every Polymarket API, wallet setup, or client-library version.
Set up API credentials with L1 wallet authentication
For L1, your wallet signs an EIP-712 message in the ClobAuthDomain. Polymarket’s example domain has version 1 and includes the chain ID; its example uses Polygon chain ID 137. The example ClobAuth typed data includes the signing address, a timestamp string, a uint256 nonce, and a message. Its message field reads: “This message attests that I control the given wallet.” See Polymarket’s authentication guide for the documented typed-data structure and current requirements.
#1 Best Overall
For direct REST authentication, the documented L1 headers are:
POLY_ADDRESS: the signer address.POLY_SIGNATURE: the CLOB EIP-712 signature.POLY_TIMESTAMP: a Unix timestamp.POLY_NONCE: a nonce, defaulting to0in the guide.
Polymarket documents two credential routes. Use the create route when generating credentials, or the derive route to derive them:
Rank #2
| Purpose | Method and route |
|---|---|
| Create API credentials | POST {clob-endpoint}/auth/api-key |
| Derive API credentials | GET {clob-endpoint}/auth/derive-api-key |
Both routes are documented with L1 authentication. The resulting credential set contains an API key, a secret, and a passphrase. Keep all three available for L2 authentication; the secret is used to generate the request signature, while the API key and passphrase are sent in headers. The routes and header requirements are listed in the official CLOB authentication documentation.
Authenticate private requests with L2
L2 uses the credentials obtained through L1 to authenticate private CLOB operations, such as posting, viewing, or cancelling orders and retrieving trades. The API secret is used to create an HMAC-SHA256 signature for the request. The API key and passphrase are included as headers, along with the signer address and timestamp.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
The documented L2 headers are:
POLY_ADDRESSPOLY_SIGNATUREPOLY_TIMESTAMPPOLY_API_KEYPOLY_PASSPHRASE
For the precise signature construction and request details, follow the current Polymarket authentication guide. An HMAC signature authenticates the API request using the credential secret; it is not the wallet’s EIP-712 signature and does not itself authorize the contents of an order.
Order signing is separate from request authentication
When a request creates a user order, L2 headers alone are not enough: the user must also sign the order payload. Think of the flow as two separate checks on a private order-creation operation: L2 authenticates the request to the API, while the order signature is required for the order itself. Polymarket’s CLOB authentication guide explicitly distinguishes the order-signing requirement.
Rank #4
- API Security in Action
- Manning Publications
- ABIS BOOK
Choose a client library or direct REST
Polymarket recommends using its Python or TypeScript CLOB clients for signing and authentication. Direct REST requests are also documented for developers who want to construct the headers and signing logic themselves. The available sources do not establish that either approach is faster, safer, or more reliable; those qualities should not be assumed.
| Approach | What it means | Considerations |
|---|---|---|
| Python or TypeScript CLOB client | Use Polymarket’s client for authentication and signing | Less signing code for you to maintain; check the chosen client version and its current documentation. |
| Direct REST | Build requests and authentication handling yourself | Gives you control over request construction, while leaving you responsible for keeping the implementation aligned with current API requirements. |
These are implementation trade-offs, not comparative test results. The official CLOB clients documentation is the starting point for the supported client options.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
Protect the wallet key and API credentials
Your wallet private key is used for L1 signing and must remain secret. Polymarket’s developer documentation warns, “Never commit private keys to version control,” and recommends environment variables or secure key-management systems. Do not put real private keys, API secrets, or passphrases in source code, logs, screenshots, or repository snippets. See the authentication guide for Polymarket’s security guidance.
The cited guidance does not establish that a particular hardware wallet or key-storage device is required or compatible with unattended API signing. Select key handling appropriate to your application, and verify the requirements of your chosen client and wallet configuration.
Check the implementation against current documentation
Before relying on an integration, confirm the current authentication guide and the version of the Python or TypeScript client you use. The documented flow here covers CLOB request authentication and order signing; it does not guarantee identical behavior across all API surfaces, accounts, wallets, or client releases.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →




