Execute API

Authentication

Authenticate with an API key from your servers, or a client ID from your web pages.

Base URL

Every route lives under https://api.execute.cash/v1. Requests and responses are JSON.

Credentials

Creating an address takes one of your account’s two credentials, both from the dashboard. Looking an address up, getting its status and listing chains take none.

CredentialHeaderSend it from
API keyAuthorization: Bearer exe_sk_…Your servers. It’s secret.
Client IDX-Client-Id: exe_client_…Your web pages. It’s publishable.

Send exactly one of them per request.

API keys

An API key is exe_sk_ and 64 hex characters, sent as a bearer token. It works from servers only: a request that carries it and an Origin header came from a browser, and is refused with 403 api_key_in_browser. A key that has been in a browser should be rotated.

Shell
curl https://api.execute.cash/v1/address/create \
  -H "Authorization: Bearer $EXECUTE_API_KEY" \
  -H "Content-Type: application/json" \
  -d @intent.json

The dashboard shows a key once, when it’s created or rotated, and keeps only its first characters. Rotating replaces it at once: the old key stops working immediately.

Client IDs

A client ID is exe_client_ and 32 hex characters, sent in the X-Client-Id header. It works only from the origins your account allows. Browsers state the origin themselves, in the Origin header, and scripts can’t change it, so a client ID copied from your page doesn’t work from anyone else’s.

TypeScript
const res = await fetch("https://api.execute.cash/v1/address/create", {
  method: "POST",
  headers: { "X-Client-Id": "exe_client_…", "Content-Type": "application/json" },
  body: JSON.stringify(intent),
});

Add allowed origins in the dashboard, as they appear in the browser’s address bar, without a path:

  • https://app.example.com allows exactly that origin.
  • https://*.example.com allows every subdomain of example.com, but not example.com itself.
  • http works for local development only: http://localhost:3000, http://127.0.0.1:5173.

An account allows up to 20 origins.

Rate limits

CredentialSustainedBurst
API key50 requests a second100
Client ID10 requests a second20

Over a limit, requests are refused with 429 rate_limited. The public routes are answered with CORS *, so pages can call them directly.

Errors

StatusCodeWhen
401unauthorizedNo credential, or one Execute doesn’t know.
403api_key_in_browserAn API key sent from a browser (the request has an Origin header).
403origin_requiredA client ID sent without an Origin header, i.e. not from a browser.
403origin_not_allowedA client ID sent from an origin the account doesn’t allow.
400invalid_requestBoth credentials in one request.
429rate_limitedOver the credential’s rate limit.

How errors are shaped is in Errors.