Available, development access

Authentication

One header, HTTPS only, server side only.

Header formatPermalink to this section

Present the key in an x-api-key header on every request. Keys are not accepted as a query parameter, because query strings end up in proxy logs and browser history.

curl "$RIDDLE_API_BASE/v1/markets/kalshi/$MARKET_ID" \
  -H "x-api-key: $RIDDLE_API_KEY"

RotationPermalink to this section

  1. 1.Ask for a second key while the first is still active.
  2. 2.Deploy the new key to your secret store and let the change roll out.
  3. 3.Confirm your traffic has moved over to the new key.
  4. 4.Retire the old key. Retirement takes effect for new requests; in-flight requests complete.

Practices we expectPermalink to this section

  • Server side only. Do not ship a key to a browser, a mobile binary or a notebook you share.
  • Redact the x-api-key header everywhere you log requests, including error reporters and traces.
  • One key per deployment target, so retiring a compromised key does not take down everything else.
  • Treat a 401 as terminal, not retryable. Retrying an unauthorised request will not make it authorised.

Riddle is a research and information platform. It is not a broker, exchange or trading venue, it does not execute orders, and nothing in this documentation is financial, investment or trading advice. Kalshi, Polymarket and Limitless are named for identification only; Riddle is not affiliated with, endorsed by or sponsored by any of them.