Mainnet runs
production-v0.4.0-2. This page tracks what is live in production, anchored to the production release that shipped each change; verify the running version at any time with GET / on https://api.arcus.xyz. Changes reach testnet first — see the testnet changelog for what is queued ahead of production.production-v0.4.0-2
API changes
- New
GET /v1/fill/{tradeId}: look up the single fill an account owns for a giventradeId. - API keys can be scoped to every subaccount of an address:
POST /v1/createApiKeyandPOST /v1/revokeApiKeyacceptaccountIndex: 255, and key rows onGET /v1/apiKeyscarry anallSubaccountsflag.
Order management
POST /v1/scheduleCancelaccepts an optionalmarketIdto arm a per-market dead man’s switch, independent of the account-wide switch. A wallet may hold a bounded number of armed switches; arming beyond it returns429, and refreshing an armed switch is always allowed.
WebSocket
- Equity and free collateral streamed over WebSocket now net funding that has accrued but not yet settled, matching the values the margin engine uses.
production-v0.4.0-2
Orders and fills
- Partially filled orders that are then canceled now report
avgFillPrice. ACANCELEDorder withfilledSizeabove zero onGET /v1/orderscarriesavgFillPrice, the volume-weighted price of its fills; until now it was omitted. closedPnlon closing fills is now computed from the cost basis the fill releases. OnGET /v1/fills, a fill that reduces or closes a position reports its notional against the cost basis it releases, minus the fee, instead of using a truncated per-unit average entry price. Opening and add legs still report−fee.- Liquidation fills now report
closedPnl. The liquidated account’s leg of a forced closure (liquidation.methodLIQUIDATION) onGET /v1/fillscarries the realized PnL of the close, net of taker trading fees (the liquidation penalty included infeeis not deducted); until now it read"0". Earlier liquidation fills are not backfilled.
production-v0.3.0
WebSocket
- WebSocket connections now receive a
1001(Going Away) close frame before the server drains them on restart, instead of being closed without a close frame.
Liquidations and risk
- Liquidation orders closed on the book carry the limit price the engine computed for the close, or
0when that limit is not a positive price. - Liquidation updates report the full fee charged, including the liquidated account’s taker trading fees, and forced-close order rows (liquidation and ADL) report
avgFillPrice. - Orders, modifies, and fills that would take a position past the engine’s maximum position notional, one fixed bound for all markets (about $922M), are rejected with
POSITION_SIZE_CAP_EXCEEDED. - A triggered TP/SL order keeps its trigger metadata on its terminal cancel, so
GET /v1/order/{orderId}still shows the stop after an IOC partial fill.
production-v0.2.0
Margin
- Per-account isolated margin is now enabled in production. Set a market to isolated mode with the optional
isolatedflag onPOST /v1/setLeverage, move collateral onto or off an isolated position’s leg withPOST /v1/adjustIsolatedMargin, and read the mode frommarginMode/isolatedon position rows,GET /v1/leverages, and theaccountAttributeUpdateschannel. The API surface shipped inproduction-v0.1.10.0and readCROSS/falsefor every account until now; isolated behaviour is active for all accounts as of this update. Testnet has carried the full mechanics sincetestnet-v1.8.0— see the testnet changelog for the detailedmarginUsed, rejection-reason, and streaming semantics.
production-v0.2.0
WebSocket / Order book
- Subaccounts across the account-scoped channels —
account,positions,orders,userFills,funding,accountTransferUpdates, andaccountAttributeUpdates: an optionalaccountIndex(0–9), part of subscription identity and echoed on every frame. Omit it for subaccount 0. - Position and order rows carry a per-account
sequenceNumber(the same counter asAccountUpdate.sequenceNumber); theorderssnapshot carrieslastSequenceId, matchingpositions.
Markets
- 13 new crypto markets enabled and tradeable: DOGE, ENA, PUMP, NEAR, PENGU, FARTCOIN, SUI, WLFI, LINK, BNB, TAO, AAVE, UNI.
production-v0.1.10.0
Breaking changes
from/toonGET /v1/fundingandGET /v1/fundingRatesare epoch microseconds, matching the unit each response reports. Millisecond values are now rejected.
API changes
- New
marketfilter (ticker or numeric id) onGET /v1/prices,GET /v1/mids,GET /v1/positions,GET /v1/leverages, andGET /v1/funding; an unresolvable value returns 400. - New
statusfilter onGET /v1/ordersandGET /v1/openOrders:OPEN,UNTRIGGERED,FILLED,CANCELED,REJECTED,LIQUIDATED,ADL. - New
sidefilter (BUY/SELL) onGET /v1/ordersandGET /v1/fills. Therolefilter onGET /v1/fillsnow matches correctly. netDepositsonGET /v1/accountand theaccountschannel reports real lifetime net deposits.
Order management
- New
POST /v1/scheduleCanceldead man’s switch: arm, refresh, or disarm a per-subaccount deadline; if it elapses the gateway firescancelAllOrdersfor that subaccount. GET /v1/positionsno longer returns 500 when the oracle price read times out.- Position rows and
GET /v1/leveragescarrymarginModeandisolated. When this release shipped both readCROSSandfalsefor every account, as per-account isolated margin was not yet enabled in production; it has since been turned on (see the latest entry above). - Cancel + place: every modify emits CANCELED (cancelReason: MODIFY_CANCELED) then the replacement outcome —PLACED, fills, orREJECTED— under the same orderId. Same-price size decreases keep queue priority. You can expect to see the cancel + place/fill messages on the same GSN but increasing account subsequence numbers for clarity about ordering. Cancels should always arrive first before any fills/place from the newly modified order.
WebSocket / Order book
marketfilter onpositions,orders, anduserFillssubscriptions and on thegetRPCs forfills,orders,positions,leverages,mids, andprices. It is part of subscription identity, sounsubscribemust repeat it.userFillssubscribe acceptsnFills(1–500, default 500) to bound the initial snapshot.isolatedandmarginModeare always present onaccountAttributeUpdatesleverage entries.- A fill could produce a duplicate account snapshot with a repeated
lastSequenceId, and anAccountUpdatecould be applied twice when a snapshot was scheduled.
Markets
- CPER-USD, GME-USD, and QNT-USD are enabled and tradeable, having been listed offline in
production-v0.1.8.
production-v0.1.8
API changes
- New filters on
GET /v1/ordersandGET /v1/fills: amarketparam (ticker or numeric id, case-insensitive).GET /v1/fillsalso gets aroleparam (MAKER/TAKER). The same market filter works onGET /v1/markets. GET /v1/apiKeyswith noaccountIndexnow returns keys for all subaccounts under the address, each tagged with its ownaccountIndex(previously just the default one).
Authentication
- API keys can carry a
withdrawpermission, allowingPOST /v1/withdrawto be authorized with an Ed25519 API-key signature instead of a wallet signature. Keys created through the publicPOST /v1/createApiKeyremain trade-only. POST /v1/createApiKeyandPOST /v1/revokeApiKeyaccept an optional single-usenoncefor replay protection; a replayed nonce returns HTTP 409.
Rate limits
GET /v1/openOrderscosts less against the account rate limit: the per-item charge is now one unit per 50 orders returned, down from one per 20, so a full page costs roughly 2.5× less budget.
WebSocket / Order book
l2Orderbooksubscriptions now support multiple simultaneous aggregation levels per market on one connection. Frames echosigFigs/roundStepso views can be demultiplexed.- Order book snapshots now carry up to 300 price levels (raised cap).
Markets
- MRNA-USD, NBIS-USD, MRVL-USD, BOT-USD, and MSTR-USD enabled. CPER-USD, GME-USD, and QNT-USD listed at 10x leverage, offline.
production-v0.1.7
Market data
- The mark price no longer holds a stale premium when the book is too thin to sample an impact mid. The 2.5-minute impact-mid EWMA previously froze at its last value for as long as depth was missing, then stepped when depth returned; it now decays toward the oracle price during regular trading hours, and toward the sealed RTH settlement price off-hours. Mark price is what margin, unrealized PnL, and liquidations are valued off, so a stale premium moved those too.
Order management
- Fixed a case where a closed position could still read as open. An entry fill and a stop-loss close landing in the same engine tick could be persisted out of order, leaving a flat position showing a size; closing it was then rejected with
REDUCE_ONLY_WOULD_INCREASE. Position rows are now versioned by publish order. - Mark price stability during thin markets — The oracle now falls back to the oracle or settlement price when the orderbook is too thin to sample an impact-mid price, preventing mark price gaps during low-liquidity conditions.
- Increased WebSocket frame buffer — The WebSocket server’s maximum request body size has been increased from 64 KB to 1 MB, reducing connection errors for clients sending larger payloads.
- More reliable position history — Fixed an edge case in position write ordering that could cause duplicate or out-of-order position records under high sequencer throughput.
production-v0.1.6
Breaking changes
from/totime bounds are now epoch microseconds on the endpoints whose timestamps are nanosecond-backed —GET /v1/openOrders,GET /v1/orders,GET /v1/fills,GET /v1/trades, andGET /v1/accountTransferUpdates. Millisecond values are rejected with HTTP 400. Clients that previously sent milliseconds must update.
API changes
GET /v1/openOrdersis now bounded and paginated:limit(1–1000) plusfrom/tooncreatedAt. An account can hold up to 10,000 live orders, so more than one page may be needed.
Authentication
- API keys can be scoped to a non-zero subaccount index.
WebSocket / Order book
userFillsdefault snapshot size increased to 500.
Market data
- Fixed a race that could silently truncate
GET /v1/candlesresponses.
production-v0.1.5
Breaking changes
- Deprecated
*Bpsfee-tier fields removed. UsemakerFeePpm/takerFeePpm(andmaker_fee_ppm/taker_fee_ppm); the values are unchanged.
API changes
GET /v1/marketsexposesminOrderSizeandmaxOrderSizein base-asset units.maxOrderSizeis a per-order gate — reduce-only orders are not exempt.pnlHistoryonGET /v1/portfoliois rebased per timeframe, so each timeframe’s first point is0.
WebSocket / Order book
l2OrderbookacceptssigFigs(2–5) androundStep(1, 2, or 5) to bucket price levels. Bids round down and asks round up, so the displayed spread is never tighter than the true book.- Off-hours trading-band shapes updated;
boundEventis now always present on delta entries, withexitRth/enterRthderived from RTH state. - Fee-tier account attribute updates now fan out to all subaccounts.
production-v0.1.4
API changes
GET /v1/pricesomits OFFLINE markets.GET /v1/marketsadds rolling 24-hourhigh24h/low24hfields.
WebSocket / Order book
- L2 order book now publishes every 200 ms.
Order management
- Fills carry a liquidation/ADL marker, and forced-closure status is consistent between live and persisted views.
production-v0.1.2
production-v0.1.0-quiesce
Breaking changes
- API-key create/revoke signing migrated to EIP-712, with a dual-accept window during which the legacy scheme still works.
API changes
- New
POST /v1/transferfor internal transfers between subaccounts. GET /v1/account/statsis sectioned, with opt-in fixed 24h/7d/30d windows.- Optional
marketfilter onGET /v1/fills.
Authentication
- API keys are scoped to
(address, publicKey), closing a cross-account revocation path. - Replayed withdrawal nonces are rejected at the gateway — a signed withdrawal is single-use.
- API-key subaccount authorization enforced on
modifyOrder.
Order management
- Maximum order size enforced at the gateway.
- Per-market open-interest caps enforced in the engine.
- TPSL handling corrected after trading-band expansion and liquidations.
Market data
- Fee-tier volume window widened from 14 to 30 days.
priceChange24Hcomputed from mark price rather than trade fills.- Candles priced from mark price; no-trade buckets filled from the BBO mid.
- Off-hours trading behavior reworked, including the EWMA anchor-price fallback.
production-v0.0.9-skhy-cc
API changes
GET /v1/candlesserves oracle-priced candles, with oracle OHLC overlaid on no-trade gap buckets.
Authentication
- Ordersign signature verification enforced on REST
cancelOrderand WebSocketbatchCancelOrders.
Order management
reduceOnlyno longer requiresIOCorFOK.
Rate limits
cancelAllOrderscharges zero IP budget.get/postframes exempt from the WebSocket outbound-message rate limit.
production-v0.0.9
API changes
- Exchange write responses return the account’s remaining rate-limit allowance.
- Rate-limit failures return the client id.
Rate limits
- Order-write endpoints cost zero against the IP bucket; the account-pool cost is configurable.
WebSocket / Order book
setLeveragerejections are surfaced on theaccountAttributeschannel.
Market data
- SOFR-carry funding formula for RWA perps, quoted on the ACT/360 divisor.
- Off-hours endpoints always advertise a distinct next trading bound.
Order management
- Off-hours partial-fill takers are rejected when the limit price violates the trading bound.
- A resting order is preserved when a modify is rejected in pre-flight.
production-v0.0.8
Market data
- Historical 1h and 1d candle volume was repaired for
2025-06-01through2026-06-30. Those buckets had kept stale volume because the rollup only re-derived each aggregate forward from its newest stored bucket, so a 1m re-fetch never reached them. Re-pull any 1h/1d candles cached from that window.
production-v0.0.6
API changes
- Unenforced fields removed from the
GET /v1/marketsresponse.
Market data
- Funding formula corrected.
production-v0.0.4
API changes
- Flat $5 minimum order notional enforced.
- Minimum withdrawal size of $1 enforced.
- Trading stat endpoints added.
- Settlement price and trading bounds surfaced on the market endpoint; open interest added.
Authentication
- API keys upsert by name — re-creating with the same
apiWalletNamerevokes the old key. - Wallet block-list enforced across the trade, withdraw, and key paths.
Order management
- Entry TPSL support, including rejecting
entryTpslchildren when the parent entry order is rejected. - Reduce-only margin check corrected.
production-v0.0.0
Initial mainnet release
- First production release of the Arcus API at
https://api.arcus.xyz.
production-v0.0.1 through production-v0.0.5 covered launch-period stabilization with no separately documented public API changes; production-v0.0.7, production-v0.1.1, and production-v0.1.3 shipped no changes an API trader needs to act on.