> ## Documentation Index
> Fetch the complete documentation index at: https://docs.totalis.trade/llms.txt
> Use this file to discover all available pages before exploring further.

# Confirm quote

> Confirm or decline an acceptance of your quote.

Requires a key for a maker with `quote:write`.



## OpenAPI

````yaml /hyperliquid/openapi.json post /v1/quotes/{quote_id}/confirm
openapi: 3.1.1
info:
  title: Totalis Hyperliquid API
  description: >-
    REST API for Totalis singles and parlays on Hyperliquid HIP-4 outcome
    markets, for client integrations and external market makers.


    Authenticate with a scoped API key created in the Totalis app, sent as
    `Authorization: Bearer <key>`. Public market reads need no key.
    Balance-affecting commands also carry the wallet or maker signature the
    HyperEVM contract verifies.


    Amounts are base-10 strings in native USDC atomic units, large identifiers
    are decimal strings, and every command `POST` requires an `Idempotency-Key`
    header.


    Every error is `{error: {code, message, retry, request_id,
    field_violations}}`. `code` is stable; each operation lists the codes it
    returns per status. `retry` is `NEVER` (stop), `BACKOFF` (resend the same
    request with the same `Idempotency-Key` after `Retry-After` seconds) or
    `REFRESH` (re-read state, then send a new request with a new key).
    `field_violations` names invalid inputs by JSON pointer, such as
    `/legs/0/side`.
  version: 127.0.0-pure-reads
servers:
  - url: https://hip4-api.totalis.trade
    description: Production public edge
  - url: https://hip4-api-staging.totalis.trade
    description: Staging and chain-998 public edge
security: []
tags:
  - name: Markets
    description: HIP-4 markets, their sides and price history. No API key needed.
  - name: RFQs & Quotes
    description: >-
      RFQs and the quotes that answer them: what a taker calls, then what a
      maker calls.
  - name: Positions
    description: Positions the account holds, or its maker backs.
  - name: Account
    description: >-
      The account a key acts for: identity, balances, activity, operations and
      withdrawals.
  - name: Makers
    description: 'The rest of a maker''s setup after Making: capital and collateral.'
  - name: Deployment
    description: The contract deployment every signature is made against.
  - name: WebSocket
    description: The authenticated WebSocket for account and maker updates.
paths:
  /v1/quotes/{quote_id}/confirm:
    parameters:
      - $ref: '#/components/parameters/QuoteId'
    post:
      tags:
        - RFQs & Quotes
      summary: Confirm quote
      description: |-
        Confirm or decline an acceptance of your quote.

        Requires a key for a maker with `quote:write`.
      operationId: confirmQuote
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConfirmQuoteCommand'
            example:
              decision: CONFIRM
              maker_signature: >-
                0xcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcd1c
      responses:
        '200':
          description: >-
            The acceptance after your answer. `ACCEPTED` means the trade is
            queued, not yet on chain, and carries its `operation_id`.
            `PENDING_FUNDING` means the taker pays from HyperCore: the
            acceptance becomes `ACCEPTED`, or `CANCELLED` if the payment fails.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConfirmQuoteResult'
              example:
                quote_id: >-
                  0x5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e
                rfq_id: 01a0df4e-5e07-7a3c-8f21-d4e6b7a90c1a
                status: ACCEPTED
                deadline: '2026-09-26T20:00:53.352Z'
                operation_id: >-
                  0x9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a9a
        '400':
          description: >-
            - `INVALID_REQUEST` (retry `NEVER`): The body, a path parameter or a
            header is malformed or fails validation. `field_violations` names
            invalid body fields.

            - `INVALID_IDEMPOTENCY_KEY` (retry `NEVER`): The command needs
            exactly one lowercase UUIDv7 `Idempotency-Key` header; confirm takes
            none.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '401':
          description: >-
            - `UNAUTHENTICATED` (retry `NEVER`): The credential is missing,
            invalid, expired or revoked.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '403':
          description: >-
            - `FORBIDDEN` (retry `NEVER`): The credential is valid but lacks the
            scope, permission or role this operation needs.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '404':
          description: >-
            - `NOT_FOUND` (retry `NEVER`): The resource does not exist or is not
            visible to this credential.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '409':
          description: >-
            Resending the same answer replays the result; a different answer to
            the same acceptance returns `IDEMPOTENCY_KEY_REUSED`. An answer
            after the acceptance's `deadline` cannot reopen it.


            - `IDEMPOTENCY_KEY_REUSED` (retry `NEVER`): The idempotency key was
            already used with different input.

            - `STATE_CONFLICT` (retry `REFRESH`): The resource changed and no
            longer admits this request.

            - `QUOTE_EXPIRED` (retry `REFRESH`): The quote expired.

            - `QUOTE_SIGNER_CHANGED` (retry `REFRESH`): The maker's quote signer
            changed after the quote was signed.

            - `QUOTE_CAPACITY_EXCEEDED` (retry `REFRESH`): The maker's current
            capacity does not cover the quote.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '422':
          description: >-
            - `INVALID_SIGNATURE` (retry `NEVER`): The signature does not verify
            for the signed terms.

            - `WRONG_AUTHORITY` (retry `REFRESH`): The signature is not from the
            current authority: the taker wallet for an accept, or the maker's
            current quote signer for a confirm.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '429':
          description: >-
            - `RATE_LIMITED` (retry `BACKOFF`): The request quota for this
            credential or route is exhausted.
          headers:
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '503':
          description: >-
            - `AUTHORIZATION_UNAVAILABLE` (retry `BACKOFF`): Identity or
            credential authority storage is unavailable.

            - `DEPENDENCY_STALE` (retry `BACKOFF`): A projection or upstream the
            request depends on (chain projection, HyperCore state, database) is
            behind its freshness bound or unavailable.

            - `FINANCIAL_ACTIONS_DISABLED` (retry `BACKOFF`): Financial actions
            are disabled for this deployment.
          headers:
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
      security:
        - apiKey:
            - quote:write
components:
  parameters:
    QuoteId:
      name: quote_id
      in: path
      required: true
      schema:
        $ref: '#/components/schemas/Bytes32'
      description: >-
        The quote's `quote_id`, from `QUOTE_CREATED`, `QUOTE_ACCEPTED` or Create
        quote.
      example: '0x2b7c9d1e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c'
  schemas:
    ConfirmQuoteCommand:
      oneOf:
        - type: object
          additionalProperties: false
          required:
            - decision
            - maker_signature
          properties:
            decision:
              const: CONFIRM
              description: Confirm and sign the accepted terms; the trade executes.
            maker_signature:
              $ref: '#/components/schemas/ContractSignature'
              description: >-
                Your quote signer's EIP-712 signature over the accepted terms:
                `entry` as `Quote`, `sell_back` as `SellBack`, `transfer` as
                `CashoutTransfer`. Your capital stays reserved for as long as
                this signature can execute.
          title: Confirm
        - type: object
          additionalProperties: false
          required:
            - decision
          properties:
            decision:
              const: DECLINE
              description: >-
                Decline the accepted terms. Nothing executes and the quote
                leaves the RFQ.
          title: Decline
      description: >-
        Your answer to the acceptance, before its `deadline`, two seconds after
        the accept: `CONFIRM` with your signature, or `DECLINE`. Send no
        `Idempotency-Key`: the quote identifies its one acceptance.
    ConfirmQuoteResult:
      allOf:
        - $ref: '#/components/schemas/AcceptanceFields'
      unevaluatedProperties: false
      type: object
      description: >-
        The acceptance after your answer. It never includes the taker's
        `acceptance_id`.
    Error:
      additionalProperties: false
      properties:
        error:
          $ref: '#/components/schemas/ErrorDetail'
          description: The one error this request failed with.
      required:
        - error
      type: object
    Bytes32:
      type: string
      pattern: ^0x[0-9a-f]{64}$
    ContractSignature:
      type: string
      pattern: ^0x(?:[0-9a-f]{2}){1,4096}$
    AcceptanceFields:
      required:
        - quote_id
        - rfq_id
        - status
        - deadline
      properties:
        acceptance_id:
          $ref: '#/components/schemas/Uuid'
          description: >-
            The `Idempotency-Key` the taker sent with the accept, which names
            this acceptance. Never sent to the maker.
        quote_id:
          $ref: '#/components/schemas/Bytes32'
          description: The accepted quote. A quote has at most one acceptance.
        rfq_id:
          $ref: '#/components/schemas/Uuid'
          description: RFQ the quote answers.
        status:
          enum:
            - PENDING_CONFIRM
            - PENDING_FUNDING
            - ACCEPTED
            - FILLED
            - FAILED
            - DECLINED
            - TIMED_OUT
            - CANCELLED
          description: >-
            `PENDING_CONFIRM`: waiting for the maker. `PENDING_FUNDING`: the
            maker confirmed an entry whose HyperCore payment is still pending.
            `ACCEPTED`: the maker confirmed and the trade is queued as
            `operation_id`. `FILLED`: the trade committed on chain. `FAILED`: it
            reverted or expired unexecuted. `DECLINED`: the maker declined.
            `TIMED_OUT`: the maker did not answer by `deadline`. `CANCELLED`:
            the quote or RFQ went away first, or the HyperCore payment failed.
        deadline:
          $ref: '#/components/schemas/CommonTimestamp'
          description: >-
            When the maker's time to confirm ends, two seconds after the accept,
            as an RFC3339 UTC timestamp.
        operation_id:
          $ref: '#/components/schemas/Bytes32'
          description: >-
            The on-chain operation that executes the trade; present once status
            is `ACCEPTED`, `FILLED` or `FAILED`.
    ErrorDetail:
      additionalProperties: false
      properties:
        code:
          $ref: '#/components/schemas/ErrorCode'
          description: Stable registered code; branch on this, not on message or status.
        field_violations:
          description: >-
            Each invalid input by JSON pointer; empty when the error is not
            about a specific input.
          items:
            $ref: '#/components/schemas/FieldViolation'
          type: array
        message:
          description: Human-readable; may change without notice.
          minLength: 1
          type: string
        request_id:
          description: >-
            UUIDv7 of this request, also returned in the X-Request-ID header.
            Quote it when reporting a problem.
          format: uuid
          pattern: >-
            ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
          type: string
        retry:
          $ref: '#/components/schemas/Retry'
          description: What the caller should do next; fixed by the registry for each code.
      required:
        - code
        - message
        - retry
        - request_id
        - field_violations
      type: object
    Uuid:
      type: string
      format: uuid
      pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
    CommonTimestamp:
      type: string
      format: date-time
      pattern: ^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$
      maxLength: 30
    ErrorCode:
      description: >-
        Stable HTTP error code. Each code has one HTTP status and one retry
        value.
      enum:
        - INVALID_REQUEST
        - INVALID_QUERY
        - INVALID_CURSOR
        - INVALID_IDEMPOTENCY_KEY
        - ORIGIN_REQUIRED
        - SUBPROTOCOL_REQUIRED
        - UNSUPPORTED_BROWSE_CONTRACT
        - UNAUTHENTICATED
        - FORBIDDEN
        - ORIGIN_NOT_ALLOWED
        - ACCESS_REQUIRED
        - NOT_FOUND
        - IDENTITY_NOT_FOUND
        - QUOTE_NOT_FOUND
        - INVITE_CODE_NOT_FOUND
        - IDEMPOTENCY_KEY_REUSED
        - STATE_CONFLICT
        - INVITE_CODE_EXHAUSTED
        - STALE_CURSOR
        - CURSOR_EXPIRED
        - CURSOR_RESET
        - RECURRING_DEFINITION_CONFLICT
        - EMBEDDED_WALLET_CONFLICT
        - SECRET_UNAVAILABLE
        - ROTATION_IN_PROGRESS
        - TELEMETRY_CONFLICT
        - RFQ_NOT_CANCELLABLE
        - RFQ_NOT_OPEN
        - RFQ_GENERATION_STALE
        - RFQ_GENERATION_IN_FLIGHT
        - QUOTE_EXPIRED
        - QUOTE_CANCELLED
        - QUOTE_REPLACED
        - QUOTE_SIGNER_CHANGED
        - QUOTE_CAPACITY_EXCEEDED
        - CORE_ACCOUNT_NOT_READY
        - CORE_EXIT_ABANDONED
        - CORE_FUNDING_CONFLICT
        - CORE_VAULT_RESERVATION
        - CORE_MOVE_IN_FLIGHT
        - INVALID_SIGNATURE
        - WRONG_AUTHORITY
        - KEY_LIMIT_REACHED
        - HYPERCORE_WALLET_UNQUALIFIED
        - HYPERCORE_ACCOUNT_NOT_MAIN
        - HYPERCORE_INSUFFICIENT_BALANCE
        - RATE_LIMITED
        - CONNECTION_LIMIT
        - RFQ_INTENT_LIMIT
        - QUOTE_EXPOSURE_LIMIT
        - DEPENDENCY_STALE
        - AUTHORIZATION_UNAVAILABLE
        - SOURCE_UNAVAILABLE
        - CONTRACT_UNAVAILABLE
        - MARKET_DATA_UNAVAILABLE
        - BROWSE_UNAVAILABLE
        - FINANCIAL_ACTIONS_DISABLED
        - CORE_FUNDING_UNAVAILABLE
        - CORE_EXIT_UNAVAILABLE
        - SPONSORSHIP_UNAVAILABLE
        - CONTRACT_SIGNATURE_OVERLOADED
        - QUOTE_EXPOSURE_STALE
        - COMBO_AUTOMATIC_DISABLED
        - EMBEDDED_WALLET_UNAVAILABLE
        - CONNECTION_DRAIN
      type: string
    FieldViolation:
      additionalProperties: false
      properties:
        code:
          description: >-
            REQUIRED: the input is missing. INVALID: it is present but malformed
            or out of range. UNEXPECTED: the input is not accepted here.
          enum:
            - REQUIRED
            - INVALID
            - UNEXPECTED
          type: string
        field:
          description: >-
            JSON pointer into the body, or into the query parameters as one flat
            object for requests without a body, for example /legs/0/stake or
            /limit.
          pattern: ^(/([^~/]|~[01])*)+$
          type: string
      required:
        - field
        - code
      type: object
    Retry:
      description: >-
        NEVER: stop. BACKOFF: resend the same request with the same
        Idempotency-Key after Retry-After. REFRESH: re-read state, then send a
        new request with a new Idempotency-Key.
      enum:
        - NEVER
        - BACKOFF
        - REFRESH
      type: string
  headers:
    RetryAfter:
      description: Seconds to wait before resending the same request
      schema:
        type: integer
        minimum: 1
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >-
        Scoped API key from the Totalis app settings. Each key acts for one
        account, yours or a maker's, and holds only scopes that account can use.
        Each operation lists the scopes it requires.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.