> ## Documentation Index
> Fetch the complete documentation index at: https://docs.totalis.trade/llms.txt
> Use this file to discover all available pages before exploring further.

# Create quote

> Create a quote in response to an RFQ.

Requires a key for a maker with `quote:write`.



## OpenAPI

````yaml /hyperliquid/openapi.json post /v1/rfqs/{rfq_id}/quotes
openapi: 3.1.1
info:
  title: Totalis Hyperliquid API
  description: >-
    REST API for Totalis singles and parlays on Hyperliquid HIP-4 outcome
    markets, for client integrations and external market makers.


    Authenticate with a scoped API key created in the Totalis app, sent as
    `Authorization: Bearer <key>`. Public market reads need no key.
    Balance-affecting commands also carry the wallet or maker signature the
    HyperEVM contract verifies.


    Amounts are base-10 strings in native USDC atomic units, large identifiers
    are decimal strings, and every command `POST` requires an `Idempotency-Key`
    header.


    Every error is `{error: {code, message, retry, request_id,
    field_violations}}`. `code` is stable; each operation lists the codes it
    returns per status. `retry` is `NEVER` (stop), `BACKOFF` (resend the same
    request with the same `Idempotency-Key` after `Retry-After` seconds) or
    `REFRESH` (re-read state, then send a new request with a new key).
    `field_violations` names invalid inputs by JSON pointer, such as
    `/legs/0/side`.
  version: 127.0.0-pure-reads
servers:
  - url: https://hip4-api.totalis.trade
    description: Production public edge
  - url: https://hip4-api-staging.totalis.trade
    description: Staging and chain-998 public edge
security: []
tags:
  - name: Markets
    description: HIP-4 markets, their sides and price history. No API key needed.
  - name: RFQs & Quotes
    description: >-
      RFQs and the quotes that answer them: what a taker calls, then what a
      maker calls.
  - name: Positions
    description: Positions the account holds, or its maker backs.
  - name: Account
    description: >-
      The account a key acts for: identity, balances, activity, operations and
      withdrawals.
  - name: Makers
    description: 'The rest of a maker''s setup after Making: capital and collateral.'
  - name: Deployment
    description: The contract deployment every signature is made against.
  - name: WebSocket
    description: The authenticated WebSocket for account and maker updates.
paths:
  /v1/rfqs/{rfq_id}/quotes:
    parameters:
      - $ref: '#/components/parameters/RfqId'
    post:
      tags:
        - RFQs & Quotes
      summary: Create quote
      description: |-
        Create a quote in response to an RFQ.

        Requires a key for a maker with `quote:write`.
      operationId: createQuote
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateQuoteCommand'
            example:
              quote_id: >-
                0x5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e
              entry:
                maker_id: '7'
                legs:
                  - outcome_id: '1209'
                    side: 'YES'
                stake: '25000000'
                payout: '98500000'
                fee_bps: 100
                taker_fee_bps: 20
                taker: '0x1111111111111111111111111111111111111111'
                expiry: '1790452875'
                salt: '48151623429108'
      responses:
        '201':
          description: >-
            The quote is live on the RFQ, or an exact retry returned it. It is
            unsigned and nothing is on chain: the taker receives it as
            `QUOTE_CREATED` and can accept it until `expiry`, and you sign only
            when you confirm that acceptance.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/QuoteCreated'
              example:
                quote_id: >-
                  0x5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e
        '400':
          description: >-
            - `INVALID_REQUEST` (retry `NEVER`): The body, a path parameter or a
            header is malformed or fails validation. `field_violations` names
            invalid body fields.

            - `INVALID_IDEMPOTENCY_KEY` (retry `NEVER`): The command needs
            exactly one lowercase UUIDv7 `Idempotency-Key` header; confirm takes
            none.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '401':
          description: >-
            - `UNAUTHENTICATED` (retry `NEVER`): The credential is missing,
            invalid, expired or revoked.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '403':
          description: >-
            - `FORBIDDEN` (retry `NEVER`): The credential is valid but lacks the
            scope, permission or role this operation needs.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '404':
          description: >-
            - `NOT_FOUND` (retry `NEVER`): The resource does not exist or is not
            visible to this credential.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '409':
          description: >-
            - `IDEMPOTENCY_KEY_REUSED` (retry `NEVER`): The idempotency key was
            already used with different input.

            - `RFQ_NOT_OPEN` (retry `REFRESH`): The RFQ is no longer open.

            - `RFQ_GENERATION_STALE` (retry `REFRESH`): The RFQ generation the
            quote targets was superseded.

            - `RFQ_GENERATION_IN_FLIGHT` (retry `REFRESH`): The RFQ generation
            is changing; re-read the RFQ.

            - `STATE_CONFLICT` (retry `REFRESH`): The resource changed and no
            longer admits this request.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '429':
          description: >-
            - `RATE_LIMITED` (retry `BACKOFF`): The request quota for this
            credential or route is exhausted.

            - `QUOTE_EXPOSURE_LIMIT` (retry `BACKOFF`): The maker's open quote
            exposure is at its limit.
          headers:
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '503':
          description: >-
            - `AUTHORIZATION_UNAVAILABLE` (retry `BACKOFF`): Identity or
            credential authority storage is unavailable.

            - `DEPENDENCY_STALE` (retry `BACKOFF`): A projection or upstream the
            request depends on (chain projection, HyperCore state, database) is
            behind its freshness bound or unavailable.

            - `QUOTE_EXPOSURE_STALE` (retry `BACKOFF`): The maker's exposure
            projection is stale.

            - `COMBO_AUTOMATIC_DISABLED` (retry `BACKOFF`): Automatic combo
            quoting is disabled.

            - `FINANCIAL_ACTIONS_DISABLED` (retry `BACKOFF`): Financial actions
            are disabled for this deployment.
          headers:
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
      security:
        - apiKey:
            - quote:write
components:
  parameters:
    RfqId:
      name: rfq_id
      in: path
      required: true
      schema:
        type: string
        format: uuid
      description: The RFQ's `rfq_id`, from Create RFQ or `RFQ_CREATED`.
      example: 01994f3a-6c2e-7d41-9b8a-2f3c4d5e6f70
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      schema:
        type: string
        format: uuid
        pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
      description: >-
        Lowercase UUIDv7 naming this command, unique per caller and route. A
        retry with the same key and body returns the original result; the same
        key with a different body returns `409 IDEMPOTENCY_KEY_REUSED`.
      example: 0198a6f6-82a5-7abc-9f2a-4f0fb437493e
  schemas:
    CreateQuoteCommand:
      oneOf:
        - type: object
          additionalProperties: false
          required:
            - quote_id
            - entry
          properties:
            quote_id:
              $ref: '#/components/schemas/Bytes32'
              description: >-
                EIP-712 digest of `entry`, as the `Quote` struct. It must match
                the terms exactly. You sign it when you confirm an acceptance,
                and it becomes the `position_id` of the position the trade
                opens.
            entry:
              $ref: '#/components/schemas/QuoteTerms'
              description: >-
                Entry terms. `stake`, `taker` and `legs` must match the RFQ,
                `maker_id` must be your maker, and `expiry` is Unix seconds, at
                most 30 seconds ahead.
          title: Entry
        - type: object
          additionalProperties: false
          required:
            - quote_id
            - sell_back
          properties:
            quote_id:
              $ref: '#/components/schemas/Bytes32'
              description: >-
                EIP-712 digest of `sell_back`, as the `SellBack` struct. It must
                match the terms exactly; you and the owner both sign it.
            sell_back:
              $ref: '#/components/schemas/SellBackTerms'
              description: >-
                Sell-back terms, only from the maker that backs the position:
                your maker vault pays the owner `price` and the position closes.
                `position_id`, `owner` and `leg_state` must match the RFQ, and
                `expiry` is 25 to 60 seconds ahead.
          title: Sell back
        - type: object
          additionalProperties: false
          required:
            - quote_id
            - transfer
          properties:
            quote_id:
              $ref: '#/components/schemas/Bytes32'
              description: >-
                EIP-712 digest of `transfer`, as the `CashoutTransfer` struct.
                It must match the terms exactly; you (the buyer) and the owner
                (the seller) both sign it.
            transfer:
              $ref: '#/components/schemas/TransferTerms'
              description: >-
                Transfer terms, from any maker other than the one that backs the
                position: `buyer`, your quote signer, pays `seller` the `price`
                and takes the position. `position_id`, `seller` and `leg_state`
                must match the RFQ, and `expiry` is 25 to 60 seconds ahead.
          title: Transfer
      description: >-
        Your quote on the RFQ: `quote_id` plus exactly one set of terms. Send
        `entry` for an entry RFQ, and `sell_back` or `transfer` for a cash-out
        RFQ. It replaces your live quote on the RFQ.
    QuoteCreated:
      type: object
      additionalProperties: false
      required:
        - quote_id
      properties:
        quote_id:
          $ref: '#/components/schemas/Bytes32'
          description: 'ID of the created quote: the digest of its terms.'
      description: The created quote's ID.
    Error:
      additionalProperties: false
      properties:
        error:
          $ref: '#/components/schemas/ErrorDetail'
          description: The one error this request failed with.
      required:
        - error
      type: object
    Bytes32:
      type: string
      pattern: ^0x[0-9a-f]{64}$
    QuoteTerms:
      type: object
      additionalProperties: false
      required:
        - maker_id
        - legs
        - stake
        - payout
        - fee_bps
        - taker_fee_bps
        - taker
        - expiry
        - salt
      properties:
        maker_id:
          $ref: '#/components/schemas/NonZeroUInt64String'
          description: On-chain maker ID of the quoting maker.
        legs:
          type: array
          minItems: 1
          maxItems: 50
          items:
            $ref: '#/components/schemas/CommonLeg'
          description: >-
            Legs the quote covers; must equal the RFQ legs in order. The signed
            Leg encodes outcome_id as uint32 and side as uint8, 0 for YES and 1
            for NO.
        stake:
          $ref: '#/components/schemas/CommonAmount'
          description: Taker stake in atomic USDC (6 decimals), before taker fees.
        payout:
          $ref: '#/components/schemas/CommonAmount'
          description: >-
            Gross amount the position pays if every leg wins, in atomic USDC (6
            decimals), before the profit fee.
        fee_bps:
          type: integer
          minimum: 0
          maximum: 10000
          description: >-
            Profit fee in basis points, charged at claim on the winning profit
            (payout minus net stake).
        taker_fee_bps:
          type: integer
          minimum: 0
          maximum: 10000
          description: >-
            Entry fee in basis points taken from the stake at accept: net stake
            is stake minus floor(stake * taker_fee_bps / 10000).
        taker:
          type: string
          pattern: ^0x[0-9a-fA-F]{40}$
          description: Wallet that must sign the accept and will own the position.
        expiry:
          $ref: '#/components/schemas/UInt64String'
          description: Unix seconds after which the quote can no longer be accepted.
        salt:
          $ref: '#/components/schemas/Uint256'
          description: >-
            Random uint256, as a decimal string, that makes each signed quote
            unique.
      description: >-
        Entry terms a maker quotes; they mirror the signed Quote and TakerAccept
        structs field for field.
    SellBackTerms:
      type: object
      additionalProperties: false
      required:
        - position_id
        - price
        - owner
        - expiry
        - salt
        - leg_state
      properties:
        position_id:
          $ref: '#/components/schemas/Hash32'
          description: Position the quote is for; the signed SellBack names it ticketId.
        price:
          $ref: '#/components/schemas/CommonAmount'
          description: >-
            Buyback price the original maker pays the owner to close the ticket,
            in atomic USDC (6 decimals).
        owner:
          $ref: '#/components/schemas/LowercaseNonZeroAddress'
          description: Current position owner, who sells the ticket back.
        expiry:
          $ref: '#/components/schemas/UInt64String'
          description: Unix seconds after which the quote can no longer be executed.
        salt:
          $ref: '#/components/schemas/Uint256'
          description: >-
            Random uint256, as a decimal string, that makes each signed quote
            unique.
        leg_state:
          $ref: '#/components/schemas/Hash32'
          description: >-
            Position leg state the quote was priced against; must equal the
            RFQ's leg_state.
      description: >-
        Sell-back terms: the underwriting maker buys the position back and it
        closes. They mirror the signed SellBack struct.
    TransferTerms:
      type: object
      additionalProperties: false
      required:
        - position_id
        - price
        - seller
        - buyer
        - expiry
        - salt
        - leg_state
      properties:
        position_id:
          $ref: '#/components/schemas/Hash32'
          description: >-
            Position the quote is for; the signed CashoutTransfer names it
            ticketId.
        price:
          $ref: '#/components/schemas/CommonAmount'
          description: >-
            Price the buyer pays the seller for the whole position, in atomic
            USDC (6 decimals).
        seller:
          $ref: '#/components/schemas/LowercaseNonZeroAddress'
          description: Current position owner, who sells the ticket.
        buyer:
          $ref: '#/components/schemas/LowercaseNonZeroAddress'
          description: >-
            The bidding maker's current quote signer, which becomes the owner
            and pays from its own vault balance.
        expiry:
          $ref: '#/components/schemas/UInt64String'
          description: Unix seconds after which the quote can no longer be executed.
        salt:
          $ref: '#/components/schemas/Uint256'
          description: >-
            Random uint256, as a decimal string, that makes each signed quote
            unique.
        leg_state:
          $ref: '#/components/schemas/Hash32'
          description: >-
            Position leg state the quote was priced against; must equal the
            RFQ's leg_state.
      description: >-
        Transfer terms: another maker buys the position and becomes its owner.
        They mirror the signed CashoutTransfer struct.
    ErrorDetail:
      additionalProperties: false
      properties:
        code:
          $ref: '#/components/schemas/ErrorCode'
          description: Stable registered code; branch on this, not on message or status.
        field_violations:
          description: >-
            Each invalid input by JSON pointer; empty when the error is not
            about a specific input.
          items:
            $ref: '#/components/schemas/FieldViolation'
          type: array
        message:
          description: Human-readable; may change without notice.
          minLength: 1
          type: string
        request_id:
          description: >-
            UUIDv7 of this request, also returned in the X-Request-ID header.
            Quote it when reporting a problem.
          format: uuid
          pattern: >-
            ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
          type: string
        retry:
          $ref: '#/components/schemas/Retry'
          description: What the caller should do next; fixed by the registry for each code.
      required:
        - code
        - message
        - retry
        - request_id
        - field_violations
      type: object
    NonZeroUInt64String:
      allOf:
        - $ref: '#/components/schemas/UInt64String'
      description: Never `0`.
    CommonLeg:
      type: object
      additionalProperties: false
      required:
        - outcome_id
        - side
      properties:
        outcome_id:
          $ref: '#/components/schemas/UInt32String'
          description: >-
            HIP-4 outcome ID the leg is on, as a decimal string. The signed Leg
            encodes it as uint32.
        side:
          $ref: '#/components/schemas/Side'
          description: >-
            Outcome side the leg backs. The signed Leg encodes YES as 0 and NO
            as 1.
      description: One (outcome, side) pair, as markets and positions name it.
    CommonAmount:
      type: string
      pattern: ^(0|[1-9][0-9]*)$
      maxLength: 39
      format: uint128-decimal
    UInt64String:
      type: string
      pattern: >-
        ^(0|[1-9][0-9]{0,18}|1[0-7][0-9]{18}|18[0-3][0-9]{17}|184[0-3][0-9]{16}|1844[0-5][0-9]{15}|18446[0-6][0-9]{14}|184467[0-3][0-9]{13}|1844674[0-3][0-9]{12}|184467440[0-6][0-9]{10}|1844674407[0-2][0-9]{9}|18446744073[0-6][0-9]{8}|1844674407370[0-8][0-9]{6}|18446744073709[0-4][0-9]{5}|184467440737095[0-4][0-9]{4}|18446744073709550[0-9]{3}|18446744073709551[0-5][0-9]{2}|1844674407370955160[0-9]|1844674407370955161[0-5])$
      maxLength: 20
      format: uint64-decimal
    Uint256:
      type: string
      pattern: ^(0|[1-9][0-9]{0,77})$
    Hash32:
      type: string
      pattern: ^0x[0-9a-f]{64}$
    LowercaseNonZeroAddress:
      type: string
      pattern: ^0x[0-9a-f]{40}$
      description: Never `0x0000000000000000000000000000000000000000`.
    ErrorCode:
      description: >-
        Stable HTTP error code. Each code has one HTTP status and one retry
        value.
      enum:
        - INVALID_REQUEST
        - INVALID_QUERY
        - INVALID_CURSOR
        - INVALID_IDEMPOTENCY_KEY
        - ORIGIN_REQUIRED
        - SUBPROTOCOL_REQUIRED
        - UNSUPPORTED_BROWSE_CONTRACT
        - UNAUTHENTICATED
        - FORBIDDEN
        - ORIGIN_NOT_ALLOWED
        - ACCESS_REQUIRED
        - NOT_FOUND
        - IDENTITY_NOT_FOUND
        - QUOTE_NOT_FOUND
        - INVITE_CODE_NOT_FOUND
        - IDEMPOTENCY_KEY_REUSED
        - STATE_CONFLICT
        - INVITE_CODE_EXHAUSTED
        - STALE_CURSOR
        - CURSOR_EXPIRED
        - CURSOR_RESET
        - RECURRING_DEFINITION_CONFLICT
        - EMBEDDED_WALLET_CONFLICT
        - SECRET_UNAVAILABLE
        - ROTATION_IN_PROGRESS
        - TELEMETRY_CONFLICT
        - RFQ_NOT_CANCELLABLE
        - RFQ_NOT_OPEN
        - RFQ_GENERATION_STALE
        - RFQ_GENERATION_IN_FLIGHT
        - QUOTE_EXPIRED
        - QUOTE_CANCELLED
        - QUOTE_REPLACED
        - QUOTE_SIGNER_CHANGED
        - QUOTE_CAPACITY_EXCEEDED
        - CORE_ACCOUNT_NOT_READY
        - CORE_EXIT_ABANDONED
        - CORE_FUNDING_CONFLICT
        - CORE_VAULT_RESERVATION
        - CORE_MOVE_IN_FLIGHT
        - INVALID_SIGNATURE
        - WRONG_AUTHORITY
        - KEY_LIMIT_REACHED
        - HYPERCORE_WALLET_UNQUALIFIED
        - HYPERCORE_ACCOUNT_NOT_MAIN
        - HYPERCORE_INSUFFICIENT_BALANCE
        - RATE_LIMITED
        - CONNECTION_LIMIT
        - RFQ_INTENT_LIMIT
        - QUOTE_EXPOSURE_LIMIT
        - DEPENDENCY_STALE
        - AUTHORIZATION_UNAVAILABLE
        - SOURCE_UNAVAILABLE
        - CONTRACT_UNAVAILABLE
        - MARKET_DATA_UNAVAILABLE
        - BROWSE_UNAVAILABLE
        - FINANCIAL_ACTIONS_DISABLED
        - CORE_FUNDING_UNAVAILABLE
        - CORE_EXIT_UNAVAILABLE
        - SPONSORSHIP_UNAVAILABLE
        - CONTRACT_SIGNATURE_OVERLOADED
        - QUOTE_EXPOSURE_STALE
        - COMBO_AUTOMATIC_DISABLED
        - EMBEDDED_WALLET_UNAVAILABLE
        - CONNECTION_DRAIN
      type: string
    FieldViolation:
      additionalProperties: false
      properties:
        code:
          description: >-
            REQUIRED: the input is missing. INVALID: it is present but malformed
            or out of range. UNEXPECTED: the input is not accepted here.
          enum:
            - REQUIRED
            - INVALID
            - UNEXPECTED
          type: string
        field:
          description: >-
            JSON pointer into the body, or into the query parameters as one flat
            object for requests without a body, for example /legs/0/stake or
            /limit.
          pattern: ^(/([^~/]|~[01])*)+$
          type: string
      required:
        - field
        - code
      type: object
    Retry:
      description: >-
        NEVER: stop. BACKOFF: resend the same request with the same
        Idempotency-Key after Retry-After. REFRESH: re-read state, then send a
        new request with a new Idempotency-Key.
      enum:
        - NEVER
        - BACKOFF
        - REFRESH
      type: string
    UInt32String:
      type: string
      pattern: >-
        ^(0|[1-9][0-9]{0,8}|[1-3][0-9]{9}|4[01][0-9]{8}|42[0-8][0-9]{7}|429[0-3][0-9]{6}|4294[0-8][0-9]{5}|42949[0-5][0-9]{4}|429496[0-6][0-9]{3}|4294967[0-1][0-9]{2}|42949672[0-8][0-9]|429496729[0-5])$
      maxLength: 10
    Side:
      type: string
      enum:
        - 'YES'
        - 'NO'
  headers:
    RetryAfter:
      description: Seconds to wait before resending the same request
      schema:
        type: integer
        minimum: 1
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >-
        Scoped API key from the Totalis app settings. Each key acts for one
        account, yours or a maker's, and holds only scopes that account can use.
        Each operation lists the scopes it requires.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.