> ## Documentation Index
> Fetch the complete documentation index at: https://docs.totalis.trade/llms.txt
> Use this file to discover all available pages before exploring further.

# Open stream

> Open the WebSocket that streams your account's or your maker's updates.

Requires one of:

- a key for your account with `account:stream`
- a key for a maker with `rfq:read`
- a key for a maker with `vault:read` and the maker permissions `READ_ACTIVITY`, `READ_CAPITAL`, `READ_PERFORMANCE`, `READ_POSITIONS`
- a key for a maker with `quote:read`
- a key for your account with `rfq:read`

Also requires `replay:read` to resume from a cursor or replay retained events.

Each key receives only the frames its scopes allow, and other frame classes are denied:

| Frames | Key | Needs |
| --- | --- | --- |
| Open RFQ discovery | key for your account | `rfq:read` |
| Account | key for your account | `account:stream` |
| RFQ | key for a maker | `rfq:read` |
| Quote | key for a maker | `quote:read` |
| Account | key for a maker | `vault:read` and the maker permissions `READ_CAPITAL`, `READ_POSITIONS`, `READ_ACTIVITY`, `READ_PERFORMANCE` |



## OpenAPI

````yaml /hyperliquid/openapi.json get /v1/stream
openapi: 3.1.1
info:
  title: Totalis Hyperliquid API
  description: >-
    REST API for Totalis singles and parlays on Hyperliquid HIP-4 outcome
    markets, for client integrations and external market makers.


    Authenticate with a scoped API key created in the Totalis app, sent as
    `Authorization: Bearer <key>`. Public market reads need no key.
    Balance-affecting commands also carry the wallet or maker signature the
    HyperEVM contract verifies.


    Amounts are base-10 strings in native USDC atomic units, large identifiers
    are decimal strings, and every command `POST` requires an `Idempotency-Key`
    header.


    Every error is `{error: {code, message, retry, request_id,
    field_violations}}`. `code` is stable; each operation lists the codes it
    returns per status. `retry` is `NEVER` (stop), `BACKOFF` (resend the same
    request with the same `Idempotency-Key` after `Retry-After` seconds) or
    `REFRESH` (re-read state, then send a new request with a new key).
    `field_violations` names invalid inputs by JSON pointer, such as
    `/legs/0/side`.
  version: 127.0.0-pure-reads
servers:
  - url: https://hip4-api.totalis.trade
    description: Production public edge
  - url: https://hip4-api-staging.totalis.trade
    description: Staging and chain-998 public edge
security: []
tags:
  - name: Markets
    description: HIP-4 markets, their sides and price history. No API key needed.
  - name: RFQs & Quotes
    description: >-
      RFQs and the quotes that answer them: what a taker calls, then what a
      maker calls.
  - name: Positions
    description: Positions the account holds, or its maker backs.
  - name: Account
    description: >-
      The account a key acts for: identity, balances, activity, operations and
      withdrawals.
  - name: Makers
    description: 'The rest of a maker''s setup after Making: capital and collateral.'
  - name: Deployment
    description: The contract deployment every signature is made against.
  - name: WebSocket
    description: The authenticated WebSocket for account and maker updates.
paths:
  /v1/stream:
    get:
      tags:
        - WebSocket
      summary: Open stream
      description: >-
        Open the WebSocket that streams your account's or your maker's updates.


        Requires one of:


        - a key for your account with `account:stream`

        - a key for a maker with `rfq:read`

        - a key for a maker with `vault:read` and the maker permissions
        `READ_ACTIVITY`, `READ_CAPITAL`, `READ_PERFORMANCE`, `READ_POSITIONS`

        - a key for a maker with `quote:read`

        - a key for your account with `rfq:read`


        Also requires `replay:read` to resume from a cursor or replay retained
        events.


        Each key receives only the frames its scopes allow, and other frame
        classes are denied:


        | Frames | Key | Needs |

        | --- | --- | --- |

        | Open RFQ discovery | key for your account | `rfq:read` |

        | Account | key for your account | `account:stream` |

        | RFQ | key for a maker | `rfq:read` |

        | Quote | key for a maker | `quote:read` |

        | Account | key for a maker | `vault:read` and the maker permissions
        `READ_CAPITAL`, `READ_POSITIONS`, `READ_ACTIVITY`, `READ_PERFORMANCE` |
      operationId: stream
      responses:
        '101':
          description: >-
            Switching protocols. Send the key as `Authorization: Bearer`;
            browsers request the `totalis.realtime.v2` subprotocol plus
            `auth.<base64url-access-token>` instead. Then send one `subscribe`
            frame: `account` with a key for your account, or `maker` with a key
            for a maker and its `maker_id`. The stream answers with a
            `subscriptionResponse`, then a snapshot or a replay from your
            cursor, then live events, every frame tagged by `channel`. The
            server closes the connection when your maker's membership or
            controller changes; reconnect to continue.
        '400':
          description: >-
            - `SUBPROTOCOL_REQUIRED` (retry `NEVER`): The stream request did not
            negotiate a supported subprotocol or extension.

            - `INVALID_REQUEST` (retry `NEVER`): The body, a path parameter or a
            header is malformed or fails validation. `field_violations` names
            invalid body fields.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '401':
          description: >-
            - `UNAUTHENTICATED` (retry `NEVER`): The credential is missing,
            invalid, expired or revoked.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '403':
          description: >-
            - `FORBIDDEN` (retry `NEVER`): The credential is valid but lacks the
            scope, permission or role this operation needs.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '404':
          description: >-
            - `NOT_FOUND` (retry `NEVER`): The resource does not exist or is not
            visible to this credential.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '429':
          description: >-
            - `RATE_LIMITED` (retry `BACKOFF`): The request quota for this
            credential or route is exhausted.

            - `CONNECTION_LIMIT` (retry `BACKOFF`): The stream connection limit
            is reached.
          headers:
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
        '503':
          description: >-
            - `AUTHORIZATION_UNAVAILABLE` (retry `BACKOFF`): Identity or
            credential authority storage is unavailable.

            - `DEPENDENCY_STALE` (retry `BACKOFF`): A projection or upstream the
            request depends on (chain projection, HyperCore state, database) is
            behind its freshness bound or unavailable.

            - `CONNECTION_DRAIN` (retry `BACKOFF`): The stream replica is
            draining; reconnect and resume from the last applied cursor.
          headers:
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
      security:
        - apiKey:
            - account:stream
        - apiKey:
            - rfq:read
        - apiKey:
            - vault:read
        - apiKey:
            - quote:read
components:
  schemas:
    Error:
      additionalProperties: false
      properties:
        error:
          $ref: '#/components/schemas/ErrorDetail'
          description: The one error this request failed with.
      required:
        - error
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        code:
          $ref: '#/components/schemas/ErrorCode'
          description: Stable registered code; branch on this, not on message or status.
        field_violations:
          description: >-
            Each invalid input by JSON pointer; empty when the error is not
            about a specific input.
          items:
            $ref: '#/components/schemas/FieldViolation'
          type: array
        message:
          description: Human-readable; may change without notice.
          minLength: 1
          type: string
        request_id:
          description: >-
            UUIDv7 of this request, also returned in the X-Request-ID header.
            Quote it when reporting a problem.
          format: uuid
          pattern: >-
            ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
          type: string
        retry:
          $ref: '#/components/schemas/Retry'
          description: What the caller should do next; fixed by the registry for each code.
      required:
        - code
        - message
        - retry
        - request_id
        - field_violations
      type: object
    ErrorCode:
      description: >-
        Stable HTTP error code. Each code has one HTTP status and one retry
        value.
      enum:
        - INVALID_REQUEST
        - INVALID_QUERY
        - INVALID_CURSOR
        - INVALID_IDEMPOTENCY_KEY
        - ORIGIN_REQUIRED
        - SUBPROTOCOL_REQUIRED
        - UNSUPPORTED_BROWSE_CONTRACT
        - UNAUTHENTICATED
        - FORBIDDEN
        - ORIGIN_NOT_ALLOWED
        - ACCESS_REQUIRED
        - NOT_FOUND
        - IDENTITY_NOT_FOUND
        - QUOTE_NOT_FOUND
        - INVITE_CODE_NOT_FOUND
        - IDEMPOTENCY_KEY_REUSED
        - STATE_CONFLICT
        - INVITE_CODE_EXHAUSTED
        - STALE_CURSOR
        - CURSOR_EXPIRED
        - CURSOR_RESET
        - RECURRING_DEFINITION_CONFLICT
        - EMBEDDED_WALLET_CONFLICT
        - SECRET_UNAVAILABLE
        - ROTATION_IN_PROGRESS
        - TELEMETRY_CONFLICT
        - RFQ_NOT_CANCELLABLE
        - RFQ_NOT_OPEN
        - RFQ_GENERATION_STALE
        - RFQ_GENERATION_IN_FLIGHT
        - QUOTE_EXPIRED
        - QUOTE_CANCELLED
        - QUOTE_REPLACED
        - QUOTE_SIGNER_CHANGED
        - QUOTE_CAPACITY_EXCEEDED
        - CORE_ACCOUNT_NOT_READY
        - CORE_EXIT_ABANDONED
        - CORE_FUNDING_CONFLICT
        - CORE_VAULT_RESERVATION
        - CORE_MOVE_IN_FLIGHT
        - INVALID_SIGNATURE
        - WRONG_AUTHORITY
        - KEY_LIMIT_REACHED
        - HYPERCORE_WALLET_UNQUALIFIED
        - HYPERCORE_ACCOUNT_NOT_MAIN
        - HYPERCORE_INSUFFICIENT_BALANCE
        - RATE_LIMITED
        - CONNECTION_LIMIT
        - RFQ_INTENT_LIMIT
        - QUOTE_EXPOSURE_LIMIT
        - DEPENDENCY_STALE
        - AUTHORIZATION_UNAVAILABLE
        - SOURCE_UNAVAILABLE
        - CONTRACT_UNAVAILABLE
        - MARKET_DATA_UNAVAILABLE
        - BROWSE_UNAVAILABLE
        - FINANCIAL_ACTIONS_DISABLED
        - CORE_FUNDING_UNAVAILABLE
        - CORE_EXIT_UNAVAILABLE
        - SPONSORSHIP_UNAVAILABLE
        - CONTRACT_SIGNATURE_OVERLOADED
        - QUOTE_EXPOSURE_STALE
        - COMBO_AUTOMATIC_DISABLED
        - EMBEDDED_WALLET_UNAVAILABLE
        - CONNECTION_DRAIN
      type: string
    FieldViolation:
      additionalProperties: false
      properties:
        code:
          description: >-
            REQUIRED: the input is missing. INVALID: it is present but malformed
            or out of range. UNEXPECTED: the input is not accepted here.
          enum:
            - REQUIRED
            - INVALID
            - UNEXPECTED
          type: string
        field:
          description: >-
            JSON pointer into the body, or into the query parameters as one flat
            object for requests without a body, for example /legs/0/stake or
            /limit.
          pattern: ^(/([^~/]|~[01])*)+$
          type: string
      required:
        - field
        - code
      type: object
    Retry:
      description: >-
        NEVER: stop. BACKOFF: resend the same request with the same
        Idempotency-Key after Retry-After. REFRESH: re-read state, then send a
        new request with a new Idempotency-Key.
      enum:
        - NEVER
        - BACKOFF
        - REFRESH
      type: string
  headers:
    RetryAfter:
      description: Seconds to wait before resending the same request
      schema:
        type: integer
        minimum: 1
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >-
        Scoped API key from the Totalis app settings. Each key acts for one
        account, yours or a maker's, and holds only scopes that account can use.
        Each operation lists the scopes it requires.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.