HTTP API

The HTTP listener uses server.metrics_addr, default 127.0.0.1:9091. It provides no native TLS. Protect it with a private network or authenticated proxy.

MethodPathAuthenticationResult
GET/healthnone200 OK or 503 when unavailable/draining
GET/readynoneSame availability check as health
GET/metricsnonePrometheus text exposition
GET/admin/statusnoneService status and per-symbol trading state
POST/admin/halt/{symbol_id}X-Admin-KeyDurable halt
POST/admin/resume/{symbol_id}X-Admin-KeyDurable resume

Halt/resume routes are not registered when server.admin.api_key is empty; requests then return 404. With a configured key, missing/incorrect credentials return 401. Keys require at least 16 printable, non-space ASCII characters. /admin/status remains public even when a key is configured.

curl --fail http://127.0.0.1:9091/ready
curl --fail http://127.0.0.1:9091/admin/status
curl --fail -X POST -H "X-Admin-Key: $ME_ADMIN_KEY" http://127.0.0.1:9091/admin/halt/0

/health and /ready return plain text: OK on success, or draining / engine unavailable with HTTP 503. They do not return JSON.

GET /admin/status example when the service is ready:

{"status":"ready","symbols":[{"symbol_id":0,"trading_enabled":true}]}

Unavailable/draining /admin/status returns HTTP 503 with {"status":"unavailable"} or {"status":"draining"}. Health also checks trading listeners, session storage and shard workers. A deliberately halted symbol remains operationally healthy.

Halt/resume responses contain symbol_id, action and success. Success returns 200; an unknown symbol returns 404, and a failed engine operation returns 503. Existing orders remain in the book when a symbol is halted.

For order commands and events, use the binary protocol.