> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aura.markets/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke a developer key. Repeated revocation is a safe no-op.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/developer/keys/{id}/revoke
openapi: 3.1.0
info:
  title: Aura API
  description: >-
    Public REST API for Aura, prediction markets on Alephium.


    This API exposes the app read model: markets, live instant order books,

    orders, fills, vault state, oracle and governance. Non-trading

    build-tx endpoints return unsigned transactions for the client to

    sign with its own wallet.


    Interactive reference: https://docs.aura.markets/api-reference/introduction


    ## Discovery


    Built for integrators, not for lazy implementers:


    - **Faceted lists.** Every list endpoint accepts `?facets=true`
      and returns category, tag, and status counts in the same response,
      so a UI can render filter chips without a second request.
    - **Cursor pagination.** Stable across inserts and fast at depth.
      Offset paging via `?page=` is still supported for compat.
    - **Rich filters.** `?q=`, `?category=`, `?tags=`, `?status=`,
      `?creator=`, and `?minVolume=` on `/v1/markets`. Tag matching is
      AND, so all listed tags must be present.
    - **Sortable.** `?sort=created-at|volume|best-bid-yes|recently-traded`
      with `?order=asc|desc`. Use `/v1/trending` for the composite-score sort.
    - **Field projection.** `?fields=id,question,bestBidYes` trims the
      wire weight for thin clients.
    - **Unified search.** `/v1/search?q=` matches strictly first, then
      falls back to typo-tolerant matching when nothing hits. The result
      type is a discriminated union, so adding events or users later is
      non-breaking.
    - **Transparent trending.** `/v1/trending` returns the full algorithm
      and per-market component scores so the ranking is auditable.
    - **Categories and tags as first-class.** `/v1/categories` and
      `/v1/tags` enumerate the taxonomy with market counts.

    ## Authentication


    Aura uses wallet-bound account sessions delivered as an HttpOnly

    cookie. Sign in by signing a one-time challenge with your wallet:


    ```

    POST /v1/auth/challenge   { "address": "..." }

    POST /v1/auth/session     { "address": "...", "publicKey": "...",
    "signature": "...", "keyType": "gl-secp256k1" }

    ```


    The `session` call sets the `aura_session` cookie and returns a CSRF

    token; send it back in the `x-csrf-token` header on every mutating

    request. Every token is checked against durable revocation state.

    `POST /v1/auth/logout` revokes the presented cookie or bearer session;

    cookie callers include the same CSRF header.


    Reads are accessible anonymously with low IP-based rate limits;

    write endpoints (`/v1/tx/*`, social writes) require a valid session.


    ## Rate limits


    | Tier      | Reads (req/min) | Writes (req/min) |

    |-----------|----------------:|-----------------:|

    | Anonymous | 60 per IP | 10 per IP |

    | Signed-in | 600 per wallet | 60 per wallet |


    Standard `RateLimit-*` response headers are returned on every

    request (IETF `draft-ietf-httpapi-ratelimit-headers`).


    ## Write endpoints


    Aura never returns raw keys, signing grants, or transaction/intent

    signatures. Embedded-wallet keys are usable only inside the measured

    enclave. Endpoints under `/v1/tx/*` return an *unsigned* transaction

    for an independently controlled wallet to sign and submit.


    Builder trading endpoints require two independent credentials: a scoped

    developer key identifies and rate-limits the integration, while a

    user-created restricted trading authorization permits only its bounded

    place/cancel policy. Aura signs and submits inside custody; the builder

    receives a receipt, never a reusable signature.


    A typical on-chain lifecycle flow:


    1. `POST /v1/tx/vault/{address}/deposit` → server returns
       `{ unsignedTx, gasEstimate, ... }`.
    2. Wallet signs `unsignedTx`.

    3. Wallet submits the signed tx to any Alephium node.
  version: 0.1.0
  license:
    name: MIT
  contact:
    name: Aura
    url: https://docs.aura.markets
servers:
  - url: /
    description: this server
security:
  - SessionCookie: []
  - SessionBearer: []
  - {}
tags:
  - name: Health
    description: Liveness + version info.
  - name: Auth
    description: Wallet account sessions (sign in, sign out).
  - name: Developer keys
    description: Create, rotate, revoke, and audit scoped builder identities.
  - name: Protocol
    description: Canonical chain, contract, trading, fee, and realtime configuration.
  - name: Transactions
    description: >-
      Reconcile Alephium transaction state with Aura indexing and recovery
      state.
  - name: Platform
    description: Site-wide banner settings and aggregate platform stats.
  - name: Realtime
    description: Server-Sent Events stream for live market and account updates.
  - name: Webhooks
    description: >-
      Durable HMAC-signed delivery of public and explicitly authorized private
      events.
  - name: Markets
    description: Browse and look up prediction markets.
  - name: Categories
    description: Top-level market taxonomy with counts.
  - name: Tags
    description: Free-form market tags with counts.
  - name: Events
    description: Linked-market groups (multi-leg events).
  - name: Search
    description: Full-text + fuzzy search across markets.
  - name: Orderbook
    description: Live order book + recent fills.
  - name: Trading
    description: Secure builder order placement, cancellation, and dead-man controls.
  - name: Trading receipts
    description: Public keys for verifying sequencer receipts.
  - name: Prices
    description: Latest prices and historical price series.
  - name: Positions
    description: Open share positions for the signed-in wallet.
  - name: Funding
    description: >-
      Wallet-authorized native funding balances, deposits, history, and
      withdrawal construction.
  - name: Parlays
    description: Parlay pool capacity, leg correlation checks, and clearance.
  - name: Vault
    description: AURA token vault. Build unsigned deposit / unlock / withdraw txs.
  - name: Disputes
    description: Optimistic oracle disputes. Read-side state and votes.
  - name: Oracle votes
    description: Build unsigned oracle txs (submit / dispute / commit / reveal).
  - name: Voting
    description: Governance proposals + voting period state.
  - name: Vote
    description: Build unsigned governance vote tx.
  - name: Proposals
    description: Validate + build market-proposal txs (single-leg, linked, parlay).
  - name: Rewards
    description: Liquidity reward programs, per-wallet accruals, and market sponsorships.
  - name: Earnings
    description: >-
      Unified creator, maker, referral, treasury, and builder attribution
      accounting.
  - name: Referrals
    description: Referral summaries and payout history.
  - name: Users
    description: Wallet-scoped reads. Profile, positions, orders, parlays.
  - name: Account actions
    description: Aggregated "what does this wallet need to do" views.
  - name: Account
    description: Watchlist and notification management for the signed-in wallet.
  - name: Leaderboard
    description: Top traders by composite score.
  - name: Account
    description: Watchlist and notification state for the signed-in wallet.
externalDocs:
  description: Full Aura documentation (guides + interactive API reference)
  url: https://docs.aura.markets
paths:
  /v1/developer/keys/{id}/revoke:
    post:
      tags:
        - Developer keys
      summary: Revoke a developer key. Repeated revocation is a safe no-op.
      parameters:
        - schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
          in: path
          name: id
          required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  key:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      name:
                        type: string
                      prefix:
                        type: string
                      builderCode:
                        type: string
                        pattern: ^[a-z0-9][a-z0-9_-]{1,31}$
                        description: >-
                          Stable public attribution code bound to this
                          developer-key owner. Copy this exact value into the
                          user trading authorization; it is not a credential.
                      environment:
                        type: string
                        enum:
                          - test
                          - live
                      scopes:
                        type: array
                        items:
                          type: string
                          enum:
                            - public:read
                            - market:read
                            - realtime:public
                            - account:read
                            - transactions:read
                            - trade:place
                            - trade:cancel
                            - webhooks:manage
                      readRequestsPerMinute:
                        type: integer
                        exclusiveMinimum: 0
                        maximum: 9007199254740991
                      writeRequestsPerMinute:
                        type: integer
                        exclusiveMinimum: 0
                        maximum: 9007199254740991
                      maxStreamConnections:
                        type: integer
                        exclusiveMinimum: 0
                        maximum: 9007199254740991
                      status:
                        type: string
                        enum:
                          - active
                          - revoked
                      generation:
                        type: integer
                        exclusiveMinimum: 0
                        maximum: 9007199254740991
                      rotatedFrom:
                        anyOf:
                          - type: string
                            format: uuid
                            pattern: >-
                              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                          - type: 'null'
                      expiresAt:
                        anyOf:
                          - type: string
                            format: date-time
                            pattern: >-
                              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                          - type: 'null'
                      lastUsedAt:
                        anyOf:
                          - type: string
                            format: date-time
                            pattern: >-
                              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                          - type: 'null'
                      createdAt:
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                      revokedAt:
                        anyOf:
                          - type: string
                            format: date-time
                            pattern: >-
                              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                          - type: 'null'
                    required:
                      - id
                      - name
                      - prefix
                      - builderCode
                      - environment
                      - scopes
                      - readRequestsPerMinute
                      - writeRequestsPerMinute
                      - maxStreamConnections
                      - status
                      - generation
                      - rotatedFrom
                      - expiresAt
                      - lastUsedAt
                      - createdAt
                      - revokedAt
                    additionalProperties: false
                required:
                  - key
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
      security:
        - SessionCookie: []
        - SessionBearer: []
components:
  securitySchemes:
    SessionCookie:
      type: apiKey
      in: cookie
      name: aura_session
      description: >-
        HttpOnly session cookie set by POST /v1/auth/session. Mutating requests
        must also send the CSRF token (returned by that call) in the
        x-csrf-token header.
    SessionBearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        The same wallet-bound session JWT returned only when POST
        /v1/auth/session uses issueToken=true. Intended for server-side/scripted
        clients; cookie CSRF does not apply.

````