> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aura.markets/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit an advanced pre-encoded instant intent through restricted custody.

> Advanced compatibility route for clients that already implement Aura’s audited 180-byte intent encoder. Aura still derives the authorization owner, revalidates every policy/cap/witness, signs in the enclave and submits itself. Attribution is fixed to the authenticated developer key’s canonical builderCode. Prefer POST /v1/orders for ordinary BUY and SELL placement.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/orders/raw
openapi: 3.1.0
info:
  title: Aura API
  description: >-
    Public REST API for Aura, prediction markets on Alephium.


    This API exposes the app read model: markets, live instant order books,

    orders, fills, vault state, oracle and governance. Non-trading

    build-tx endpoints return unsigned transactions for the client to

    sign with its own wallet.


    Interactive reference: https://docs.aura.markets/api-reference/introduction


    ## Discovery


    Built for integrators, not for lazy implementers:


    - **Faceted lists.** Every list endpoint accepts `?facets=true`
      and returns category, tag, and status counts in the same response,
      so a UI can render filter chips without a second request.
    - **Cursor pagination.** Stable across inserts and fast at depth.
      Offset paging via `?page=` is still supported for compat.
    - **Rich filters.** `?q=`, `?category=`, `?tags=`, `?status=`,
      `?creator=`, and `?minVolume=` on `/v1/markets`. Tag matching is
      AND, so all listed tags must be present.
    - **Sortable.** `?sort=created-at|volume|best-bid-yes|recently-traded`
      with `?order=asc|desc`. Use `/v1/trending` for the composite-score sort.
    - **Field projection.** `?fields=id,question,bestBidYes` trims the
      wire weight for thin clients.
    - **Unified search.** `/v1/search?q=` matches strictly first, then
      falls back to typo-tolerant matching when nothing hits. The result
      type is a discriminated union, so adding events or users later is
      non-breaking.
    - **Transparent trending.** `/v1/trending` returns the full algorithm
      and per-market component scores so the ranking is auditable.
    - **Categories and tags as first-class.** `/v1/categories` and
      `/v1/tags` enumerate the taxonomy with market counts.

    ## Authentication


    Aura uses wallet-bound account sessions delivered as an HttpOnly

    cookie. Sign in by signing a one-time challenge with your wallet:


    ```

    POST /v1/auth/challenge   { "address": "..." }

    POST /v1/auth/session     { "address": "...", "publicKey": "...",
    "signature": "...", "keyType": "gl-secp256k1" }

    ```


    The `session` call sets the `aura_session` cookie and returns a CSRF

    token; send it back in the `x-csrf-token` header on every mutating

    request. Every token is checked against durable revocation state.

    `POST /v1/auth/logout` revokes the presented cookie or bearer session;

    cookie callers include the same CSRF header.


    Reads are accessible anonymously with low IP-based rate limits;

    write endpoints (`/v1/tx/*`, social writes) require a valid session.


    ## Rate limits


    | Tier      | Reads (req/min) | Writes (req/min) |

    |-----------|----------------:|-----------------:|

    | Anonymous | 60 per IP | 10 per IP |

    | Signed-in | 600 per wallet | 60 per wallet |


    Standard `RateLimit-*` response headers are returned on every

    request (IETF `draft-ietf-httpapi-ratelimit-headers`).


    ## Write endpoints


    Aura never returns raw keys, signing grants, or transaction/intent

    signatures. Embedded-wallet keys are usable only inside the measured

    enclave. Endpoints under `/v1/tx/*` return an *unsigned* transaction

    for an independently controlled wallet to sign and submit.


    Builder trading endpoints require two independent credentials: a scoped

    developer key identifies and rate-limits the integration, while a

    user-created restricted trading authorization permits only its bounded

    place/cancel policy. Aura signs and submits inside custody; the builder

    receives a receipt, never a reusable signature.


    A typical on-chain lifecycle flow:


    1. `POST /v1/tx/vault/{address}/deposit` → server returns
       `{ unsignedTx, gasEstimate, ... }`.
    2. Wallet signs `unsignedTx`.

    3. Wallet submits the signed tx to any Alephium node.
  version: 0.1.0
  license:
    name: MIT
  contact:
    name: Aura
    url: https://docs.aura.markets
servers:
  - url: /
    description: this server
security:
  - SessionCookie: []
  - SessionBearer: []
  - {}
tags:
  - name: Health
    description: Liveness + version info.
  - name: Auth
    description: Wallet account sessions (sign in, sign out).
  - name: Developer keys
    description: Create, rotate, revoke, and audit scoped builder identities.
  - name: Protocol
    description: Canonical chain, contract, trading, fee, and realtime configuration.
  - name: Transactions
    description: >-
      Reconcile Alephium transaction state with Aura indexing and recovery
      state.
  - name: Platform
    description: Site-wide banner settings and aggregate platform stats.
  - name: Realtime
    description: Server-Sent Events stream for live market and account updates.
  - name: Webhooks
    description: >-
      Durable HMAC-signed delivery of public and explicitly authorized private
      events.
  - name: Markets
    description: Browse and look up prediction markets.
  - name: Categories
    description: Top-level market taxonomy with counts.
  - name: Tags
    description: Free-form market tags with counts.
  - name: Events
    description: Linked-market groups (multi-leg events).
  - name: Search
    description: Full-text + fuzzy search across markets.
  - name: Orderbook
    description: Live order book + recent fills.
  - name: Trading
    description: Secure builder order placement, cancellation, and dead-man controls.
  - name: Trading receipts
    description: Public keys for verifying sequencer receipts.
  - name: Prices
    description: Latest prices and historical price series.
  - name: Positions
    description: Open share positions for the signed-in wallet.
  - name: Funding
    description: >-
      Wallet-authorized native funding balances, deposits, history, and
      withdrawal construction.
  - name: Parlays
    description: Parlay pool capacity, leg correlation checks, and clearance.
  - name: Vault
    description: AURA token vault. Build unsigned deposit / unlock / withdraw txs.
  - name: Disputes
    description: Optimistic oracle disputes. Read-side state and votes.
  - name: Oracle votes
    description: Build unsigned oracle txs (submit / dispute / commit / reveal).
  - name: Voting
    description: Governance proposals + voting period state.
  - name: Vote
    description: Build unsigned governance vote tx.
  - name: Proposals
    description: Validate + build market-proposal txs (single-leg, linked, parlay).
  - name: Rewards
    description: Liquidity reward programs, per-wallet accruals, and market sponsorships.
  - name: Earnings
    description: >-
      Unified creator, maker, referral, treasury, and builder attribution
      accounting.
  - name: Referrals
    description: Referral summaries and payout history.
  - name: Users
    description: Wallet-scoped reads. Profile, positions, orders, parlays.
  - name: Account actions
    description: Aggregated "what does this wallet need to do" views.
  - name: Account
    description: Watchlist and notification management for the signed-in wallet.
  - name: Leaderboard
    description: Top traders by composite score.
  - name: Account
    description: Watchlist and notification state for the signed-in wallet.
externalDocs:
  description: Full Aura documentation (guides + interactive API reference)
  url: https://docs.aura.markets
paths:
  /v1/orders/raw:
    post:
      tags:
        - Trading
      summary: >-
        Submit an advanced pre-encoded instant intent through restricted
        custody.
      description: >-
        Advanced compatibility route for clients that already implement Aura’s
        audited 180-byte intent encoder. Aura still derives the authorization
        owner, revalidates every policy/cap/witness, signs in the enclave and
        submits itself. Attribution is fixed to the authenticated developer
        key’s canonical builderCode. Prefer POST /v1/orders for ordinary BUY and
        SELL placement.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                intentHex:
                  type: string
                  pattern: ^[0-9a-fA-F]{360}$
                clientOrderId:
                  type: string
                  pattern: ^(0|[1-9][0-9]*)$
                  description: >-
                    Exact token base-unit quantity encoded as canonical JSON
                    string.
                marketWitnesses:
                  minItems: 1
                  maxItems: 16
                  type: array
                  items:
                    type: object
                    properties:
                      marketId:
                        type: string
                        pattern: ^(0|[1-9][0-9]*)$
                        description: >-
                          Exact token base-unit quantity encoded as canonical
                          JSON string.
                      group:
                        type: integer
                        minimum: 0
                        maximum: 3
                    required:
                      - marketId
                      - group
                    additionalProperties: false
              required:
                - intentHex
                - clientOrderId
                - marketWitnesses
              additionalProperties: false
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  authorizationId:
                    type: string
                    format: uuid
                    pattern: >-
                      ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                  authorizationGeneration:
                    type: integer
                    exclusiveMinimum: 0
                    maximum: 9007199254740991
                  status:
                    type: string
                    minLength: 1
                    maxLength: 80
                    pattern: ^[A-Za-z0-9_.:-]+$
                  receipt:
                    anyOf:
                      - type: object
                        properties:
                          receiptBytesHex:
                            type: string
                            pattern: ^[0-9a-f]{404}$
                          signatureHex:
                            type: string
                            pattern: ^[0-9a-f]{128}$
                          signingKeyId:
                            type: integer
                            minimum: 0
                            maximum: 4294967295
                        required:
                          - receiptBytesHex
                          - signatureHex
                          - signingKeyId
                        additionalProperties: false
                      - type: 'null'
                  intentHash:
                    type: string
                    pattern: ^[0-9a-f]{64}$
                required:
                  - authorizationId
                  - authorizationGeneration
                  - status
                  - receipt
                  - intentHash
                additionalProperties: false
        '201':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  authorizationId:
                    type: string
                    format: uuid
                    pattern: >-
                      ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                  authorizationGeneration:
                    type: integer
                    exclusiveMinimum: 0
                    maximum: 9007199254740991
                  status:
                    type: string
                    minLength: 1
                    maxLength: 80
                    pattern: ^[A-Za-z0-9_.:-]+$
                  receipt:
                    anyOf:
                      - type: object
                        properties:
                          receiptBytesHex:
                            type: string
                            pattern: ^[0-9a-f]{404}$
                          signatureHex:
                            type: string
                            pattern: ^[0-9a-f]{128}$
                          signingKeyId:
                            type: integer
                            minimum: 0
                            maximum: 4294967295
                        required:
                          - receiptBytesHex
                          - signatureHex
                          - signingKeyId
                        additionalProperties: false
                      - type: 'null'
                  intentHash:
                    type: string
                    pattern: ^[0-9a-f]{64}$
                required:
                  - authorizationId
                  - authorizationGeneration
                  - status
                  - receipt
                  - intentHash
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '409':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '429':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '502':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '503':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        description: Machine-readable error code (snake_case).
                      message:
                        type: string
                        description: Human-readable error message.
                      requestId:
                        type: string
                        description: >-
                          Per-request correlation id. Include it when reporting
                          an error to Aura.
                      details: {}
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
      security:
        - DeveloperKey: []
          TradingAuthorization: []
components:
  securitySchemes:
    SessionCookie:
      type: apiKey
      in: cookie
      name: aura_session
      description: >-
        HttpOnly session cookie set by POST /v1/auth/session. Mutating requests
        must also send the CSRF token (returned by that call) in the
        x-csrf-token header.
    SessionBearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        The same wallet-bound session JWT returned only when POST
        /v1/auth/session uses issueToken=true. Intended for server-side/scripted
        clients; cookie CSRF does not apply.
    DeveloperKey:
      type: apiKey
      in: header
      name: x-aura-developer-key
      description: >-
        Builder identity and quota key. It never substitutes for a wallet
        session or restricted trading authorization and can never sign or
        custody assets.
    TradingAuthorization:
      type: apiKey
      in: header
      name: x-aura-trading-authorization
      description: >-
        One-time-shown, user-created restricted trading credential bound to a
        developer key, policy limits, expiry and optional source IP. Aura signs
        and submits inside custody; the credential never reveals a grant,
        transaction signature, intent signature or seed.

````