GETTING STARTEDIntroductionOverview of the xauapi data APIGETTING STARTEDQuickstartCreate a key and make your first requestGETTING STARTEDAuthenticationBearer tokens, key rotation and revocationGETTING STARTEDMCP integrationConnect AI tools to gold market data · Proposed integrationCONCEPTSBroker feedsBrokers and source identityCONCEPTSFreshness & coverageTimestamps, sampling and stale dataAPI REFERENCELatest quoteGET /v1/quote · Bid, Ask and spreadAPI REFERENCECandlesGET /v1/candles · M1, M5 and M15 OHLCAPI REFERENCEFeed statusGET /v1/status · Connection and freshnessRESOURCESErrors401, 429 and 503 response handlingRESOURCESUsage & limitsAnnual allowance, rate limits and billing

11 topics. Select a result to open it.

getting started

Authentication

Bearer tokens, key rotation and revocation

Draft reference · Examples use sample data.

Authorization header

Send a Bearer token with each request. Use a server-side integration so your key is not exposed to visitors.

HTTP header
Authorization: Bearer YOUR_API_KEY

Key lifecycle

  • Create: generate the first key from your workspace.
  • Rotate: replace the key, then update your integration.
  • Revoke: disable the key when it is no longer needed.

The workspace supports one active key. It does not implement a rotation grace period.

Authentication failures

401 · application/json
{
  "demo": true,
  "error": "INVALID_API_KEY",
  "message": "Create or select an active demo key."
}

Check the key before retrying. Manage your demo key →