# Bullish > Bullish is an institutional digital-asset exchange and custodian running a regulated spot, perpetual, dated-futures and options venue with an integrated automated market maker and qualified custody. It publishes a 79-operation OpenAPI 3.0.3 Trading API, six AsyncAPI 3.0.0 WebSocket documents, and a documented FIX order-entry and drop-copy surface. Authentication is a JWT bearer token minted by exchanging a client-signed ECDSA R1 (P-256) or HMAC login — there is no OAuth. Listed on the NYSE as BLSH. Generated by the API Evangelist enrichment pipeline on 2026-08-08. Bullish does not publish its own /llms.txt (probed: 404 on bullish.com, www.bullish.com, api.exchange.bullish.com, docs.exchange.bullish.com, exchange.bullish.com). ## Start here - [Developer docs](https://docs.exchange.bullish.com/): Root of the Bullish developer documentation. - [REST introduction](https://docs.exchange.bullish.com/rest/introduction): What the Trading API offers and how bearer auth works. - [Authentication](https://docs.exchange.bullish.com/rest/authentication): HMAC vs ECDSA API keys, the two login endpoints, the BX-* signing headers, and the 24-hour token lifetime. - [API specifications](https://docs.exchange.bullish.com/api-specifications): Downloadable OpenAPI and AsyncAPI documents. ## Machine-readable specifications - [Bullish Trading API OpenAPI 3.0.3](https://docs.exchange.bullish.com/assets/files/bullish-trading-api-ef0f4d1847eab78c70a8651acd61ba69.yml): 75 paths, 79 operations, 211 component schemas. - [Bullish Deprecated Features and APIs OpenAPI 3.0.0](https://docs.exchange.bullish.com/assets/files/bullish-deprecated-api-213e07015e048e4906175e6726d510cb.yml): 15 deprecated and decommissioned operations, published separately from the live spec. - [WebSocket Multi-Order Book (AsyncAPI 3.0.0)](https://docs.exchange.bullish.com/assets/files/ws-mkt-data-orderbook-994d2943030aaaad03b1294c1f9d95fc.yml) - [WebSocket Anonymous Trades (AsyncAPI 3.0.0)](https://docs.exchange.bullish.com/assets/files/ws-mkt-data-trades-088f84b3567841aff4e49c7cb1a4d8fe.yml) - [WebSocket Anonymous Ticks (AsyncAPI 3.0.0)](https://docs.exchange.bullish.com/assets/files/ws-mkt-data-ticks-0836383feafb0bb737c56b861468fee0.yml) - [WebSocket Auction Feed (AsyncAPI 3.0.0)](https://docs.exchange.bullish.com/assets/files/ws-auction-8746f48dd7c72713d722f3a23dce5fdd.yml) - [WebSocket Index Data (AsyncAPI 3.0.0)](https://docs.exchange.bullish.com/assets/files/ws-index-data-6a48b12c1e631257018099a8d0b63aed.yml) - [WebSocket Private Data (AsyncAPI 3.0.0)](https://docs.exchange.bullish.com/assets/files/ws-private-data-4346b0e46fa3c134c25b76ee11096b34.yml) ## APIs - [Trading API](https://docs.exchange.bullish.com/rest/introduction): REST, base https://api.exchange.bullish.com/trading-api. Markets, assets, index prices, option ladders, orders, trades, AMM instructions, market-maker protection, derivatives positions, portfolio-margin simulation, OTC and inter-dealer-broker booking, custody, and history. - [WebSocket APIs](https://docs.exchange.bullish.com/websocket/servers/server): Public market data (order book, trades, ticks, auction, index) and an authenticated private stream. - [FIX API](https://docs.exchange.bullish.com/fix/introduction): Order management, drop copy, reference data, trading status, session management. - [Aggregator API](https://docs.exchange.bullish.com/aggregator/bullish-aggregator-api): Non-authenticated public tickers, order books and last-100-trades for market-data aggregators. ## Cross-cutting semantics - [Rate limits](https://docs.exchange.bullish.com/rest/general/rate-limits): 50 req/s per category, 500 req/10 s per IP with a 60-second block, x-ratelimit-* headers, HTTP 429 with code 96000 or 96001. BX-RATELIMIT-TOKEN selects a higher tier. - [Pagination](https://docs.exchange.bullish.com/rest/general/pagination): Cursor-based. _pageSize (5/25/50/100, default 25), _metaData, _nextPage, _previousPage; data + links envelope. - [Filtering](https://docs.exchange.bullish.com/rest/general/filtering) - [Price and quantity precision](https://docs.exchange.bullish.com/rest/general/price-quantity-precision) - [Numeric identifier constraints](https://docs.exchange.bullish.com/rest/general/numeric-identifier-constraints) - [Order create/cancel request mechanism](https://docs.exchange.bullish.com/rest/order-processing-create-cancel-request-mechanism): BX-NONCE must be unique and increasing; BX-NONCE-WINDOW-ENABLED relaxes ordering to uniqueness within a window of 100. Wait for the acknowledgement carrying orderId before sending the next request. - [Error and rejection codes](https://github.com/bullish-exchange/api-docs/wiki/Error-&-Rejection-Codes): 167 numeric reason codes across order processing, custody, OTC and MMP. REST uses statusReasonCode / statusReason; FIX uses OrdRejReason (103) / Text (58). - [Exchange time](https://docs.exchange.bullish.com/rest/general/exchange-time) - [Connectivity options](https://docs.exchange.bullish.com/rest/general/connectivity-options) ## Agent-relevant cautions - There is NO idempotency key. The Bullish nonce is strictly increasing, so a blind retry of a failed order request FAILS rather than deduplicating. After a 5xx or timeout, resolve the outcome with GET /trading-api/v2/orders/client-order-id/{clientOrderId} before resubmitting. - HMAC-minted JWTs reach trading endpoints ONLY. Custody operations require an ECDSA R1 key and return 403 otherwise. - Custody withdrawals are irreversible and require a whitelisted destination that belongs to the calling user. - Bullish publishes no MCP server, no A2A agent card, no /.well-known/ documents and no security.txt. ## Change management - [REST changelog](https://docs.exchange.bullish.com/rest/changelog): Dated monthly entries; breaking removals are called out. - [WebSocket changelog](https://docs.exchange.bullish.com/websocket/ws-api-change-log) - [Deprecated features and APIs](https://docs.exchange.bullish.com/rest/deprecated/bullish-deprecated-features-apis) - [Status page](https://status.bullish.com/) — JSON summary at https://status.bullish.com/api/v2/summary.json ## Code and libraries - [GitHub organization](https://github.com/bullish-exchange) - [js-signer (npm)](https://www.npmjs.com/package/js-signer): JavaScript/TypeScript ECDSA R1 signer, MIT. - [python-signer](https://github.com/bullish-exchange/python-signer) - [java-signer](https://github.com/bullish-exchange/java-signer) - [cpp-signer](https://github.com/bullish-exchange/cpp-signer): Includes end-to-end order-entry and custody examples. - [python-bullish-client](https://github.com/bullish-exchange/python-bullish-client) - [ccxt-bullish-python](https://github.com/bullish-exchange/ccxt-bullish-python) - [api-examples](https://github.com/bullish-exchange/api-examples) - [security-audit](https://github.com/bullish-exchange/security-audit): Published third-party audit reports. ## Company, trust and support - [Bullish](https://www.bullish.com/us/) - [Trust and transparency](https://www.bullish.com/us/trust): SOC 1 Type 1 and SOC 2 Type 1 (Deloitte), Deloitte-audited IFRS financials, GFSC, BaFin (MiCA CASP), Hong Kong SFC, FinCEN and NYDFS. - [Bug bounty program](https://www.bullish.com/us/bug-bounty-program): Two Bugcrowd programs — bugcrowd.com/bullish and bugcrowd.com/bullish-exchange. - [Help center](https://support.bullish.com) - [Service desk](https://support.exchange.bullish.com/servicedesk/customer/portals) - [Understanding fees](https://support.exchange.bullish.com/servicedesk/customer/portal/1/article/9373547) - [Sign up](https://exchange.bullish.com/register/sign-up) - [Investor relations](https://investors.bullish.com/) - API support contact: support@bullish.com