# Dunamu > Dunamu Inc. (두나무 주식회사) is a South Korean fintech and blockchain company founded in April 2012 > and headquartered in Seocho-gu, Seoul. Dunamu operates Upbit — Korea's largest digital asset > exchange and the country's first registered VASP — and Stockplus, a securities trading > application, alongside Stockplus Unlisted for pre-IPO shares. Dunamu publishes no developer > program at dunamu.com; its entire public API surface is served under the Upbit brand through the > Upbit Developer Center. This file was generated by API Evangelist from the public Dunamu corporate surface and the Dunamu-operated Upbit developer surface. Dunamu publishes no llms.txt of its own at dunamu.com (probed 2026-08-12, HTTP 404); the Upbit Developer Center does publish one, linked below. ## Company - [Dunamu](https://dunamu.com/): Corporate site (Korean; /en for English). - [About Dunamu](https://dunamu.com/about/company): Company facts, milestone timeline, and the certification history (ISMS 2018, ISO 27001 2018, ISO 27701 2021, ISMS-P 2021, ISO 22301 2023). - [Vision](https://dunamu.com/about/vision) - [Blockchain services](https://dunamu.com/services/blockchain): Upbit and the Korean digital asset index. - [Securities services](https://dunamu.com/services/securities): Stockplus and Stockplus Unlisted. - [Newsroom](https://dunamu.com/news) - [Notices](https://dunamu.com/notice) - [Investor relations](https://dunamu.com/ir/announcement) - [Disclosures](https://dunamu.com/ir/disclosure) - [ESG](https://dunamu.com/esg/management) - [Careers](https://dunamu.com/careers/jobs) ## APIs Dunamu serves no API from dunamu.com. The API surface below is operated by Dunamu under the Upbit brand and is catalogued in full at the Upbit provider profile (https://raw.githubusercontent.com/api-evangelist/upbit/refs/heads/main/apis.yml). - [Upbit Developer Center](https://global-docs.upbit.com/): Developer portal for the Upbit Open API. - [API reference](https://global-docs.upbit.com/reference): REST and WebSocket reference — quotation (public market data), exchange accounts, orders, deposits, withdrawals, service, Travel Rule. - [First API call](https://global-docs.upbit.com/docs/first-exchange-api-call): Getting started. - [Authentication](https://global-docs.upbit.com/reference/auth): JWT (HS256) bearer token, claims `access_key`, `nonce`, `query_hash`, `query_hash_alg`. No OAuth, no OIDC, no scopes. - [Rate limits](https://global-docs.upbit.com/reference/rate-limits): Per-group limits reported on every response in the `Remaining-Req` header (`group=…; min=…; sec=…`). Budget against `sec` — `min` is documented as deprecated and fixed. 429 escalates to 418 (temporary block) on continued violation. Browser-originated calls (requests carrying an `Origin` header) are limited to 1 request per 10 seconds. - [REST API usage and error guide](https://global-docs.upbit.com/reference/rest-api-guide): The error envelope and the full published error-code table. - [Changelog](https://global-docs.upbit.com/changelog): Dated announcement feed for API changes. - [Upbit llms.txt](https://global-docs.upbit.com/llms.txt): The Upbit Developer Center's own llms.txt. Regional REST bases (there is no single global host — pick the one for your service region): `https://sg-api.upbit.com` (Singapore), `https://id-api.upbit.com` (Indonesia), `https://th-api.upbit.com` (Thailand, documented as beta and subject to change). WebSocket: `wss://-api.upbit.com/websocket/v1` (public) and `/websocket/v1/private` (authenticated). Access is free. There is one tier and no paid upgrade path — public quotation endpoints need no account at all, and authenticated exchange endpoints need an Upbit account at security level 2+ with an API key issued from the PC web. Order and withdrawal permissions require a static allowlisted IP; dynamic-IP environments are unsupported. Retired: `https://quotation-api-cdn.dunamu.com/v1/forex/recent` — Dunamu's long-running public FX rate endpoint. The host no longer resolves (NXDOMAIN, probed 2026-08-12). Do not use it. ## SDKs and tooling All first-party, published by Dunamu from https://github.com/upbit-official. - [upbit-sdk (Python)](https://pypi.org/project/upbit-sdk/): v0.9.0, 2026-04-14. `pip install upbit-sdk` - [@upbit-official/upbit-sdk (TypeScript)](https://www.npmjs.com/package/@upbit-official/upbit-sdk): v0.9.0, 2026-04-14. - [upbit-sdk-go](https://pkg.go.dev/github.com/upbit-official/upbit-sdk-go): v0.9.0, 2026-05-06. - [@upbit-official/upbit-cli](https://www.npmjs.com/package/@upbit-official/upbit-cli): v0.9.3, 2026-07-23. `npm install -g @upbit-official/upbit-cli` - [upbit-strategy-toolkit](https://github.com/upbit-official/upbit-strategy-toolkit): Strategy backtesting driven by an AI agent. Git clone only, no registry release. ## Agent surface - [Upbit Agent Skills](https://github.com/upbit-official/upbit-agent-skills): Provider-published Agent Skill (v0.9.2, Apache-2.0) for skill-aware coding agents. It drives the `upbit` CLI rather than raw HTTP, is bilingual Korean/English, requires an `X-Upbit-Initiator` attribution header on every API-calling command, and requires a typed CONFIRM before any write operation. - [Upbit AI integration guide](https://global-docs.upbit.com/docs/ai-guide): Dunamu's own guidance on driving the docs from an LLM. Every documentation page is served as Markdown by appending `.md` to its URL (e.g. `/reference/rest-api-guide.md`) — verified 200 on 2026-08-12. Each twin carries an `updatedAt` timestamp and a pointer back to llms.txt. Note the provider's own caveat: commercial redistribution or monetization of the docs may violate the [Open API Terms of Use](https://sg.upbit.com/open_api_agreement). - Retry safety: `Test Order` is a real dry-run (validates without creating). Order creation accepts a client-assigned `identifier` that is permanently non-reusable, which suppresses duplicate orders on retry — but it REJECTS the duplicate rather than replaying the original response, and there is no `Idempotency-Key` header. A retry must also carry a fresh JWT `nonce` or it fails with `nonce_used` (401) first. - No MCP server, no A2A agent card. Probed 2026-08-12: `/.well-known/agent-card.json` and `/.well-known/agent.json` return 404 on dunamu.com, stockplus.com, global-docs.upbit.com and all three regional API hosts. Community MCP servers for Upbit exist on GitHub; none is first-party. ## Legal - [Upbit terms of service](https://upbit.com/terms_of_service) - [Upbit privacy policy](https://upbit.com/privacy_policy) - [Stockplus terms](https://stockplus.com/agreements/term) - [Stockplus privacy](https://stockplus.com/agreements/privacy) - [Upbit Care investor protection center](https://upbitcare.com) ## API Evangelist artifacts - packages/dunamu-packages.yml — first-party SDK inventory with registry versions and dates. - cli/dunamu-cli.yml — the `upbit` CLI command surface. - skills/dunamu-upbit-skill.md — the provider-published Agent Skill, saved verbatim. - changelog/dunamu-changelog.yml — recent dated API changes. - lifecycle/dunamu-lifecycle.yml — versioning, deprecation practice, retired surfaces. - conformance/dunamu-conformance.yml — published certifications. - security/dunamu-domain-security.yml — TLS/DNS posture probe. - well-known/dunamu-well-known.yml — recorded absence of every /.well-known/ document, the STEP 0b contract-discovery sweep, and the MCP/agent-card negative results. - authentication/dunamu-authentication.yml — JWT scheme, claims, API-key permissions, IP allowlist. - conventions/dunamu-conventions.yml — cross-cutting runtime semantics: idempotency, pagination, encoding, gzip, versioning, error branching, rate-limit signaling, agent surface. - errors/dunamu-problem-types.yml — the published error-code catalog and envelope. - rate-limits/dunamu-rate-limits.yml — every published limit group, the `Remaining-Req` header, and the 429 → 418 escalation. - plans/dunamu-plans-pricing.yml — one free tier; no developer pricing page exists.