generated: '2026-07-20' method: derived source: - openapi/one-trading-fast-openapi.yml - asyncapi/one-trading-streams-asyncapi.yml - https://docs.onetrading.com/llms.txt standards: - id: openapi-3 conforms: true evidence: REST surface captured as OpenAPI 3.0.3. - id: asyncapi-2 conforms: true evidence: WebSocket streaming surface captured as AsyncAPI 2.6. - id: bearer-token-auth conforms: true evidence: HTTP Authorization Bearer API token with permission scopes. - id: oauth2 conforms: false evidence: No OAuth2 authorization/token flow; API tokens are UI-generated. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: Errors use a flat {"error":"CODE"} envelope, not application/problem+json. - id: cursor-pagination conforms: true evidence: List endpoints use max_page_size + cursor. - id: idempotency conforms: true evidence: client_id acts as the order-placement idempotency key. - id: websocket conforms: true evidence: wss://streams.fast.onetrading.com real-time API. notes: >- One Trading Exchange B.V. is an EU-based regulated crypto and derivatives venue. No machine-verifiable security-certification page (SOC 2 / ISO 27001 / PCI) was located during this pass, so no Compliance pointer is asserted.