Trading

Operator update Hyperliquid leverage for an agent position

Operator recovery endpoint. Auth deliberately accepts platform operators or tenant admins and must not require an agent JWT, so humans can recover funds when the agent token is expired. Raw signing keys never leave the vault; all recovery actions are audited and idempotency-protected. Builder-perp symbols such as xyz:SPCX are forced to isolated margin and capped at 3x before submitting Hyperliquid's separate updateLeverage action.

post/trade/{venue}/leverage

Headers

X-Steward-Request-Timestampstring

Unix seconds, Unix milliseconds, or HTTP/ISO timestamp. Sensitive mutating routes require this or X-Steward-Request-Expires-At when request-expiry or request signatures are enforced.

X-Steward-Request-Expires-Atstring

Unix seconds, Unix milliseconds, or HTTP/ISO expiry time. Sensitive mutating routes require this or X-Steward-Request-Timestamp when request-expiry or request signatures are enforced.

X-Steward-Signaturestring

Authorization signature for sensitive mutating routes when STEWARD_REQUIRE_AUTH_SIGNATURE=true or production enforcement is enabled. Use v1=<hmac-sha256> or p256=<signature>.

X-Steward-Signing-Key-Idstring

Tenant request-signing key id used to select a managed HMAC signing key. Required when signing with a managed tenant key; omit only for static or app-client signing secrets.

Idempotency-Keystring

Required for signed sensitive requests and recommended for all sensitive mutating requests. Replays are scoped to authenticated or explicitly signed contexts.

Request body

agentIdstring required
idempotencyKeystring
leverageinteger required
isCrossboolean

Example request

{
  "coin": "xyz:SPCX"
}

Response

JSON response

oktrue required

Example response

{
  "data": {
    "coin": "xyz:SPCX"
  }
}

Changes

Changed in 1 of the 9 revisions of this API.1