> ## Documentation Index
> Fetch the complete documentation index at: https://docs.limitless.exchange/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Partner Sub-Account

> Creates a new sub-account linked to the authenticated partner. Requires HMAC authentication with the `account_creation` scope.

**Server wallet mode** (`createServerWallet: true`): Creates a Privy server wallet and profile. The partner can then submit orders on behalf of this account using delegated signing.

**EOA mode** (default): Requires wallet ownership verification via `x-account`, `x-signing-message`, and `x-signature` headers. The end user signs their own orders.

<Info>
  Requires **HMAC authentication** with the `account_creation` scope. API key auth and Privy auth are not accepted.
</Info>

Creates a new sub-account profile linked to the authenticated partner.

If account creation succeeds but your app fails to persist the returned
`profileId`, use [List Partner Sub-Accounts](/api-reference/partner-accounts/list-partner-accounts)
with the `account` filter to recover it.

### Server wallet mode

Set `createServerWallet: true` to create a Privy server wallet for the sub-account. This enables [delegated signing](/developers/authentication#delegated-signing) — you can submit unsigned orders and the server signs them using the managed wallet.

Before the first delegated trade, call [Check Partner Account Allowances](/api-reference/partner-accounts/check-allowances). If any target is `missing` or `failed` with `retryable=true`, call [Retry Partner Account Allowances](/api-reference/partner-accounts/retry-allowances), then poll the check endpoint again.

<Warning>
  Server wallet creation requires the `delegated_signing` scope on your API token (in addition to `account_creation`). Without it, the request returns `"Server wallet creation requires delegated_signing scope"`.
</Warning>

```json theme={null}
{
  "displayName": "user-bob",
  "createServerWallet": true
}
```

### EOA mode

Omit `createServerWallet` (or set it to `false`) to create an account for an externally-owned address. The end user manages their own keys and signs their own orders.

EOA mode requires three additional headers for wallet ownership verification:

| Header              | Description                                                           |
| ------------------- | --------------------------------------------------------------------- |
| `x-account`         | Checksummed Ethereum address (EIP-55)                                 |
| `x-signing-message` | Hex-encoded signing message obtained from `GET /auth/signing-message` |
| `x-signature`       | Hex-encoded signature produced by signing the message with the wallet |

#### Signing message format

The `x-signing-message` value is **not** the raw text — it is the **hex-encoded** UTF-8 representation of the message returned by `GET /auth/signing-message`. The raw text (which you sign) looks like:

```
Welcome to Limitless Exchange!

This request will not trigger a blockchain transaction or cost any gas fees.

Signature is required to authenticate an upcoming API request.

Nonce: 0x<keccak256-hash>
```

The full flow:

1. **Fetch** the signing message: `GET /auth/signing-message` → returns the plain-text message with a unique nonce.
2. **Sign** the plain-text message with the wallet (e.g. `personal_sign` / `eth_sign`).
3. **Hex-encode** the plain-text message: prepend `0x` to the UTF-8 hex representation.
4. **Send** all three headers on the request.

<CodeGroup>
  ```python Python theme={null}
  import requests
  from eth_account import Account
  from eth_account.messages import encode_defunct

  # 1. Fetch the signing message
  signing_message = requests.get(f"{API_BASE_URL}/auth/signing-message").text

  # 2. Sign the plain-text message
  message = encode_defunct(text=signing_message)
  signed = account.sign_message(message)

  # 3. Hex-encode the message for the header
  hex_message = "0x" + signing_message.encode("utf-8").hex()

  # 4. Use in headers
  headers = {
      "x-account": account.address,                # checksummed address
      "x-signing-message": hex_message,             # hex-encoded message
      "x-signature": "0x" + signed.signature.hex(), # hex-encoded signature
  }
  ```

  ```typescript TypeScript theme={null}
  import { createWalletClient, http, toHex } from 'viem';
  import { privateKeyToAccount } from 'viem/accounts';
  import { base } from 'viem/chains';

  // 1. Fetch the signing message
  const signingMessage = await fetch(`${API_BASE_URL}/auth/signing-message`).then(r => r.text());

  // 2. Sign the plain-text message
  const account = privateKeyToAccount(PRIVATE_KEY);
  const signature = await account.signMessage({ message: signingMessage });

  // 3. Hex-encode the message for the header
  const hexMessage = toHex(new TextEncoder().encode(signingMessage));

  // 4. Use in headers
  const headers = {
    'x-account': account.address,      // checksummed address
    'x-signing-message': hexMessage,   // hex-encoded message
    'x-signature': signature,          // hex-encoded signature
  };
  ```
</CodeGroup>

```json theme={null}
{
  "displayName": "user-alice"
}
```

### Constraints

* `displayName` is optional (max 44 characters). Defaults to the wallet address if omitted.
* Returns `409 Conflict` if a profile already exists for the target address.
* Cannot create a sub-account for the partner's own address.


## OpenAPI

````yaml POST /profiles/partner-accounts
openapi: 3.0.0
info:
  title: Limitless Exchange API
  description: >-

    # Limitless Exchange Trading API


    *Production-ready API for prediction market trading, portfolio management,
    and market data*


    > 🎯 **Quick Navigation**: [Authentication](#tag/authentication) |
    [Markets](#tag/markets) | [Trading](#tag/trading) |
    [Portfolio](#tag/portfolio)


    ---
      


    ## 🚀 Quick Start


    Choose your preferred programming language for complete end-to-end
    implementation:


    ### Overview


    The Limitless Exchange API offers both REST and WebSocket integration:


    **REST API (Trading)**:

    1. **🔐 Authentication**: Use API key for all programmatic access

    2. **📊 Fetch Market Data**: Get market info including venue contract
    addresses (once per market)

    3. **📋 Order Creation**: Build and sign orders using EIP-712 structured
    data

    4. **🚀 Order Submission**: Submit signed orders and receive confirmations


    **WebSocket API (Real-Time Data)**:

    1. **🔌 Connection**: Connect to `/markets` namespace for real-time updates

    2. **📊 Subscriptions**: Subscribe to market prices and position changes

    3. **📡 Events**: Handle live market data and transaction updates


    ### 🔐 Authentication for API Users


    > **⚠️ DEPRECATION NOTICE**: Cookie-based session authentication is
    deprecated and will be removed within weeks. Please migrate to API keys
    immediately.


    | Method | Header | Status |

    |--------|--------|--------|

    | **API Key** | `X-API-Key: lmts_...` | ✅ Required for programmatic access |

    | Cookie Session | `Cookie: limitless_session=...` | ⚠️ Deprecated (removal
    imminent) |


    **Getting an API Key**


    API keys can only be created via the Limitless Exchange UI:

    1. Log in to [limitless.exchange](https://limitless.exchange) using your
    wallet

    2. Click your profile menu (top right)

    3. Select "Api keys"

    4. Generate a new key


    **Using Your API Key**


    Include in all requests via the `X-API-Key` header:


    ```bash

    # REST API

    curl -H "X-API-Key: lmts_your_key_here"
    https://api.limitless.exchange/markets


    # WebSocket - pass X-API-Key header during connection handshake

    ```


    ### Migration from Cookie to API Key


    If you're currently using cookie-based authentication, migrate by:


    1. **Generate an API key** via the UI (profile menu → Api keys)

    2. **Replace cookie header** with API key header:


    ```diff

    # Before (deprecated)

    - Cookie: limitless_session=your_session_token


    # After

    + X-API-Key: lmts_your_key_here

    ```


    3. **Remove session management code** - no more login flow or cookie
    handling needed


    ### Important: Venue System for CLOB Markets


    CLOB markets use a **venue system** where each market is associated with
    specific contract addresses. Before placing orders:


    1. **Fetch market data once**: `GET /markets/:slug` returns venue
    information

    2. **Use venue.exchange**: This is the `verifyingContract` for EIP-712 order
    signing

    3. **Cache the venue**: Venue data is static per market - fetch once and
    reuse


    **Sample venue response:**

    ```json

    {
      "venue": {
        "exchange": "0xA1b2C3...",
        "adapter": "0xD4e5F6..."
      }
    }

    ```


    ### Required Approvals


    Before trading, set up token approvals based on order type:


    | Order Type | Market Type | Approve To |

    |------------|-------------|------------|

    | BUY | All CLOB | USDC → `venue.exchange` |

    | SELL | Simple CLOB | CT → `venue.exchange` |

    | SELL | NegRisk/Grouped | CT → `venue.exchange` AND `venue.adapter` |


    ### Checksummed Addresses


    All addresses must use **checksummed format** (EIP-55 mixed-case):

    - Authentication: `x-account` header

    - Orders: `maker` and `signer` fields

    - Example: `0x5aAeb6053F3E94C9b9A09f33669435E7Ef1BeAed`


    ### Implementation Guides


    **[🐍 Python Quick Start](#description/-python-quick-start)**

    - REST API: eth-account, requests, and web3.py libraries

    - WebSocket: python-socketio, asyncio integration


    **[☕ Java Quick Start](#description/-java-quick-start)**  

    - REST API: Web3j, OkHttp3, and Jackson libraries


    **[📦 Node.js/TypeScript Quick
    Start](#description/-nodejs-typescript-quick-start)**

    - REST API: viem, ethers, and cross-fetch libraries

    - WebSocket: socket.io-client for real-time trading

    - Full TypeScript support with end-to-end examples


    **[🔌 WebSocket Integration](#description/-websocket-integration)**

    - Real-time market data and position updates

    - Production-ready Python client with authentication


    ---
      


    ## 🐍 Python Quick Start


    Complete end-to-end Python implementation for Limitless Exchange API
    integration.
      


    ### 🐍 Python E2E Order Creation Guide


    Complete Python implementation guide is being loaded from external
    documentation...


    **Guide Contents:**

    - 🔐 Complete authentication flow with eth-account

    - 📋 Order construction with Web3.py calculations

    - ✍️ EIP-712 structured data signing

    - 🚀 Order submission with requests library

    - ⚠️ Comprehensive error handling

    - 🛠️ Production deployment considerations


    *For the complete Python guide, ensure the file is available at
    docs/scripts-samples/python-e2e-order-creation.md*
        


    ## ☕ Java Quick Start


    Complete end-to-end Java implementation for Limitless Exchange API
    integration.
      


    ### ☕ Java E2E Order Creation Guide


    Complete Java enterprise implementation guide is being loaded from external
    documentation...


    **Guide Contents:**

    - 🔐 Complete authentication flow with Web3j

    - 📋 Order construction with BigInteger precision

    - ✍️ EIP-712 structured data signing

    - 🚀 Order submission with OkHttp3

    - ⚠️ Enterprise error handling patterns

    - 🏗️ Production Maven project structure


    *For the complete Java guide, ensure the file is available at
    docs/scripts-samples/java-e2e-order-creation.md*
        


    ## 📦 Node.js/TypeScript Quick Start


    Complete end-to-end Node.js/TypeScript implementation for trading and
    WebSocket subscriptions.
      


    ### 📦 Node.js/TypeScript Trading & WebSocket Guide


    Complete Node.js/TypeScript implementation guide is being loaded from
    external documentation...


    **Guide Contents:**

    - 🔐 **Authentication**: Wallet-based auth with ethers and viem

    - 📋 **Order Creation**: EIP-712 signing with viem WalletClient

    - 🚀 **Order Submission**: REST API integration with cross-fetch

    - 🔌 **WebSocket Subscriptions**: socket.io-client for real-time updates

    - 📊 **Market Data**: AMM prices and CLOB orderbook subscriptions

    - ⚠️ **Type Safety**: Full TypeScript support with proper types

    - 🛠️ **Production Ready**: Complete end-to-end working example


    **Key Features:**

    - **Combined Subscriptions**: Subscribe to both AMM and CLOB markets
    simultaneously

    - **Authentication Flow**: Complete wallet-based authentication with session
    management

    - **Trading Integration**: Place orders and receive real-time updates

    - **TypeScript First**: Type-safe implementation with proper interfaces


    *For the complete Node.js guide, ensure the file is available at
    docs/scripts-samples/node-socket-trading-and-subscribe.md*
        


    ## 🔌 WebSocket Integration


    Real-time market data and position updates using WebSocket connections.
      


    ### 🔌 WebSocket Real-Time Integration Guide


    Complete WebSocket implementation guide is being loaded from external
    documentation...


    **Guide Contents:**

    - 🔌 **WebSocket Connection**: python-socketio client with async support

    - 🔐 **Authentication**: JWT session cookie integration

    - 📊 **Market Subscriptions**: Real-time price updates and position changes

    - ⚡ **Event Handling**: Comprehensive event processing patterns

    - 🔄 **Auto-Reconnection**: Production-ready reconnection logic

    - 🛠️ **Error Recovery**: Robust error handling and fallback strategies


    **Key Features:**

    - **Public Mode**: Market price updates without authentication

    - **Authenticated Mode**: Full access to positions and transactions

    - **Multi-Market Support**: Subscribe to multiple markets simultaneously

    - **Production Ready**: Tested patterns for production deployment


    *For the complete WebSocket guide, ensure the file is available at
    docs/scripts-samples/python-socket-subscribe.md*
        
  version: '1.0'
  contact:
    name: API Support
    url: https://limitless.exchange
    email: hey@limitless.network
servers:
  - url: https://api.limitless.exchange
    description: Production API
security: []
tags:
  - name: Authentication
    description: User authentication and session management
  - name: Markets
    description: Browse, search, and analyze prediction markets
  - name: Market Navigation
    description: Navigation tree, market pages, and property filters
  - name: Trading
    description: Create, manage, and cancel orders
  - name: Portfolio
    description: Position tracking, trade history, and performance
  - name: Feed
    description: Public trading activity feeds
paths:
  /profiles/partner-accounts:
    post:
      tags:
        - Partner Accounts
      summary: Create partner sub-account
      description: >-
        Creates a new sub-account linked to the authenticated partner. Requires
        HMAC authentication with the `account_creation` scope.


        **Server wallet mode** (`createServerWallet: true`): Creates a Privy
        server wallet and profile. The partner can then submit orders on behalf
        of this account using delegated signing.


        **EOA mode** (default): Requires wallet ownership verification via
        `x-account`, `x-signing-message`, and `x-signature` headers. The end
        user signs their own orders.
      operationId: ProfileController_createPartnerAccount
      parameters:
        - name: x-account
          in: header
          required: false
          schema:
            type: string
          description: >-
            EOA mode only. Checksummed Ethereum address of the sub-account
            wallet.
        - name: x-signing-message
          in: header
          required: false
          schema:
            type: string
          description: EOA mode only. Hex-encoded signing message.
        - name: x-signature
          in: header
          required: false
          schema:
            type: string
          description: EOA mode only. Hex-encoded signature from the sub-account wallet.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreatePartnerAccountRequest'
      responses:
        '201':
          description: Sub-account created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreatePartnerAccountResponse'
        '400':
          description: >-
            Cannot create a partner account for the partner's own address, or
            profile creation failed
        '401':
          description: Wallet ownership verification failed (EOA mode)
        '403':
          description: Requires apiToken auth with account_creation scope
        '409':
          description: A profile already exists for this address
      security:
        - HmacAuth: []
components:
  schemas:
    CreatePartnerAccountRequest:
      type: object
      properties:
        displayName:
          type: string
          maxLength: 44
          description: >-
            Public display name for the sub-account. Defaults to the wallet
            address if omitted.
          example: user-alice
        createServerWallet:
          type: boolean
          description: >-
            If true, creates a Privy server wallet for the sub-account (enables
            delegated signing). If false or omitted, requires EOA wallet
            ownership headers.
          default: false
    CreatePartnerAccountResponse:
      type: object
      properties:
        profileId:
          type: integer
          description: Profile ID of the created sub-account
          example: 789
        account:
          type: string
          description: Wallet address of the created sub-account
          example: '0x5aAeb6053F3E94C9b9A09f33669435E7Ef1BeAed'
      required:
        - profileId
        - account
  securitySchemes:
    HmacAuth:
      type: apiKey
      in: header
      name: lmts-api-key
      description: >-
        Scoped API token with HMAC-SHA256 signing. Requires three headers:
        lmts-api-key (token ID), lmts-timestamp (ISO-8601), lmts-signature
        (Base64-encoded HMAC). See Authentication docs for details.

````