Kalshi API · request anatomy

Kalshi signing message builder

Separate the URL you request from the path you sign. Check the prefix, method and timestamp before adding authentication in your own client.

Build the message to sign

Enter public request details. The example timestamp is fixed for illustration; use a fresh timestamp for an actual request. This helper builds text, without signing it or sending a request.

Request URL · query retained

https://external-api.demo.kalshi.co/trade-api/v2/portfolio/orders?limit=5

Signing path · query excluded

/trade-api/v2/portfolio/orders

Message bytes as UTF-8 text

1791316800000GET/trade-api/v2/portfolio/orders

Concatenation order: timestamp + uppercase method + full signing path. The query remains in the request URL but is excluded from this signing message.

A valid-looking message does not verify a key, account permission or endpoint. Keep the API key ID, private key and signature out of this helper.

What goes into the signing message?

The official authentication guide specifies timestamp + HTTP method + full request path. The timestamp is in milliseconds. The cryptographic signature and authentication headers must still be produced in your own client.

The request URL and signing path are different

Kalshi's environment documentation excludes the host and query from the signed path. This helper preserves the query in the displayed request URL, adds the Predictions API prefix once, and shows the text used for signing. It does not verify endpoint existence or account access.

Use a fresh timestamp when sending

The initial timestamp is a fixed example for reproducible comparisons. Use the current-timestamp button when inspecting a new request, and generate the timestamp again immediately before signing and sending in your actual client. Keep the header timestamp and message timestamp identical.

Continue with the setup guide

Read the Kalshi API-key setup guide for credentials, environment alignment and troubleshooting. The general API guide covers public market data and rate limits.