NEW: Live arbitrage across 10+ prediction markets.Arbitrage →
← Index
APISep 26, 2026

Polymarket CLOB API (2026): Keys, Endpoints and Rate Limits

Polymarket CLOB API (2026): Keys, Endpoints and Rate Limits

The Short Answer

The Polymarket CLOB API at https://clob.polymarket.com is the exchange's order book and trading API. Order books, prices, midpoints and spreads are public and need no credentials. Placing and managing orders takes two layers of authentication: an L1 wallet signature that creates or derives your API credentials, then L2 HMAC-SHA256 headers on every private request, with a wallet signature on each order as well. New integrations use Polymarket's unified SDKs, @polymarket/client and polymarket-client, which handle that signing. To read Polymarket's books alongside 15+ other venues, Predictefy serves them all in one normalized shape through one API key.

Key Takeaways

  • Market data such as /book, /price, /midpoint and /prices-history needs no key at all.
  • API credentials come from an L1 EIP-712 signature: create them with POST /auth/api-key or recover them with GET /auth/derive-api-key.
  • Every private request carries five POLY_ headers, signed with HMAC-SHA256 over timestamp, method, path and body.
  • Polymarket's docs point new work to the unified SDKs, at 0.11.0 this week, with a migration guide for the older CLOB clients.
  • Order endpoints have their own per-signer limits, up to 5,000 order requests per 10 seconds in bursts.
  • To compare Polymarket's books with Kalshi and other venues, Predictefy serves 15+ venues in one order book shape through a single API key.

What is the Polymarket CLOB API?

CLOB stands for central limit order book, the matching engine behind every Polymarket trade. The CLOB API is how you read that book and put orders onto it. It is one of several Polymarket APIs, and each has its own job:

APIBase URLWhat it is for
Gammahttps://gamma-api.polymarket.comDiscovering events and markets, and their metadata
CLOBhttps://clob.polymarket.comPrices and order books, then placing and managing orders
Datahttps://data-api.polymarket.comPositions, activity and leaderboards
Relayerhttps://relayer-v2.polymarket.comWallet transactions without holding POL for gas

Live updates arrive over WebSockets: the public market channel at wss://ws-subscriptions-clob.polymarket.com/ws/market and the authenticated user channel at /ws/user on the same host. For discovery, start with the Polymarket Gamma API, and for wallet activity, the Polymarket Data API.

Two details catch most first integrations. Trading collateral is pUSD, Polymarket USD. And the CLOB identifies each outcome by a token ID, so the market you see on a web page has to be translated before you can ask for its book, which is covered in finding Polymarket market and token IDs.

Which CLOB endpoints are public?

Everything that describes the market rather than your account can be read without credentials:

EndpointReturns
GET /bookThe order book for one outcome token
/booksBooks for many tokens in one request
GET /price, /midpoint, /spreadThe best price on a side, the midpoint and the spread
GET /last-trade-priceThe most recent trade price
GET /prices-historyPrice history for a token
GET /tick-size, /neg-risk, /fee-rateThe tick size, negative risk flag and fee rate an order has to respect
curl -s "https://clob.polymarket.com/book?token_id=YOUR_TOKEN_ID"

The response lists bids and asks as price and size levels for that one outcome token. The batch versions, such as /books, take a list of tokens, which matters for rate limits as soon as you watch more than a handful of markets. Reading and interpreting depth is covered in the Polymarket order book API.

How do you get Polymarket CLOB API keys?

CLOB credentials are derived from your wallet rather than issued from a dashboard. The flow is one signature and one request:

  1. Build Polymarket's ClobAuth typed data: EIP-712 domain ClobAuthDomain, version 1, chain ID 137, carrying your signer address, a Unix timestamp, a nonce (0 unless you manage several credential sets) and the fixed message "This message attests that I control the given wallet".
  2. Sign it with the private key that controls that address. That signature is your L1 signature.
  3. Send it in the POLY_ADDRESS, POLY_SIGNATURE, POLY_TIMESTAMP and POLY_NONCE headers to POST /auth/api-key to create credentials, or to GET /auth/derive-api-key to recover the ones that already exist for that address and nonce.
  4. Store the three values that come back: apiKey, secret and passphrase.
curl -X POST "https://clob.polymarket.com/auth/api-key" \
  -H "POLY_ADDRESS: YOUR_SIGNER_ADDRESS" \
  -H "POLY_SIGNATURE: YOUR_L1_SIGNATURE" \
  -H "POLY_TIMESTAMP: UNIX_SECONDS" \
  -H "POLY_NONCE: 0"

Derive is the safe default in scripts, because running it twice returns the same credentials instead of creating new ones. The signer is not always the address that holds your funds, which is the most common reason for empty responses later; Polymarket wallet types explains which address goes where, and Polymarket API keys explained covers the whole credential story.

How are private CLOB requests signed?

Every private request is an L2 request. Concatenate a fresh Unix timestamp in seconds, the uppercase HTTP method, the request path and the exact serialized body, then sign that string with HMAC-SHA256 using your base64-decoded secret, and encode the result as URL-safe base64:

message   = timestamp + "GET" + "/data/orders"      # append the exact body on POST requests
signature = urlsafe_base64(HMAC_SHA256(base64_decode(secret), message))
HeaderValue
POLY_ADDRESSYour Polygon signer address
POLY_SIGNATUREThe HMAC-SHA256 signature above
POLY_TIMESTAMPThe Unix timestamp used in the signature
POLY_API_KEYYour credentials' apiKey
POLY_PASSPHRASEYour credentials' passphrase

Placing an order needs one more signature on top. The order itself is signed by the wallet, while L2 authenticates the request that carries it. That third signature, with its rounding rules on price and size, is where most hand-rolled integrations go wrong, and it is the strongest reason to let an SDK do the work.

How do you place an order with the unified SDK?

Polymarket's unified TypeScript SDK wraps all three signatures. This is the flow from Polymarket's own quickstart, placing a small market buy:

import { createSecureClient, OrderSide } from '@polymarket/client';
import { privateKey } from '@polymarket/client/viem';

const client = await createSecureClient({
  wallet: process.env.POLYMARKET_WALLET_ADDRESS as `0x${string}`,
  signer: privateKey(process.env.POLYMARKET_PRIVATE_KEY as `0x${string}`),
});

const market = await client.fetchMarket({ slug: 'your-market-slug' });
const tokenId = market.outcomes.yes.tokenId!;

const response = await client.placeMarketOrder({ tokenId, side: OrderSide.BUY, amount: '10' });
if (!response.ok) throw new Error(response.message);

await client.waitForOrderFillSettlement(response);

wallet is your Polymarket account address from the profile menu, and signer is the key that controls it. On a market buy, amount is the pUSD you are willing to spend, and anything left unfilled is cancelled rather than resting. Trades match immediately but settle on-chain asynchronously, which is why the example waits before you read positions. The Python client, polymarket-client, follows the same steps with AsyncSecureClient.create and place_market_order.

What are the Polymarket CLOB rate limits?

EndpointLimit
General CLOB traffic9,000 requests per 10 seconds
/book, /price, /midpoint1,500 per 10 seconds each
/books, /prices, /midpoints500 per 10 seconds each
/prices-history1,000 per 10 seconds
POST /order, DELETE /order5,000 per 10 seconds in bursts, 120,000 per 10 minutes sustained
DELETE /cancel-all250 per 10 seconds in bursts, 6,000 per 10 minutes sustained

Read limits are applied per IP and endpoint, and traffic over them is throttled and queued rather than refused. Order and cancel requests draw on per-signer token buckets instead, and a request over that budget comes back as a 429 with a Retry-After header. The complete tables, including Gamma and the Data API, are in Polymarket API rate limits, and the ways to raise them in how to increase your Polymarket rate limit.

Should you still use py-clob-client?

Not for new work. Polymarket's documentation now points integrations to the unified SDKs, @polymarket/client on npm and polymarket-client on PyPI, both at 0.11.0 this week, and publishes a migration guide away from the earlier packages, including @polymarket/clob-client-v2 and the builder signing libraries. The unified clients cover market data, order placement, settlement and positions through one interface, and they need Node.js 24 or Python 3.11 or newer. Choosing between them is covered in the Polymarket SDK guide.

How do you read Polymarket's books alongside other venues?

The CLOB API answers for Polymarket alone. When a strategy compares Polymarket with Kalshi, Limitless or any other venue, Predictefy serves every order book in one normalized shape through one API key, across 15+ venues:

import { Predictefy } from '@predictefy/sdk';

const client = new Predictefy({ apiKey: process.env.PREDICTEFY_API_KEY });

const polymarketBook = await client.polymarket.fetchOrderBook('POLYMARKET_TOKEN_ID');
const kalshiBook = await client.kalshi.fetchOrderBook('KALSHI_OUTCOME_ID');

Both books come back in the same shape, bids and asks as probability prices with sizes, so comparison code never branches on venue. Polymarket's native token ID is accepted directly. Trading runs through client-signed execution: orders are built server side, signed in your own process and relayed, so your keys never leave your control.

Frequently Asked Questions

What is the Polymarket CLOB API?

It is Polymarket's order book and trading API at https://clob.polymarket.com. Public endpoints return order books, prices, midpoints, spreads and price history without credentials. Authenticated endpoints place, cancel and list orders and trades, using API credentials derived from a wallet signature plus HMAC-signed request headers and a signature on every order.

Do you need an API key to read Polymarket order books?

No. GET /book, /price, /midpoint, /spread and /prices-history are public, so market data needs no credentials. You only need CLOB API credentials for account actions: placing and cancelling orders, and reading your own orders and trades. Batch endpoints such as /books help you stay inside the read rate limits.

How do you create Polymarket CLOB API keys?

Sign Polymarket's ClobAuth EIP-712 message with the private key that controls your wallet, then send that signature with your address, timestamp and nonce to POST /auth/api-key. Use GET /auth/derive-api-key to recover existing credentials. Either way you receive an apiKey, a secret and a passphrase for signing private requests.

What are the Polymarket CLOB API rate limits?

General CLOB traffic allows 9,000 requests per 10 seconds, and single-book reads such as /book allow 1,500 per 10 seconds. Placing and cancelling orders allows 5,000 requests per 10 seconds in bursts and 120,000 per 10 minutes sustained, metered per signer, with throttled order requests returning 429 and Retry-After.

Should you use py-clob-client in 2026?

Not for new work. Polymarket's documentation points new integrations to its unified SDKs, @polymarket/client for TypeScript and polymarket-client for Python, and publishes a migration guide from the older CLOB clients. The unified SDKs handle wallet signatures, request signing, pagination and settlement through one typed interface.

Can you read Polymarket's order book alongside other prediction markets?

Yes. Predictefy serves order books for Polymarket, Kalshi and the rest of its 15+ prediction market venues through one API key, every book in the same normalized shape. It accepts Polymarket's native token ID directly, and its client-signed execution builds orders server side while you sign them in your own process, so keys never leave your control.