Polymarket CLOB API (2026): Keys, Endpoints and Rate Limits

The Short Answer
The Polymarket CLOB API at https://clob.polymarket.com is the exchange's order book and trading API. Order books, prices, midpoints and spreads are public and need no credentials. Placing and managing orders takes two layers of authentication: an L1 wallet signature that creates or derives your API credentials, then L2 HMAC-SHA256 headers on every private request, with a wallet signature on each order as well. New integrations use Polymarket's unified SDKs, @polymarket/client and polymarket-client, which handle that signing. To read Polymarket's books alongside 15+ other venues, Predictefy serves them all in one normalized shape through one API key.
Key Takeaways
- Market data such as
/book,/price,/midpointand/prices-historyneeds no key at all. - API credentials come from an L1 EIP-712 signature: create them with
POST /auth/api-keyor recover them withGET /auth/derive-api-key. - Every private request carries five
POLY_headers, signed with HMAC-SHA256 over timestamp, method, path and body. - Polymarket's docs point new work to the unified SDKs, at 0.11.0 this week, with a migration guide for the older CLOB clients.
- Order endpoints have their own per-signer limits, up to 5,000 order requests per 10 seconds in bursts.
- To compare Polymarket's books with Kalshi and other venues, Predictefy serves 15+ venues in one order book shape through a single API key.
What is the Polymarket CLOB API?
CLOB stands for central limit order book, the matching engine behind every Polymarket trade. The CLOB API is how you read that book and put orders onto it. It is one of several Polymarket APIs, and each has its own job:
| API | Base URL | What it is for |
|---|---|---|
| Gamma | https://gamma-api.polymarket.com | Discovering events and markets, and their metadata |
| CLOB | https://clob.polymarket.com | Prices and order books, then placing and managing orders |
| Data | https://data-api.polymarket.com | Positions, activity and leaderboards |
| Relayer | https://relayer-v2.polymarket.com | Wallet transactions without holding POL for gas |
Live updates arrive over WebSockets: the public market channel at wss://ws-subscriptions-clob.polymarket.com/ws/market and the authenticated user channel at /ws/user on the same host. For discovery, start with the Polymarket Gamma API, and for wallet activity, the Polymarket Data API.
Two details catch most first integrations. Trading collateral is pUSD, Polymarket USD. And the CLOB identifies each outcome by a token ID, so the market you see on a web page has to be translated before you can ask for its book, which is covered in finding Polymarket market and token IDs.
Which CLOB endpoints are public?
Everything that describes the market rather than your account can be read without credentials:
| Endpoint | Returns |
|---|---|
GET /book | The order book for one outcome token |
/books | Books for many tokens in one request |
GET /price, /midpoint, /spread | The best price on a side, the midpoint and the spread |
GET /last-trade-price | The most recent trade price |
GET /prices-history | Price history for a token |
GET /tick-size, /neg-risk, /fee-rate | The tick size, negative risk flag and fee rate an order has to respect |
curl -s "https://clob.polymarket.com/book?token_id=YOUR_TOKEN_ID"
The response lists bids and asks as price and size levels for that one outcome token. The batch versions, such as /books, take a list of tokens, which matters for rate limits as soon as you watch more than a handful of markets. Reading and interpreting depth is covered in the Polymarket order book API.
How do you get Polymarket CLOB API keys?
CLOB credentials are derived from your wallet rather than issued from a dashboard. The flow is one signature and one request:
- Build Polymarket's
ClobAuthtyped data: EIP-712 domainClobAuthDomain, version 1, chain ID 137, carrying your signer address, a Unix timestamp, a nonce (0 unless you manage several credential sets) and the fixed message "This message attests that I control the given wallet". - Sign it with the private key that controls that address. That signature is your L1 signature.
- Send it in the
POLY_ADDRESS,POLY_SIGNATURE,POLY_TIMESTAMPandPOLY_NONCEheaders toPOST /auth/api-keyto create credentials, or toGET /auth/derive-api-keyto recover the ones that already exist for that address and nonce. - Store the three values that come back:
apiKey,secretandpassphrase.
curl -X POST "https://clob.polymarket.com/auth/api-key" \
-H "POLY_ADDRESS: YOUR_SIGNER_ADDRESS" \
-H "POLY_SIGNATURE: YOUR_L1_SIGNATURE" \
-H "POLY_TIMESTAMP: UNIX_SECONDS" \
-H "POLY_NONCE: 0"
Derive is the safe default in scripts, because running it twice returns the same credentials instead of creating new ones. The signer is not always the address that holds your funds, which is the most common reason for empty responses later; Polymarket wallet types explains which address goes where, and Polymarket API keys explained covers the whole credential story.
How are private CLOB requests signed?
Every private request is an L2 request. Concatenate a fresh Unix timestamp in seconds, the uppercase HTTP method, the request path and the exact serialized body, then sign that string with HMAC-SHA256 using your base64-decoded secret, and encode the result as URL-safe base64:
message = timestamp + "GET" + "/data/orders" # append the exact body on POST requests
signature = urlsafe_base64(HMAC_SHA256(base64_decode(secret), message))
| Header | Value |
|---|---|
POLY_ADDRESS | Your Polygon signer address |
POLY_SIGNATURE | The HMAC-SHA256 signature above |
POLY_TIMESTAMP | The Unix timestamp used in the signature |
POLY_API_KEY | Your credentials' apiKey |
POLY_PASSPHRASE | Your credentials' passphrase |
Placing an order needs one more signature on top. The order itself is signed by the wallet, while L2 authenticates the request that carries it. That third signature, with its rounding rules on price and size, is where most hand-rolled integrations go wrong, and it is the strongest reason to let an SDK do the work.
How do you place an order with the unified SDK?
Polymarket's unified TypeScript SDK wraps all three signatures. This is the flow from Polymarket's own quickstart, placing a small market buy:
import { createSecureClient, OrderSide } from '@polymarket/client';
import { privateKey } from '@polymarket/client/viem';
const client = await createSecureClient({
wallet: process.env.POLYMARKET_WALLET_ADDRESS as `0x${string}`,
signer: privateKey(process.env.POLYMARKET_PRIVATE_KEY as `0x${string}`),
});
const market = await client.fetchMarket({ slug: 'your-market-slug' });
const tokenId = market.outcomes.yes.tokenId!;
const response = await client.placeMarketOrder({ tokenId, side: OrderSide.BUY, amount: '10' });
if (!response.ok) throw new Error(response.message);
await client.waitForOrderFillSettlement(response);
wallet is your Polymarket account address from the profile menu, and signer is the key that controls it. On a market buy, amount is the pUSD you are willing to spend, and anything left unfilled is cancelled rather than resting. Trades match immediately but settle on-chain asynchronously, which is why the example waits before you read positions. The Python client, polymarket-client, follows the same steps with AsyncSecureClient.create and place_market_order.
What are the Polymarket CLOB rate limits?
| Endpoint | Limit |
|---|---|
| General CLOB traffic | 9,000 requests per 10 seconds |
/book, /price, /midpoint | 1,500 per 10 seconds each |
/books, /prices, /midpoints | 500 per 10 seconds each |
/prices-history | 1,000 per 10 seconds |
POST /order, DELETE /order | 5,000 per 10 seconds in bursts, 120,000 per 10 minutes sustained |
DELETE /cancel-all | 250 per 10 seconds in bursts, 6,000 per 10 minutes sustained |
Read limits are applied per IP and endpoint, and traffic over them is throttled and queued rather than refused. Order and cancel requests draw on per-signer token buckets instead, and a request over that budget comes back as a 429 with a Retry-After header. The complete tables, including Gamma and the Data API, are in Polymarket API rate limits, and the ways to raise them in how to increase your Polymarket rate limit.
Should you still use py-clob-client?
Not for new work. Polymarket's documentation now points integrations to the unified SDKs, @polymarket/client on npm and polymarket-client on PyPI, both at 0.11.0 this week, and publishes a migration guide away from the earlier packages, including @polymarket/clob-client-v2 and the builder signing libraries. The unified clients cover market data, order placement, settlement and positions through one interface, and they need Node.js 24 or Python 3.11 or newer. Choosing between them is covered in the Polymarket SDK guide.
How do you read Polymarket's books alongside other venues?
The CLOB API answers for Polymarket alone. When a strategy compares Polymarket with Kalshi, Limitless or any other venue, Predictefy serves every order book in one normalized shape through one API key, across 15+ venues:
import { Predictefy } from '@predictefy/sdk';
const client = new Predictefy({ apiKey: process.env.PREDICTEFY_API_KEY });
const polymarketBook = await client.polymarket.fetchOrderBook('POLYMARKET_TOKEN_ID');
const kalshiBook = await client.kalshi.fetchOrderBook('KALSHI_OUTCOME_ID');
Both books come back in the same shape, bids and asks as probability prices with sizes, so comparison code never branches on venue. Polymarket's native token ID is accepted directly. Trading runs through client-signed execution: orders are built server side, signed in your own process and relayed, so your keys never leave your control.
Frequently Asked Questions
What is the Polymarket CLOB API?
It is Polymarket's order book and trading API at https://clob.polymarket.com. Public endpoints return order books, prices, midpoints, spreads and price history without credentials. Authenticated endpoints place, cancel and list orders and trades, using API credentials derived from a wallet signature plus HMAC-signed request headers and a signature on every order.
Do you need an API key to read Polymarket order books?
No. GET /book, /price, /midpoint, /spread and /prices-history are public, so market data needs no credentials. You only need CLOB API credentials for account actions: placing and cancelling orders, and reading your own orders and trades. Batch endpoints such as /books help you stay inside the read rate limits.
How do you create Polymarket CLOB API keys?
Sign Polymarket's ClobAuth EIP-712 message with the private key that controls your wallet, then send that signature with your address, timestamp and nonce to POST /auth/api-key. Use GET /auth/derive-api-key to recover existing credentials. Either way you receive an apiKey, a secret and a passphrase for signing private requests.
What are the Polymarket CLOB API rate limits?
General CLOB traffic allows 9,000 requests per 10 seconds, and single-book reads such as /book allow 1,500 per 10 seconds. Placing and cancelling orders allows 5,000 requests per 10 seconds in bursts and 120,000 per 10 minutes sustained, metered per signer, with throttled order requests returning 429 and Retry-After.
Should you use py-clob-client in 2026?
Not for new work. Polymarket's documentation points new integrations to its unified SDKs, @polymarket/client for TypeScript and polymarket-client for Python, and publishes a migration guide from the older CLOB clients. The unified SDKs handle wallet signatures, request signing, pagination and settlement through one typed interface.
Can you read Polymarket's order book alongside other prediction markets?
Yes. Predictefy serves order books for Polymarket, Kalshi and the rest of its 15+ prediction market venues through one API key, every book in the same normalized shape. It accepts Polymarket's native token ID directly, and its client-signed execution builds orders server side while you sign them in your own process, so keys never leave your control.