# Hashlock Markets - [Hashlock Markets](https://docs.hashlock.markets/index.md): Non-custodial atomic P2P cross-chain swaps: Bitcoin to EVM, TRON and Solana, via sealed RFQ and HTLC. - [Quickstart](https://docs.hashlock.markets/quickstart.md): From an API key to a settled swap over the /v1 REST API. - [How it works](https://docs.hashlock.markets/concepts/how-it-works.md): Sealed RFQ, negotiation thread, agreed swap, two HTLC legs, and the secret that settles both. - [HTLC and timelocks](https://docs.hashlock.markets/concepts/htlc-and-timelocks.md): One sha256 hashlock on every chain, and asymmetric timelocks so nobody holds a free option. - [Roles](https://docs.hashlock.markets/concepts/roles.md): Taker, maker, initiator and counterparty — and which leg each one funds. - [Settlement by chain](https://docs.hashlock.markets/concepts/settlement-by-chain.md): How the HTLC escrow is built on Bitcoin, EVM, TRON and Solana. - [Non-custodial guarantees](https://docs.hashlock.markets/concepts/non-custodial.md): What the server and the keeper can and cannot do with your funds. - [API keys](https://docs.hashlock.markets/guides/api-keys.md): Minting, scopes, expiry, limits, and proving wallets. - [Settle a leg](https://docs.hashlock.markets/guides/settle-a-leg.md): Build unsigned fund, claim and refund transactions, sign them yourself, and broadcast. - [Webhooks](https://docs.hashlock.markets/guides/webhooks.md): Swap lifecycle events pushed to your HTTPS endpoint, signed with HMAC-SHA256. - [Maker feed](https://docs.hashlock.markets/guides/maker-feed.md): A WebSocket that streams the RFQs you can quote, and takes your quotes back. - [Rate limits and idempotency](https://docs.hashlock.markets/guides/rate-limits-and-idempotency.md): RateLimit headers, 429 handling, and safe retries with Idempotency-Key. - [MCP server](https://docs.hashlock.markets/agents/mcp.md): Connect Claude or any MCP client to Hashlock Markets: hosted by URL, or local over stdio. - [Agents without a human](https://docs.hashlock.markets/agents/agents-without-a-human.md): An agent that holds its own wallet mints its own API key by signature, then trades over MCP or REST. - [Introduction](https://docs.hashlock.markets/api-reference/introduction.md): Servers, authentication and conventions of the /v1 REST API. - [Verify the key, list its scopes and the wallets attached to its account](https://docs.hashlock.markets/api-reference/verify-the-key-list-its-scopes-and-the-wallets-attached-to-its-account.md) - [Start minting an API key: a single-use nonce (5 minutes). No key needed.](https://docs.hashlock.markets/api-reference/start-minting-an-api-key:-a-single-use-nonce-5-minutes-no-key-needed.md) - [Mint an API key with a wallet signature — no browser, no key needed (agents start here)](https://docs.hashlock.markets/api-reference/mint-an-api-key-with-a-wallet-signature-—-no-browser-no-key-needed-agents-start-here.md): Sign, with the wallet, a message that says `create an API key`, names the address and carries a nonce from `GET /v1/keys/nonce`. Optional lines `Key name: ` and `Scopes: read, taker` (default all three) decide the key — they are read from the signed text only. The key belongs to the account th… - [A single-use nonce to put in the message you are about to sign](https://docs.hashlock.markets/api-reference/a-single-use-nonce-to-put-in-the-message-you-are-about-to-sign.md): Expires shortly and is consumed by the first proof that presents it. It is a LINK nonce: it cannot be spent at a login endpoint, so the signature you collect is not a session. - [Prove a EVM wallet this account holds](https://docs.hashlock.markets/api-reference/prove-a-evm-wallet-this-account-holds.md): Sign with personal_sign / EIP-191 a message carrying `Hashlock Markets`, the words `link this wallet`, the address itself and a nonce from `GET /v1/wallets/nonce`. Needed before this account can create an order that GIVES a EVM asset. The proof is recorded as a proof — it does not become the account… - [Prove a TRON wallet this account holds](https://docs.hashlock.markets/api-reference/prove-a-tron-wallet-this-account-holds.md): Sign with signMessageV2 a message carrying `Hashlock Markets`, the words `link this wallet`, the address itself and a nonce from `GET /v1/wallets/nonce`. Needed before this account can create an order that GIVES a TRON asset. The proof is recorded as a proof — it does not become the account's payout… - [Prove a Solana wallet this account holds](https://docs.hashlock.markets/api-reference/prove-a-solana-wallet-this-account-holds.md): Sign with ed25519 signMessage, base58 a message carrying `Hashlock Markets`, the words `link this wallet`, the address itself and a nonce from `GET /v1/wallets/nonce`. Needed before this account can create an order that GIVES a Solana asset. The proof is recorded as a proof — it does not become the… - [Prove a Bitcoin wallet this account holds](https://docs.hashlock.markets/api-reference/prove-a-bitcoin-wallet-this-account-holds.md): Sign with BIP-322 (UniSat / OKX `signMessage(msg, 'bip322-simple')`) a message carrying `Hashlock Markets`, the words `link this wallet`, and a nonce from `GET /v1/wallets/nonce`. Needed before this account can create an order that GIVES a Bitcoin asset. The proof is recorded as a proof — it does no… - [Withdraw a proof this account made](https://docs.hashlock.markets/api-reference/withdraw-a-proof-this-account-made.md): Removes the address from what this account can trade from. Reach for it after rotating a leaked key: the proofs made with that key outlive it otherwise. Proofs only — a login address is not one and is not removable here. Putting a proof back needs that wallet to sign again. - [Enabled asset registry](https://docs.hashlock.markets/api-reference/enabled-asset-registry.md) - [Order book (open RFQs to quote) — cursor-paginated](https://docs.hashlock.markets/api-reference/order-book-open-rfqs-to-quote-—-cursor-paginated.md) - [Create an RFQ (scope: taker)](https://docs.hashlock.markets/api-reference/create-an-rfq-scope:-taker.md) - [Get an RFQ](https://docs.hashlock.markets/api-reference/get-an-rfq.md) - [Withdraw your own RFQ (scope: taker)](https://docs.hashlock.markets/api-reference/withdraw-your-own-rfq-scope:-taker.md): Only before a deal is agreed, and only your own order — the id alone does not cancel someone else's. - [Quote an RFQ (scope: maker) — opens a settlement thread](https://docs.hashlock.markets/api-reference/quote-an-rfq-scope:-maker-—-opens-a-settlement-thread.md) - [Get a negotiation thread (messages, current terms)](https://docs.hashlock.markets/api-reference/get-a-negotiation-thread-messages-current-terms.md) - [Propose a new price on a thread](https://docs.hashlock.markets/api-reference/propose-a-new-price-on-a-thread.md) - [Accept the counterparty's pending price](https://docs.hashlock.markets/api-reference/accept-the-counterpartys-pending-price.md): Name the price you are accepting: it is refused if a newer counter has replaced it since you read the thread. - [Accept the current terms — COMMITS, and cannot be undone](https://docs.hashlock.markets/api-reference/accept-the-current-terms-—-commits-and-cannot-be-undone.md): Name the price you are accepting: it is refused if the terms moved since you read the thread. The initiator (funds the long leg) also passes hashlock = sha256(secret); when BOTH sides accept, the swap is created. - [List your swaps — cursor-paginated](https://docs.hashlock.markets/api-reference/list-your-swaps-—-cursor-paginated.md) - [Swap lifecycle status](https://docs.hashlock.markets/api-reference/swap-lifecycle-status.md) - [Set a settlement address](https://docs.hashlock.markets/api-reference/endpoints/set-swap-address.md) - [Build UNSIGNED transaction(s) to fund a leg — sign with your own key/HSM, then broadcast](https://docs.hashlock.markets/api-reference/build-unsigned-transactions-to-fund-a-leg-—-sign-with-your-own-keyhsm-then-broadcast.md): EVM: sign every returned transaction from the returned `from` address — the leg refund address. The factory refuses any other sender, and the escrow refunds to it. - [Build UNSIGNED claim (reveals the secret) — body: { secret: 32-byte hex }](https://docs.hashlock.markets/api-reference/build-unsigned-claim-reveals-the-secret-—-body:-.md) - [Build UNSIGNED refund (after the timelock)](https://docs.hashlock.markets/api-reference/build-unsigned-refund-after-the-timelock.md) - [Relay a client-signed transaction](https://docs.hashlock.markets/api-reference/relay-a-client-signed-transaction.md) - [List your webhooks (secret not shown)](https://docs.hashlock.markets/api-reference/list-your-webhooks-secret-not-shown.md) - [Register a webhook](https://docs.hashlock.markets/api-reference/endpoints/register-webhook.md) - [Delete a webhook](https://docs.hashlock.markets/api-reference/delete-a-webhook.md) - [Send a test delivery to a webhook](https://docs.hashlock.markets/api-reference/send-a-test-delivery-to-a-webhook.md) ## OpenAPI Specs - [openapi](https://dev.hashlock.markets/api/v1/openapi.json)