FUNCTOR API

API reference · testnet

Rules and limits

The limits every client must stay within, what happens when it doesn't, and what is not allowed. The numbers on this page are read from the code that enforces them.

Terms of use

  1. The API is open: no key or account is needed. Reads need nothing; actions need a valid signature from the account or its approved session key.
  2. The testnet has no value and no service-level agreement. It can pause, change or reset at any time.
  3. Do not evade a limit by spreading requests over several IP addresses or accounts.
  4. Do not load-test the public node. Ask on Telegram first.
  5. Do not script the faucet across many addresses.
  6. Never send a private key to the API. Requests carry signatures, never keys.

Breaking these rules gets the IP addresses involved blocked at Cloudflare.

IP limits (HTTP)

Every IP address has a budget of 1,200 weight per minute, refilled continuously (20 per second). Each request costs its weight:

RequestWeight
POST /exchange1 + floor(batch length ÷ 40). Single actions: 1
POST /info: candles, userFills, recentTrades, tokenDetails, vaultDetails, vaults2
POST /info: every other type1
GET /status, POST /faucet, anything else1

Hyperliquid charges 2 and 20 for info requests. Functor charges 1 and 2 because its web app polls over HTTP; one browser tab uses about 150 a minute at most.

Address limits (actions)

Each account has a request budget for /exchange actions, whichever key signs them (a session key spends its owner's budget):

Check the numbers with userRateLimit.

Open orders

Enforced by the chain itself, so every validator applies it:

WebSocket limits

LimitPer IP
Open connections10
New connections30 per minute
Subscriptions, all connections1,000
Subscriptions on one connection20
Distinct users in user subscriptions10
Messages sent to the node2,000 per minute

A refused subscription gets an error message; the connection stays open.

Faucet

10,000 mock USDC and 1,000 test FCTR per address, once every 24 hours, and at most 5 different addresses per IP per 24 hours.

Nonces

Every action carries a nonce. Use the current time in milliseconds. The node keeps the 100 highest nonces per signer (Hyperliquid's rule). A nonce must:

Because a nonce works only once, resending a request after a timeout is safe: a duplicate is refused with nonce already used.

When you are limited

HTTP limits answer 429 with a Retry-After header (seconds) and a JSON body:

{
  "status": "err",
  "response": "rate limited: 1200 request weight per minute per IP; retry in 1 s"
}

Requests that set their own CF-Connecting-IP header are refused by Cloudflare with 403.

Generated from the node's source code by tools/api-docs.mjs; examples are real responses from https://api.functorfund.com. Questions: Telegram. Changes: News.

On this page

Terms of useIP limitsAddress limitsOpen ordersWebSocket limitsFaucetNoncesWhen you are limited