Key format
The canonical private key format is a base64-encoded 32-byte Ed25519 seed. This is the format you should use when storing keys in environment variables, secrets managers, or configuration files. The SDK also accepts the following alternative representations, all of which resolve to the same 32-byte seed:Generate a keypair
Use thenacl library (installed as a dependency of the molecule package) to generate a new keypair and export the seed in canonical format. Register the printed public key hex with Molecule, and store the private seed securely.
Loading the key in the SDK
Pass the private seed directly to theMolecule constructor using the private_key parameter, alongside your registered key_id.
Using environment variables
The SDK reads the following environment variables if the corresponding constructor parameters are omitted:
With all three variables set, you can instantiate the client with no arguments:
Loading the key from raw bytes at runtime
If your secrets manager returns the key as raw bytes rather than a string, pass them directly:Security best practices
Store keys in environment variables or secrets managers
Store keys in environment variables or secrets managers
Never hardcode a private key in source code or configuration files that are committed to version control. Use environment variables for local development and a dedicated secrets manager (AWS Secrets Manager, GCP Secret Manager, HashiCorp Vault, or equivalent) for production workloads. Rotate access to the secrets manager itself through IAM roles rather than long-lived credentials.
Never commit keys to version control
Never commit keys to version control
A private key committed to a repository — even a private one, even for a single commit — must be considered compromised. The commit history persists indefinitely. If a key is accidentally committed, rotate it immediately: register a new public key, update your running systems, and revoke the exposed key through the Molecule dashboard.
Use separate keys per trading system
Use separate keys per trading system
Trading keys are bound to subaccounts. If you operate multiple independent trading systems, register a distinct keypair for each. This limits the blast radius of a compromised key to a single system and gives you a clear audit trail of which system generated each signed request.
Rotate keys on a regular schedule
Rotate keys on a regular schedule
To rotate a trading key:
- Generate a new Ed25519 keypair using the snippet in Key format.
- Register the new public key with Molecule through the dashboard.
- Update your running systems to use the new
key_idandprivate_key. - Verify that traffic is signing correctly with the new key.
- Deregister the old public key.
