> ## Documentation Index
> Fetch the complete documentation index at: https://molelcule.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Non-Custodial Architecture: Your Keys, Your Control

> Molecule never holds assets or private keys. Venue accounts are owned by you, and Molecule routes orders only when authorised by a signed request.

Molecule is execution infrastructure, not a custodian. Your trading accounts on Polymarket, Kalshi, and other supported venues are owned and operated by you. Molecule connects to those accounts using credentials you supply at runtime and routes orders on your behalf — but Molecule never independently holds, moves, or controls your assets. This is an architectural property of the system, not a policy.

## How It Works

Molecule acts as an intermediary between your strategy and the venues you trade on. At no point in that flow does Molecule take possession of your assets or acquire the ability to act without your credentials.

**Your venue accounts belong to you.** You create and fund your own accounts on each venue. Molecule does not provision venue accounts or hold venue credentials in escrow.

**Your private key never leaves your process.** The Ed25519 private key you pass to the SDK is used locally to sign outgoing requests. It is never transmitted to Molecule's servers. Molecule stores only the corresponding public key, which it uses to verify that requests originated from your signing key.

**Molecule uses credentials you provide, not credentials it owns.** When the SDK signs a request, the signature authorises that specific API call. Molecule's infrastructure cannot independently initiate withdrawals, transfers, or any action not expressly requested by a signed API call from your process.

```python theme={"dark"}
import os
from molecule import Molecule

# The private key is loaded and used entirely within your process.
# It is never sent to Molecule's servers.
client = Molecule(
    base_url=os.environ["MOLECULE_BASE_URL"],
    key_id=os.environ["MOLECULE_KEY_ID"],
    private_key=os.environ["MOLECULE_PRIVATE_KEY"],
)
```

## What Molecule Controls

Molecule's infrastructure can perform the following actions when authorised by a valid signed request from your key:

* **Route and submit orders** to supported venues (Polymarket, Kalshi, Demo) on your behalf
* **Read your positions, balances, and fills** for portfolio and risk management
* **Cancel orders** when instructed by a signed cancel request or when the kill switch is activated

Molecule cannot move funds between accounts, withdraw assets to external addresses, create new venue accounts, or take any action that is not explicitly initiated by a signed request from your process.

## What You Control

You retain full control over all material aspects of your trading activity.

**Your Ed25519 private key.** This key is the root of your authorisation. Because it never leaves your process, revoking access is as simple as stopping the process or rotating to a new key pair.

**Your venue accounts and assets.** Balances and positions on Polymarket, Kalshi, and other venues are held in accounts you own directly. Molecule has no independent path to those assets.

**Risk limits.** You can define order-level and account-level constraints that bound Molecule's order-submission behaviour. Risk limits are enforced server-side and apply to all orders routed through your account, including those submitted programmatically.

```python theme={"dark"}
# Set a maximum notional per order and a daily loss limit
client.risk.set_limits(
    subaccount_id="sa_1",
    max_order_notional="5000",
    max_daily_loss="10000",
)
```

**The kill switch.** Activating the kill switch immediately halts all order activity for your account. No new orders will be accepted and all open orders will be cancelled until you explicitly disable it.

```python theme={"dark"}
# Halt all order activity immediately
client.risk.kill_switch(enabled=True)

# Resume order activity when ready
client.risk.kill_switch(enabled=False)
```

<Note>
  The non-custodial property follows from the key design: Molecule's servers never receive your private key, so they cannot sign requests on your behalf. This is not a policy that could change — it is a structural consequence of how Ed25519 signing works.
</Note>

<Tip>
  Configure risk limits and test the kill switch before deploying an automated strategy to a live venue. Confirm that `client.risk.limits()` returns the values you expect and that `client.risk.kill_switch(enabled=True)` correctly stops order flow in your staging environment.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.