> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.walletstech.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.walletstech.com/_mcp/server.

# Approve a quote

POST https://api-demo.walletstech.com/trade/approve
Content-Type: application/json

Accepts an `open` quote and works the order. This is the committing step.

The quote you were shown was indicative. Approving **prices the order again**, holding the leg you fixed and moving the derived one, and the confirmed numbers come back on the top-level `cryptoAmount` / `fiatAmount` / `price`. The original stays under `quote`, so you can show the user what moved.

A trade you have already approved is not approved twice. The outcomes:

- already `completed` → the original result is **replayed**. Nothing trades again.
- still `executing` → `409`. The order is placed and the outcome is not yet confirmed — poll `/trade`, never re-approve.
- `expired`, `failed` or `cancelled` → `409`. Request a new quote.

Approving an order whose quote has lapsed marks it `expired` and answers `409` — that
holds for a trade you already approved but never settled, not just an untouched one.

A `502` or `504` means the order was rejected or the outcome is unknown. Poll `/trade` before doing anything else: a trade sitting at `executing` has not been abandoned, and re-approving it is the one thing that could trade twice.

Reference: https://docs.walletstech.com/api-reference/trading/approve-trade

## Authentication

- `Authorization` header (bearer token, required) — A 15-minute token from `/auth`. Required on every endpoint except `/auth`.

## Servers

- `https://api-demo.walletstech.com` (Sandbox. Develop and test here. Requires its own credentials., default)
- `https://api.walletstech.com` (Production — real funds, and transfers that cannot be reversed. Requires its own credentials.)

## Request

### Headers

- `X-Request-Id` (string, optional) — Correlation id. Generated if omitted, echoed on every response, and written to the audit log. **`/send` is the exception — there it is required, and it doubles as the idempotency key.**
- `X-USER-ID` (string, optional) — Optional. When present it **overrides** any `userId` in the body.

### Body (application/json)

This endpoint expects an object.

- `userId` (string, required) — 24-character hex id, returned by `/create`.
- `tradeId` (string, required) — 24-character hex id of a trade, returned by `/order` and `/sell`.

## Response

### 200

OK — the order settled, or was accepted and is being worked.

- `result` (object, required) — One trade, whichever side it is. `cryptoAmount`, `fiatAmount` and `price` are the **best known** figures: what executed if it has, else what you approved, else what was quoted. `quote` always holds the original quoted leg, so you can show both. Every amount and price is cut — not rounded — to at most 6 decimal places, with trailing zeros trimmed, so `100.00` is returned as `100`.
  - `tradeId` (string, required) — 24-character hex id of a trade, returned by `/order` and `/sell`.
  - `side` (enum, required)
    - Allowed values: `buy`, `sell`
  - `status` (enum, required) — Where the trade is in its lifecycle. `open` is the only status you can approve or cancel. `executing` is in flight — poll, never approve again. `completed`, `failed`, `expired` and `cancelled` are terminal.
    - Allowed values: `open`, `approved`, `executing`, `completed`, `failed`, `expired`, `cancelled`
  - `assetId` (enum, required) — Primary asset selector. An all-digit string (`"21"`) is accepted and normalised to an integer. - `1` — BITCOIN BTC (native, 8 decimals) - `2` — ETHEREUM ETH (native, 18 decimals) - `21` — ETHEREUM USDT (ERC20, 6 decimals) - `22` — ETHEREUM USDC (ERC20, 6 decimals) - `3` — BSC BNB (native, 18 decimals) - `31` — BSC USDT (BEP20, 18 decimals) - `32` — BSC USDC (BEP20, 18 decimals) - `4` — TRON TRX (native, 6 decimals) - `41` — TRON USDT (TRC20, 6 decimals) - `42` — TRON USDC (TRC20, 6 decimals) — not on every endpoint - `5` — POLYGON POL (native, 18 decimals) - `51` — POLYGON USDT (ERC20, 6 decimals) — not on every endpoint - `52` — POLYGON USDC (ERC20, 6 decimals) - `6` — SOLANA SOL (native, 9 decimals) - `61` — SOLANA USDT (SPL, 6 decimals) — not on every endpoint - `62` — SOLANA USDC (SPL, 6 decimals)
    - Allowed values: `1`, `2`, `21`, `22`, `3`, `31`, `32`, `4`, `41`, `42`, `5`, `51`, `52`, `6`, `61`, `62`
  - `symbol` (string, required) — Ticker of the traded asset, e.g. `BTC`.
  - `fiat` (enum, required) — Fiat currency the trade is priced in. Defaults to `USD` when omitted.
    - Allowed values: `USD`, `EUR`, `GBP`, `CAD`, `AUD`, `SEK`, `DKK`, `PLN`, `BRL`, `AED`
  - `cryptoAmount` (string, required, nullable) — Decimal string. `null` only if the stored amount could not be read.
  - `fiatAmount` (string, required, nullable) — Decimal string. `null` only if the stored amount could not be read.
  - `price` (string, required) — Unit price of one whole coin, in `fiat`.
  - `quote` (object, required) — The original quote, unchanged by approval or settlement.
    - `cryptoAmount` (string, required, nullable)
    - `fiatAmount` (string, required, nullable)
    - `price` (string, required)
    - `expiresAt` (datetime, required) — After this instant the quote has lapsed and approving it is a `409`.
  - `createdAt` (datetime, required)
  - `approvedAt` (datetime, required, nullable) — `null` until the quote is approved.
  - `completedAt` (datetime, required, nullable) — `null` until the trade reaches a terminal status.
  - `reference` (string, optional) — Present only when the fill carried one.
  - `failureReason` (string, optional) — Present only on a `failed` trade.
- `requestId` (string, required) — Echo of the inbound `X-Request-Id`, or a generated one.

## Errors

### 400 Bad Request Error

Bad Request

- `message` (string, required) — Safe, client-facing message. Internal detail never leaks here.
- `error` (string, required) — The HTTP status code, as a string.
- `requestId` (string, required) — Echo of the inbound `X-Request-Id`, or a generated one.

### 401 Unauthorized Error

Unauthorized — no bearer token, or one that does not verify. Get a fresh access token from `/refresh` (or `/auth`) and replay the request.

- `message` (string, required) — Safe, client-facing message. Internal detail never leaks here.
- `error` (string, required) — The HTTP status code, as a string.
- `requestId` (string, required) — Echo of the inbound `X-Request-Id`, or a generated one.

### 403 Forbidden Error

Forbidden — that asset is not enabled for your api client. Permanent until your operator enables it: do not retry.

- `message` (string, required) — Safe, client-facing message. Internal detail never leaks here.
- `error` (string, required) — The HTTP status code, as a string.
- `requestId` (string, required) — Echo of the inbound `X-Request-Id`, or a generated one.

### 404 Not Found Error

Not Found — no such trade for this user. Check the `tradeId`; retrying unchanged will not help.

- `message` (string, required) — Safe, client-facing message. Internal detail never leaks here.
- `error` (string, required) — The HTTP status code, as a string.
- `requestId` (string, required) — Echo of the inbound `X-Request-Id`, or a generated one.

### 409 Conflict Error

Conflict — the trade is not in a state that can be approved.

- `message` (string, required) — Safe, client-facing message. Internal detail never leaks here.
- `error` (string, required) — The HTTP status code, as a string.
- `requestId` (string, required) — Echo of the inbound `X-Request-Id`, or a generated one.

### 502 Bad Gateway Error

Bad Gateway — the order was rejected, or no price could be obtained. `Order rejected: …` means nothing traded and the trade is now `failed`; request a new quote. Otherwise retry with backoff.

- `message` (string, required) — Safe, client-facing message. Internal detail never leaks here.
- `error` (string, required) — The HTTP status code, as a string.
- `requestId` (string, required) — Echo of the inbound `X-Request-Id`, or a generated one.

### 503 Service Unavailable Error

Service Unavailable — trading is not available for that asset right now. Do not retry in a tight loop; contact your operator if it persists.

- `message` (string, required) — Safe, client-facing message. Internal detail never leaks here.
- `error` (string, required) — The HTTP status code, as a string.
- `requestId` (string, required) — Echo of the inbound `X-Request-Id`, or a generated one.

### 504 Gateway Timeout Error

Gateway Timeout — the outcome is **unknown**. The trade stays `executing`. Poll `/trade`; do not approve again.

- `message` (string, required) — Safe, client-facing message. Internal detail never leaks here.
- `error` (string, required) — The HTTP status code, as a string.
- `requestId` (string, required) — Echo of the inbound `X-Request-Id`, or a generated one.

## Examples

### Approved and filled

**Request**

```json
{
  "userId": "60f7c2d3e4f5a6b7c8d9e0f1",
  "tradeId": "6a1f0c2d3e4f5a6b7c8d9e0f"
}
```

**Response**

```json
{
  "result": {
    "tradeId": "6a1f0c2d3e4f5a6b7c8d9e0f",
    "side": "buy",
    "status": "completed",
    "assetId": 1,
    "symbol": "BTC",
    "fiat": "USD",
    "cryptoAmount": "0.001544",
    "fiatAmount": "100",
    "price": "64733.64",
    "quote": {
      "cryptoAmount": "0.001546",
      "fiatAmount": "100",
      "price": "64665.47",
      "expiresAt": "2026-08-16T10:31:00.000Z"
    },
    "createdAt": "2026-08-16T10:30:00.000Z",
    "approvedAt": "2026-08-16T10:30:22.000Z",
    "completedAt": "2026-08-16T10:30:23.000Z"
  },
  "requestId": "b7a1f0c2-3d4e-4a5b-9c6d-7e8f90a1b2c3"
}
```

**SDK Code**

```python Approved and filled
import requests

url = "https://api-demo.walletstech.com/trade/approve"

payload = {
    "userId": "60f7c2d3e4f5a6b7c8d9e0f1",
    "tradeId": "6a1f0c2d3e4f5a6b7c8d9e0f"
}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript Approved and filled
const url = 'https://api-demo.walletstech.com/trade/approve';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"userId":"60f7c2d3e4f5a6b7c8d9e0f1","tradeId":"6a1f0c2d3e4f5a6b7c8d9e0f"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Approved and filled
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api-demo.walletstech.com/trade/approve"

	payload := strings.NewReader("{\n  \"userId\": \"60f7c2d3e4f5a6b7c8d9e0f1\",\n  \"tradeId\": \"6a1f0c2d3e4f5a6b7c8d9e0f\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Approved and filled
require 'uri'
require 'net/http'

url = URI("https://api-demo.walletstech.com/trade/approve")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"userId\": \"60f7c2d3e4f5a6b7c8d9e0f1\",\n  \"tradeId\": \"6a1f0c2d3e4f5a6b7c8d9e0f\"\n}"

response = http.request(request)
puts response.read_body
```

```java Approved and filled
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api-demo.walletstech.com/trade/approve")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"userId\": \"60f7c2d3e4f5a6b7c8d9e0f1\",\n  \"tradeId\": \"6a1f0c2d3e4f5a6b7c8d9e0f\"\n}")
  .asString();
```

```php Approved and filled
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api-demo.walletstech.com/trade/approve', [
  'body' => '{
  "userId": "60f7c2d3e4f5a6b7c8d9e0f1",
  "tradeId": "6a1f0c2d3e4f5a6b7c8d9e0f"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp Approved and filled
using RestSharp;

var client = new RestClient("https://api-demo.walletstech.com/trade/approve");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"userId\": \"60f7c2d3e4f5a6b7c8d9e0f1\",\n  \"tradeId\": \"6a1f0c2d3e4f5a6b7c8d9e0f\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Approved and filled
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "userId": "60f7c2d3e4f5a6b7c8d9e0f1",
  "tradeId": "6a1f0c2d3e4f5a6b7c8d9e0f"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api-demo.walletstech.com/trade/approve")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Approved, settling

**Request**

```json
{
  "userId": "60f7c2d3e4f5a6b7c8d9e0f1",
  "tradeId": "6a1f0c2d3e4f5a6b7c8d9e11"
}
```

**Response**

```json
{
  "result": {
    "tradeId": "6a1f0c2d3e4f5a6b7c8d9e11",
    "side": "sell",
    "status": "approved",
    "assetId": 1,
    "symbol": "BTC",
    "fiat": "USD",
    "cryptoAmount": "0.25",
    "fiatAmount": "16183.41",
    "price": "64733.64",
    "quote": {
      "cryptoAmount": "0.25",
      "fiatAmount": "16166.36",
      "price": "64665.47",
      "expiresAt": "2026-08-16T10:31:00.000Z"
    },
    "createdAt": "2026-08-16T10:30:00.000Z",
    "approvedAt": "2026-08-16T10:30:22.000Z",
    "completedAt": null
  },
  "requestId": "b7a1f0c2-3d4e-4a5b-9c6d-7e8f90a1b2c3"
}
```

**SDK Code**

```python Approved, settling
import requests

url = "https://api-demo.walletstech.com/trade/approve"

payload = {
    "userId": "60f7c2d3e4f5a6b7c8d9e0f1",
    "tradeId": "6a1f0c2d3e4f5a6b7c8d9e11"
}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript Approved, settling
const url = 'https://api-demo.walletstech.com/trade/approve';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"userId":"60f7c2d3e4f5a6b7c8d9e0f1","tradeId":"6a1f0c2d3e4f5a6b7c8d9e11"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Approved, settling
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api-demo.walletstech.com/trade/approve"

	payload := strings.NewReader("{\n  \"userId\": \"60f7c2d3e4f5a6b7c8d9e0f1\",\n  \"tradeId\": \"6a1f0c2d3e4f5a6b7c8d9e11\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Approved, settling
require 'uri'
require 'net/http'

url = URI("https://api-demo.walletstech.com/trade/approve")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"userId\": \"60f7c2d3e4f5a6b7c8d9e0f1\",\n  \"tradeId\": \"6a1f0c2d3e4f5a6b7c8d9e11\"\n}"

response = http.request(request)
puts response.read_body
```

```java Approved, settling
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api-demo.walletstech.com/trade/approve")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"userId\": \"60f7c2d3e4f5a6b7c8d9e0f1\",\n  \"tradeId\": \"6a1f0c2d3e4f5a6b7c8d9e11\"\n}")
  .asString();
```

```php Approved, settling
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api-demo.walletstech.com/trade/approve', [
  'body' => '{
  "userId": "60f7c2d3e4f5a6b7c8d9e0f1",
  "tradeId": "6a1f0c2d3e4f5a6b7c8d9e11"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp Approved, settling
using RestSharp;

var client = new RestClient("https://api-demo.walletstech.com/trade/approve");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"userId\": \"60f7c2d3e4f5a6b7c8d9e0f1\",\n  \"tradeId\": \"6a1f0c2d3e4f5a6b7c8d9e11\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Approved, settling
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "userId": "60f7c2d3e4f5a6b7c8d9e0f1",
  "tradeId": "6a1f0c2d3e4f5a6b7c8d9e11"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api-demo.walletstech.com/trade/approve")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```