> ## Documentation Index
> Fetch the complete documentation index at: https://docs.darknyx.trade/llms.txt
> Use this file to discover all available pages before exploring further.

> The caller's currently open orders.

# Get Open Orders

The authoritative server-side view of what is resting. After a stream gap or a restart,
reconcile against this rather than trusting local state.


## OpenAPI

````yaml api-reference/openapi/darknyx-public.yaml GET /account
openapi: 3.1.0
info:
  title: Darknyx TEE API
  version: 4.1.0
  description: |
    Public + authenticated REST and WebSocket API for the Darknyx dark pool
    TEE matching layer. One attested endpoint may expose several independently
    routed spot markets. Pairs with the v2 on-chain custody program
    (vault, program ID `C63vKvysCzX55PKraas4Wc22ijqjGJQdPC1mrzCFVWZx`).
  contact:
    name: Darknyx engineering
  license:
    name: PolyForm Perimeter License 1.0.1
    url: https://polyformproject.org/licenses/perimeter/1.0.1
servers:
  - url: https://api.darknyx.example.com
    description: Mainnet placeholder; use the origin published with a deployment.
  - url: https://api.devnet.darknyx.example.com
    description: Devnet placeholder; use the origin published with a deployment.
security: []
tags:
  - name: auth
    description: OAuth2 client-credentials and bearer-token lifecycle.
  - name: attestation
    description: |
      Darknyx engine and transport attestation plus the deployment gateway's
      separate evidence bundle. Programmatic clients verify the certificate on
      their actual connection with `/transport-attestation` before any
      credential or sensitive write. `/evidences/*` describes surrounding
      ingress infrastructure and is not a substitute for the engine check.
  - name: info
    description: |
      Application/instance metadata, boot-session id, and settlement signers.
      Verify measured identity through `/attestation`, not self-reported fields.
  - name: instruments
    description: Public market metadata.
  - name: orders
    description: Place / cancel / modify / inspect orders.
  - name: system
    description: Public engine liveness + server time (GTT slot conversion).
  - name: account
    description: Per-account open orders and preferences. Balances remain client-derived.
  - name: tree
    description: >-
      Convenience Merkle-tree mirror; clients can verify the same state on
      Solana.
  - name: transparency
    description: Public solvency snapshot + engine identity + aggregate stats.
  - name: settlement
    description: Batch settlement status (TEE → L1 tx_signature lookup).
paths:
  /account:
    get:
      tags:
        - account
      summary: The caller's open orders.
      description: |
        Returns the orders this account placed that are still in the book.
        Balances + notes are intentionally NOT returned — the TEE has no
        spending key, so clients derive those themselves from `/tree/*` + their
        own keys.
      responses:
        '200':
          description: Open-orders snapshot.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Account'
        '401':
          description: >-
            Missing / invalid / expired / revoked bearer token, or a token
            invalidated by the operator.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: The account is suspended.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - BearerAuth: []
components:
  schemas:
    Account:
      type: object
      description: |
        `GET /account` response. Returns ONLY the caller's open orders — the
        slice of account state the TEE legitimately holds (it tracks the
        order_id→account map at intake). Balances and notes are intentionally
        absent: linking an account to its notes needs the spending key, which
        the TEE never sees. Clients derive balances + spendable notes themselves
        from `/tree/*` + their own keys.
      required:
        - account_id
        - open_orders
      properties:
        account_id:
          type: string
        open_orders:
          type: array
          description: The caller's orders still resting across all market books.
          items:
            $ref: '#/components/schemas/Order'
    Error:
      type: object
      description: |
        The error envelope. Every non-2xx response renders as this shape, with
        the mapped HTTP status. Success responses are NOT enveloped (their typed
        body is returned directly). Every response — success and error — carries
        an `x-request-id` header for correlation with server logs.
      required:
        - code
        - message
      properties:
        code:
          type: integer
          description: |
            Stable numeric error code. Ranges: 1000–1099 request validation,
            1100–1199 auth, 1200–1299 conflict, 1300–1399 not found, 1400–1499
            rate limit, 5000+ server. See the Error Codes reference.

            One exception to the ranges: `1402` is returned with HTTP 503, not
            429. It signals that credential verification is momentarily at
            capacity and was refused rather than queued. Branch on the numeric
            code rather than inferring the status from its range.
          example: 1102
        message:
          type: string
          example: trading_key_signature does not verify against the canonical body
    Order:
      type: object
      description: The `GET /orders/{order_id}` status body.
      required:
        - order_id
        - symbol
        - side
        - order_type
        - status
        - amount
        - filled_quantity
        - price_limit
        - expiry_slot
        - arrival_slot
      properties:
        order_id:
          type: string
          description: 16-byte order id, hex (the one supplied at placement).
        symbol:
          type: string
          description: Canonical instrument symbol selecting the isolated market book.
        side:
          type: string
          enum:
            - bid
            - ask
        order_type:
          type: string
          enum:
            - limit
            - ioc
            - fok
        status:
          type: string
          enum:
            - empty
            - pending
            - pending_settlement
            - expired
            - cancelled
          description: |
            `pending` (resting), `pending_settlement` (reserved while the TEE
            reconciles Tx D), `expired`, `cancelled`, or `empty` (slot
            reclaimed). Definitive failures leave the order lookup surface and
            emit terminal `settlement_failed` on the authenticated orders
            channel with a reason and lock expiry slot.
        amount:
          type: integer
          format: uint64
          description: Original order size, base units.
        filled_quantity:
          type: integer
          format: uint64
          description: Cumulative filled quantity.
        price_limit:
          type: integer
          format: uint64
        expiry_slot:
          type: integer
          format: uint64
        arrival_slot:
          type: integer
          format: uint64
          description: Slot stamped on arrival; frozen for the order's life.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: |
        Short-lived (≤ 1h) bearer token from POST /auth/token.

        Expiry is EXACT — there is no grace period past `expires_in`, on REST
        or on the streaming transport. Refresh on a margin.

        A structurally valid, unexpired token is still refused when it has been
        revoked (401), when the operator has invalidated the tokens the account
        was holding (401), or when the account is suspended (403). Suspension
        also blocks issuing a new one, so re-authenticating does not clear it.

````