Read a Uniswap V3 token price from The Graph and return it ONLY if four checks pass: the indexer signed the exact bytes that arrived, that signer resolves on chain to an indexer with stake, the reading is a usable price (a verified signature over a GraphQL error or a zero is not a price), and the price's own age is measured apart from the subgraph head's age — a head can be fresh while the price it carries is a year old. On refusal no price is returned and the answer names both the check that stopped it (`stage`) and that check's own reason (`cause`): `price_absent_or_zero`, `graphql_errors` and `price_stale` are three different problems with three different fixes. Costs one cent in USDC on Base per query and needs X402_PRIVATE_KEY set; without that key it refuses `no_payer_key` and spends nothing. Name the token by `token_address` when you can: a ticker is not a key, and this subgraph holds several tokens called WETH. With neither address nor ticker it returns the most recently priced tokens, filtered to those that actually carry a price. Runs OUTSIDE the enclave.
List the venues this Signer can sign trades for. Returns the venue id, asset class (perp / spot / margin), and auth scheme (hmac / eip712 / ed25519). Read-only static manifest — does NOT need the Signer gateway to be reachable. Call this first to discover what's signable.
Fetch the Signer enclave's AWS Nitro attestation document with a FRESH NONCE and verify it locally, with no dependencies and no trust in this tool's own summary. Five named checks are returned and any of them can fail: the document decodes as a COSE_Sign1 (document_readable), the nonce inside it is the one just sent (nonce_echoed), its root certificate is the pinned AWS Nitro root (root_pinned), the certificate chain leads to that root (chain_verified), and the hardware signature covers these exact bytes (signature_verified). PCR0/PCR1/PCR2 are read out of the SIGNED bytes, not from a field beside them. WHAT THIS DOES NOT ESTABLISH: that PCR0 corresponds to the published source — rebuild the image from the public clone and compare, or query the on-chain PCR0 registry; and nothing about any past signature, since an attestation speaks about the code that answered this request. If any check is false, treat the document as no evidence rather than weak evidence.
Return equity, free margin, and open positions for a venue. Read-only (does not sign anything that mutates state). Use BEFORE place_order to confirm the account has margin. Requires SIGNER_API_TOKEN.
Place a single order on the named venue. Accepts canonical symbol (BTC / BTCUSDT) and qty in BASE ASSET; translates both to the venue's native format (okx sizes in contracts) and echoes the translation in the result — always check `translation.sent` to see what actually hit the exchange. The Signer enclave signs the venue-native payload using a key that has never been exported. Policy enforced server-side: orders that exceed per-asset caps are rejected by the enclave before signing. Returns the venue's order_id on success. Side effect: real or testnet trade depending on venue env.
Place a 2-leg MARKET hedge ATOMICALLY: both legs are signed inside the enclave (if either leg fails policy, NOTHING executes), then the gateway fires both venue calls in parallel server-side — minimal leg gap, works even when a venue geo-blocks your residential IP. Accepts canonical symbol (BTC) + qty in BASE ASSET per leg (contract venues converted, translation echoed per leg). Result status: executed (both venue receipts accepted) | partial (ONE leg live — naked position, repair via legs[].outcome) | unknown (a receipt was lost — that leg MAY be live: reconcile with get_account BEFORE any retry, never blind-retry) | failed (both rejected, safe to retry). Market orders only in v1. Side effect: real or testnet trades.
Cancel an outstanding order by its venue order_id. Signed inside the enclave just like place_order. Returns the cancellation receipt from the venue. Idempotent: cancelling a non-existent / already-filled order returns ok=false with a reason from the venue.