> ## Documentation Index
> Fetch the complete documentation index at: https://docs.0xinsider.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Pre-game sides

> List upcoming Polymarket games ranked by the side S, A, and B wallets hold most of the graded money on.

Use this to rank moneyline and prop markets before kickoff. Every row is a market where graded wallets sit heavily on one side, and every raw number behind that reading is in the row, so you can re-rank them yourself. It is not the Pick of the Day selector, and the markets it turns away are measured on [Pre-game side observations](/api-reference/endpoint/get-pre-game-side-observations).

`GET /api/v1/sports-edge-signals` is the deprecated spelling of this path. It stays live and answers the same body, and its responses carry `Deprecation` and `Link` headers that name this path as the successor.

## Parameters

| Parameter       | Description                                                                                                                                                                                 |
| --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `category`      | A sport bucket such as `Basketball`, `Tennis`, or `Soccer`. A raw Polymarket value such as `NBA` resolves to its bucket. A value that is not a sport returns an empty list.                 |
| `horizon_hours` | How far ahead to look for kickoffs, from 1 to 48 hours. The default is 12, and a value outside the range is clamped rather than refused. Games that had already started are never included. |
| `min_grade`     | The best [grade](/concepts/grades) that must be present on the heavy side: `S`, `A`, or `B` (the default). `A` needs an S or an A wallet there. `C`, `D`, and `F` answer `400`.             |
| `limit`         | How many markets to return, from 1 to 100. The default is 20, and a value outside the range is clamped rather than refused.                                                                 |
| `cursor`        | The `next_cursor` from the previous response.                                                                                                                                               |

## Key response fields

| Field                                             | Meaning                                                                                                                                                                                                                                                                     |
| ------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `ranked_at`                                       | When the server computed the snapshot this row came from. Every row in one response shares it, and it is never your request time. The row also carries the same value as the deprecated `signal_created_at`.                                                                |
| `game_start_time`                                 | Kickoff, in UTC. It was in the future when the snapshot was computed. A snapshot is served for about 180 seconds, so a kickoff can be up to about 180 seconds past by the time you read it.                                                                                 |
| `side`, `piled_outcome_index`                     | The display label and the column number of the side holding most of the graded money: `0` is the YES column, `1` is the NO column. Neither names a team on its own, so read them together with `title`. The row also carries the same label as the deprecated `piled_side`. |
| `sharp_pct`                                       | That side's share of the graded dollars in the market, above 0.5 and at most 1.                                                                                                                                                                                             |
| `backed_sharp_usd`                                | The graded dollars on that side, in USD. Size a position from this number, not from `sharp_pct`.                                                                                                                                                                            |
| `s_count`, `a_count`, `b_count`, `graded_holders` | How many S, A, and B wallets hold that side, and the sum of the three.                                                                                                                                                                                                      |
| `backing_score`                                   | `(5*s + 4*a + 3*b) * sharp_pct`, over those same counts: graded holders times the share of their money on the side. The row also carries the same value as the deprecated `conviction_score`.                                                                               |
| `side_share`                                      | That side's share of the graded dollars as a signed number, from -1 to 1. The row also carries the same value as the deprecated `smart_score`.                                                                                                                              |
| `directional_confidence`                          | The share of that side's graded dollars held by wallets backing one team across the whole game, from 0 to 1. It is `null` when the read did not run, or ran and classified nobody.                                                                                          |
| `directional_rank_score`                          | The sort key: `backing_score * (1 + 0.25 * directional_confidence)`. It equals `backing_score` when `directional_confidence` is `null`.                                                                                                                                     |
| `category_skill`                                  | Evidence about how these wallets have done in this sport. It never changes which markets appear, their order, their `rank`, or the cursor.                                                                                                                                  |
| `meta.ranking_source`                             | `live` normally. `db_only` means the live holder read was unavailable and a weaker fallback ranking was used instead.                                                                                                                                                       |
| `meta.directional_source`                         | `live` normally. `degraded` means the one-way read failed, so nothing was measured and the ranking fell back to `backing_score` alone.                                                                                                                                      |

Rows are sorted by `directional_rank_score`, then `backing_score`, then `side_share`, then `condition_id`.

A healthy response comes from a snapshot cached for about 180 seconds. When `meta.ranking_source` or `meta.directional_source` reports a degraded input, that snapshot is cached for about 30 seconds instead, so it recovers faster.

## When a cursor expires

A cursor stops working once the snapshot it came from is replaced. It then answers `400` with `error.reason` `cursor_expired` and `error.param` `cursor`. Request the first page again, and expect no `Retry-After`, because waiting does not fix it.

A cursor the server cannot read at all is a different `400`. It carries `error.param` `cursor` and no `error.reason`.

## Example

```bash theme={null}
curl -H "Authorization: Bearer $OXINSIDER_API_KEY" \
  "https://api.0xinsider.com/api/v1/sports/pre-game-sides?category=Basketball&horizon_hours=12&min_grade=B&limit=10"
```

## What it does not return

* A game that had already started when the snapshot was computed. Live markets are on [Pre-game side observations](/api-reference/endpoint/get-pre-game-side-observations).
* A market where the money is split near 50/50. A market with no clear heavy side is left out.
* Reconstructed history. Coverage starts at launch and counts only the taker buys that crossed 0xinsider's whale-alert size thresholds.
* The Pick of the Day. That ranker is editorial and separate from this one.

## Caching

Send the `ETag` from a response back in an `If-None-Match` header. If the list has not changed, you get `304 Not Modified` with an empty body.


## OpenAPI

````yaml GET /api/v1/sports/pre-game-sides
openapi: 3.1.0
info:
  x-generated-rate-limit-policy-from: web/src/lib/rate-limit-facts.ts via web/scripts/generate-api-policy.ts
  title: 0xinsider API
  description: >-
    Follow provider-exposed large-trade activity from Polymarket. Polymarket
    wallet-attributed trades can add grades, P&L, strategy, and diagnostic-score
    context when sufficient source data exists. Fields can be null or
    unavailable. Normal API requests use a 30-second server timeout that returns
    HTTP 408 Request Timeout with the standard error envelope (error.code
    request_timeout) when exceeded. Every /api/v1 failure answers that envelope,
    including a body that is not JSON or does not fit the request schema (400
    invalid_body), a query or path value that does not parse (400 invalid_query,
    invalid_path), a missing Content-Type: application/json (415
    unsupported_media_type), a body over 1048576 bytes (413 payload_too_large)
    and a method the path does not serve (405 method_not_allowed), each with
    error.param naming the field where one is known and meta.request_id equal to
    X-Request-Id. Unknown query names are ignored by default and reported in
    X-Query-Ignored, while X-Effective-Query lists the normalized names and
    values applied using form-urlencoded decoding, where + is a space; strict
    mode returns 400 bad_request with error.reason unknown_query_parameter
    before the handler runs, including for an unknown name with an incomplete
    percent escape. Public REST /api/v1/* endpoints, excluding /api/v1/mcp, use
    Bearer-token based non-credentialed browser CORS: any Origin may call with
    Authorization, Content-Type, If-None-Match, Idempotency-Key, Mcp-Session-Id,
    Mcp-Protocol-Version, Last-Event-Id, and X-Query-Validation request headers.
    X-Query-Validation: strict opts into rejecting unknown query names; the
    default remains compatible. Remote MCP at /api/v1/mcp is non-credentialed,
    but still validates Origin against the 0xinsider/localhost allowlist per MCP
    Streamable HTTP DNS-rebinding guidance. Successful browser CORS preflight
    responses advertise Access-Control-Max-Age: 86400. Browser JavaScript may
    read RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, the legacy
    X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, Retry-After,
    ETag, X-Request-Id, X-Request-Cost, X-Usage-Accounting,
    X-Batch-RateLimit-Limit, X-Batch-RateLimit-Remaining,
    X-Batch-RateLimit-Reset, Mcp-Session-Id, X-Mcp-Error-Code, X-Query-Ignored,
    and X-Effective-Query response headers. Rate-limit headers describe the
    budget a request was counted against: the API key's per-minute window on an
    authenticated call, and the per-IP budget on a public route or on a refused
    credential (401, 402, 403, 423), so a client looping on a bad or lapsed key
    still sees how much room it has. Conditional GET: these operations return a
    weak ETag and answer If-None-Match with 304 Not Modified and an empty body:
    GET /api/v1/health, GET /api/v1/insider-radar, GET
    /api/v1/insider-radar/{id}, GET /api/v1/large-positions, GET
    /api/v1/leaderboard, GET /api/v1/leaderboard/trending, GET
    /api/v1/market/{condition_id}/candles, GET
    /api/v1/market/{condition_id}/flow, GET /api/v1/market/{condition_id}/intel,
    GET /api/v1/market/{condition_id}/snapshot, GET /api/v1/markets/explore, GET
    /api/v1/markets/sharp-money-flows, GET /api/v1/markets/smart-money-flows,
    GET /api/v1/pick-of-the-day, GET /api/v1/pick-of-the-day/archive, GET
    /api/v1/positions, GET /api/v1/sports-edge-observations, GET
    /api/v1/sports-edge-signals, GET /api/v1/trader/{address}, GET
    /api/v1/trader/{address}/context, GET /api/v1/trader/{address}/pnl, GET
    /api/v1/trader/{address}/position-timeline, GET
    /api/v1/traders/{trader}/position-timeline, GET /api/v1/whale-trades, GET
    /api/v1/whale-trades/history, GET /api/v1/whale-trades/{id}, GET
    /api/v1/whale-trades/{id}/counterparties/executions, GET
    /api/v1/whale-trades/{id}/counterparties/executions/{execution_id}/makers.
    Credentialed first-party routes such as /api/keys, /api/billing, and auth
    endpoints remain restricted to configured 0xinsider origins. Protected V1
    responses, except the zero-cost /api/v1/usage route, after handler execution
    carry X-Usage-Accounting: persisted, failed, or unknown. This reports the
    usage-record write; it does not change the handler result. Do not replay a
    successful mutation to repair an unknown usage record. Before execution,
    unavailable accounting capacity returns HTTP 503 with
    error.reason=request_accounting_unavailable; honor Retry-After. Public API
    responses add the browser-readable Server-Timing header: Processing time in
    milliseconds, for example api;dur=12.345. Includes API authentication, quota
    admission, handler work and response construction. Excludes network transit
    and streamed body or export-file transfer. The engineering budget is
    strictly below 250 ms; this header reports observations, not a latency
    guarantee or a new timeout.
  version: 1.0.0
  contact:
    name: 0xinsider
    email: support@0xinsider.com
    url: https://0xinsider.com
servers:
  - url: https://api.0xinsider.com
    description: >-
      Production (live data). Authenticate with a live key (oxi_sk_live_...);
      requires an active Pro subscription. A sandbox key (oxi_sk_test_...) is
      answered with 401 invalid_api_key and error.reason sandbox_api_key.
  - url: https://0xinsider.com/sandbox
    description: >-
      Sandbox. No credential required and no production data: every documented
      operation answers with its documented example or a deterministic sample of
      its response schema. GET /api/v1/stream is the one exclusion and answers
      400 there, because a Server-Sent Events stream is a live connection rather
      than a body. Add ?sandbox_status=<code> to receive one of the error
      responses the operation documents (for example 429 with Retry-After).
      Documented query parameters and JSON request bodies are checked against
      this document, the two context.md routes answer 200 text/markdown, GET
      /api/v1/trader/{address}/export/download answers its 302 with a Location
      the sandbox serves itself rather than an object store, and nothing is
      stored between requests. A sandbox key (oxi_sk_test_..., issued with no
      account by POST https://api.0xinsider.com/api/v1/agents/register) is
      optional: on an operation that requires a credential, a well-formed key is
      answered with X-Oxi-Sandbox-Key: valid and a malformed one with 401
      invalid_api_key.
security:
  - bearerAuth: []
  - oauth2:
      - read
tags:
  - name: Traders
    description: Traders, batch lookups, timelines, and export readiness.
  - name: Positions
    description: Current prediction-market position snapshots from backend-owned mirrors.
  - name: Large Positions
    description: Largest current open positions from graded traders (Polymarket-only).
  - name: Large trades
    description: Recent and historical large trades.
  - name: Leaderboard
    description: Ranked trader discovery and category/strategy leaderboards.
  - name: Pick of the Day
    description: >-
      One sourced sharp-money call a day: the side profitable wallets are
      backing, with pre-game odds, the holders, and the track record.
  - name: Games
    description: >-
      Sports and esports games: both sides, schedules, provider status and the
      Polymarket markets linked to each game.
  - name: Markets
    description: Market search, discovery, snapshots, and sharp-money flow.
  - name: Content
    description: Search across 0xinsider editorial content.
  - name: Suspicious trades
    description: Trades whose recorded suspicion score meets the live flag threshold.
  - name: Insider Radar
    description: >-
      Deprecated spelling of Suspicious trades; both operations stay live as
      aliases.
  - name: Events
    description: Durable public event replay streams.
  - name: Streaming
    description: Resumable real-time Server-Sent Events stream of live feed envelopes.
  - name: Webhooks
    description: Signed builder webhook destinations and delivery controls.
  - name: Usage
    description: Developer API budget and usage introspection.
  - name: Onboarding
    description: >-
      Self-serve agent registration: a sandbox key with no account, and the path
      to live access.
  - name: System
    description: Health and operational status checks.
  - name: MCP
    description: Remote Model Context Protocol transport.
  - name: Reports
    description: Daily, weekly, monthly, and trader export report snapshots.
  - name: Account
    description: Identify the account and credential authenticated for a paid API request.
externalDocs:
  description: 0xinsider API docs
  url: https://docs.0xinsider.com
paths:
  /api/v1/sports/pre-game-sides:
    get:
      tags:
        - Markets
      summary: List upcoming games ranked by the side profitable wallets hold
      description: >-
        Canonical since #16310; GET /api/v1/sports-edge-signals is its
        deprecated alias and serves the same body. Pro-tier. Ranked list of
        upcoming pre-game sports markets (moneyline + props) where graded
        (S/A/B) sharp money is piled on one side, each row carrying
        signal_created_at (the UTC time its immutable snapshot was computed),
        the piled side, its grade distribution, kickoff, piled-side Polymarket
        CLOB token id, and required shadow-only category_skill evidence.
        signal_created_at is not provider market creation time or request time.
        Eligibility and ranking remain the funded FLOW/HOLDER contract; category
        skill cannot change membership, order, rank, cursor, routing, or sizing.
        meta exposes explicit category source/model/status plus independently
        computed pre/post SHA-256 base-vector hashes that must match. Served
        from a shared server-side snapshot cache (healthy TTL ~180s, degraded
        ~30s) computed once per category at the maximum 48h horizon and filtered
        at request time; the cursor pins to that snapshot and a stale cursor is
        rejected. Polymarket only; source coverage is partial first-observed
        post-launch Goldsky primary taker BUY fills admitted by the canonical
        whale-alert thresholds, never reconstructed history. Deliberately not
        the editorial Pick of the Day ranker. Rows carry the canonical field
        names side, ranked_at, backing_score and side_share; the older
        piled_side, signal_created_at, conviction_score and smart_score keys
        carry the same values and stay on the wire.
      operationId: listPreGameSides
      parameters:
        - name: X-Query-Validation
          in: header
          required: false
          description: >-
            Opt into strict query-name validation. The default is compatible:
            unknown names are ignored and reported in X-Query-Ignored. With
            strict, an unknown name returns 400 bad_request with error.reason
            unknown_query_parameter before the handler runs, including when its
            percent escape is incomplete.
          schema:
            type: string
            enum:
              - strict
        - name: category
          in: query
          description: >-
            Optional canonical sport bucket filter (e.g. Basketball, Tennis,
            Soccer). A raw provider value (NBA) resolves to its canonical
            bucket. A non-sport category returns an empty list.
          schema:
            type: string
        - name: limit
          in: query
          description: Page size.
          schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 20
        - name: cursor
          in: query
          description: >-
            Opaque cursor from a previous response's next_cursor. Encodes the
            snapshot anchor plus the last row's directional_rank_score,
            conviction_score, smart_score and condition_id. A cursor from an
            expired snapshot returns 400.
          schema:
            type: string
        - name: horizon_hours
          in: query
          description: >-
            Kickoff ceiling in hours from now; the floor is now (only games not
            yet started). Clamped to 1..48.
          schema:
            type: integer
            minimum: 1
            maximum: 48
            default: 12
        - name: min_grade
          in: query
          description: >-
            Minimum trader grade required on the piled side. Only S, A, B are
            accepted (the piled-side grade distribution is S/A/B only; C, D, F
            return 400). Default B means at least one S/A/B holder is piled; S
            requires an S holder, A requires an S or A holder.
          schema:
            type: string
            enum:
              - S
              - A
              - B
            default: B
        - name: If-None-Match
          in: header
          required: false
          description: >-
            Conditional GET validator from a previous ETag. Matching values
            return 304 Not Modified with an empty body.
          schema:
            type: string
      responses:
        '200':
          description: Upcoming games ranked by the side profitable wallets hold
          headers:
            X-Query-Ignored:
              $ref: '#/components/headers/X-Query-Ignored'
            X-Effective-Query:
              $ref: '#/components/headers/X-Effective-Query'
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimit-Limit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimit-Remaining'
            RateLimit-Reset:
              $ref: '#/components/headers/RateLimit-Reset'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            ETag:
              $ref: '#/components/headers/ETag'
            X-Usage-Accounting:
              $ref: '#/components/headers/X-Usage-Accounting'
            Server-Timing:
              $ref: '#/components/headers/Server-Timing'
          content:
            application/json:
              schema:
                type: object
                required:
                  - object
                  - data
                  - has_more
                  - meta
                properties:
                  object:
                    type: string
                    const: list
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/PreGameSide'
                  has_more:
                    type: boolean
                  next_cursor:
                    type: string
                  total:
                    type: integer
                  meta:
                    $ref: '#/components/schemas/ResponseMeta'
              x-examples:
                success:
                  object: list
                  data: []
                  has_more: false
                  next_cursor: null
                  meta:
                    request_id: req_example
                    cached: false
                    cost: 5
        '304':
          description: >-
            Not Modified. Returned when If-None-Match matches the current
            payload.
          headers:
            X-Query-Ignored:
              $ref: '#/components/headers/X-Query-Ignored'
            X-Effective-Query:
              $ref: '#/components/headers/X-Effective-Query'
            ETag:
              $ref: '#/components/headers/ETag'
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimit-Limit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimit-Remaining'
            RateLimit-Reset:
              $ref: '#/components/headers/RateLimit-Reset'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            X-Usage-Accounting:
              $ref: '#/components/headers/X-Usage-Accounting'
            Server-Timing:
              $ref: '#/components/headers/Server-Timing'
          x-empty-body: true
        '400':
          description: >-
            Bad request. On this cursor-paginated route a 400 has TWO distinct
            causes; branch on error.reason. (1) error.reason="cursor_expired"
            (with error.param="cursor"): the pagination cursor was invalidated
            by an upstream data change mid-walk (e.g. the ranking snapshot
            behind the page refreshed). It is NOT a malformed parameter and NOT
            a reason to stop: recovery is mechanical -- re-request the first
            page and walk forward again. There is deliberately no Retry-After
            and no error.retry_at, because waiting changes nothing. (2) no
            error.reason: an ordinary invalid request parameter -- check
            error.param when present, otherwise error.message. Both carry
            error.code="bad_request" (a FROZEN contract value), so error.reason
            is the discriminator.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '401':
          description: Missing or invalid API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '402':
          description: >-
            Active Pro subscription required. The key is valid but the account
            has no active Pro subscription; error.reason is
            subscription_inactive and error.message names the reactivation URL
            (https://0xinsider.com/billing). Permanent until a person
            reactivates: no Retry-After, never retry on a schedule.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '403':
          description: Account access denied
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '408':
          description: >-
            The handler did not answer inside the server's 30-second timeout.
            error.code is request_timeout. On GET and HEAD the response carries
            Retry-After and error.retry_at; on a mutation it carries neither,
            because the request may have completed on the server: check its
            state before repeating it, and reuse its Idempotency-Key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '423':
          description: Account is locked
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '429':
          description: >-
            Rate limit exceeded. Three independent budgets. (1) 100
            requests/minute per user (sliding window), on every authenticated
            route. (2) On the BATCH routes only: 2500 batch item units/minute
            per user, reserved before any item is executed. A batch with N
            requested items costs N item units, including duplicate and invalid
            items. 2500 = 100 requests x 25 items per batch, which is the most
            item work a key can buy through the request limiter at all: a caller
            may spend their entire 100-request minute on full 25-item batches
            without the item budget being what stops them. The REQUEST budget is
            the effective ceiling, and batching is never the more expensive
            choice. The item budget can still deny at a sliding-window boundary
            (both counters carry the previous window forward with a floor, and
            the item counter runs 25x the request counter), so honor a 429 from
            either. Over-quota batches return 429 with Retry-After plus
            RateLimit-Limit, RateLimit-Remaining, and RateLimit-Reset before any
            item work is done. (3) The monthly quota: Pro includes 250,000
            authenticated requests per UTC calendar month, whatever the billing
            cadence. Over 250,000: with pay as you go on, requests keep
            answering and the excess bills at USD 0.20 per 1,000 on a monthly
            invoice, up to 1,000,000 requests a month; without it, from 1
            October 2026 the next request answers 429 rate_limited with
            error.reason monthly_quota_exceeded and a Retry-After to the month's
            reset, and from the same day a pay-as-you-go account answers the
            same past 1,000,000. A refused request is not counted. Every
            authenticated response carries X-Monthly-Quota-Limit,
            X-Monthly-Quota-Remaining, and X-Monthly-Quota-Reset (unix seconds,
            the first of next month). (4) The per-address budget: 1200
            requests/minute per IP, shared by every caller behind one address
            and counted before authentication, on every route. A 429 from it
            carries error.reason ip_rate_limited and describes that bucket in
            RateLimit-*; a throttled address (sustained over-limit traffic)
            carries error.reason ip_throttled with a Retry-After of minutes to
            days, and a request before it does not shorten the cooldown. Every
            429 is the standard error envelope with meta.request_id equal to
            X-Request-Id.
          headers:
            Retry-After:
              description: Seconds until rate limit resets.
              schema:
                type: integer
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimit-Limit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimit-Remaining'
            RateLimit-Reset:
              $ref: '#/components/headers/RateLimit-Reset'
            X-RateLimit-Limit:
              schema:
                type: integer
            X-RateLimit-Remaining:
              schema:
                type: integer
            X-RateLimit-Reset:
              schema:
                type: integer
            X-Request-Id:
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '503':
          description: >-
            Redis-backed authenticated rate limiter unavailable; retry after the
            per-process outage cooldown
          headers:
            Retry-After:
              description: >-
                Seconds until the middleware will probe the Redis-backed rate
                limiter again.
              schema:
                type: integer
            X-Request-Id:
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
      x-codeSamples:
        - lang: curl
          label: cURL
          source: |-
            curl -sS \
              -H "Authorization: Bearer $OXINSIDER_API_KEY" \
              'https://api.0xinsider.com/api/v1/sports/pre-game-sides?category=Basketball&horizon_hours=12&min_grade=B&limit=10'
components:
  headers:
    X-Query-Ignored:
      description: >-
        Comma-separated, percent-encoded query names the operation did not
        publish and therefore ignored in compatible mode. Names are sorted and
        de-duplicated.
      schema:
        type: string
    X-Effective-Query:
      description: >-
        Normalized, percent-encoded query string containing only the recognized
        names and values applied by the operation. Query names and values use
        form-urlencoded decoding, where + is a space. Repeated names are
        retained and sorted by name.
      schema:
        type: string
    RateLimit-Limit:
      description: >-
        Request limit of the budget this request was counted against, for its
        current window: the API key's per-minute sliding window on an
        authenticated call; the per-IP budget on a public route and on a refused
        credential (401, 402, 403, 423), which never reaches the per-key
        limiter. Standard RateLimit header spelling.
      schema:
        type: integer
        example: 100
    RateLimit-Remaining:
      description: >-
        Requests remaining in that budget's current window after this response.
        Standard RateLimit header spelling.
      schema:
        type: integer
        example: 84
    RateLimit-Reset:
      description: >-
        Seconds until that budget's current window resets. Standard RateLimit
        header spelling.
      schema:
        type: integer
        example: 42
    X-RateLimit-Limit:
      description: >-
        Request limit of the budget this request was counted against, for its
        current window: the API key's per-minute sliding window on an
        authenticated call; the per-IP budget on a public route and on a refused
        credential (401, 402, 403, 423).
      schema:
        type: integer
        example: 100
    X-RateLimit-Remaining:
      description: Requests remaining in that budget's current window after this response.
      schema:
        type: integer
        example: 84
    X-RateLimit-Reset:
      description: Unix timestamp when that budget's current window resets.
      schema:
        type: integer
        example: 1710772860
    X-Request-Id:
      description: >-
        Server-generated request identifier for support and tracing. On every
        /api/v1 response, including 304, 408, CORS preflights and every error,
        and always equal to meta.request_id in the body. It is the key of the
        request's usage accounting row and of every log line the request
        emitted, so quote either form to support. A client-supplied X-Request-Id
        request header is ignored: the value is never adopted or echoed.
      schema:
        type: string
        example: req_550e8400
    ETag:
      description: >-
        Weak semantic validator for conditional GET. Request-specific response
        metadata is excluded; send as If-None-Match to receive 304 when the
        stable payload is unchanged.
      schema:
        type: string
        example: W/"8f14e45fceea167a5a36dedd4bea2543"
    X-Usage-Accounting:
      description: >-
        Usage-record persistence for a protected V1 handler response. persisted:
        confirmed row; failed: write failed; unknown: completion could not be
        confirmed. Independent of handler success; do not replay successful
        mutations to repair accounting. Absent before accounting admission and
        on public routes. The zero-cost /api/v1/usage route also omits it.
      schema:
        type: string
        enum:
          - persisted
          - failed
          - unknown
    Server-Timing:
      description: >-
        Processing time in milliseconds, for example api;dur=12.345. Includes
        API authentication, quota admission, handler work and response
        construction. Excludes network transit and streamed body or export-file
        transfer. The engineering budget is strictly below 250 ms; this header
        reports observations, not a latency guarantee or a new timeout.
      schema:
        type: string
      example: api;dur=12.345
  schemas:
    PreGameSide:
      type: object
      description: >-
        One ranked pre-game sports market where graded sharp money is piled on
        one side, with required-status shadow category evidence from partial
        forward-observed Polymarket fills.
      required:
        - condition_id
        - signal_created_at
        - token_id
        - category
        - raw_category
        - title
        - event_slug
        - game_start_time
        - piled_side
        - piled_outcome_index
        - sharp_pct
        - backed_sharp_usd
        - s_count
        - a_count
        - b_count
        - graded_holders
        - top_grade
        - smart_score
        - volume
        - net_side
        - conviction_score
        - one_way_holder_count
        - hedged_holder_count
        - one_way_graded_usd
        - directional_confidence
        - directional_rank_score
        - category_skill
        - rank
        - side
        - ranked_at
        - backing_score
        - side_share
      properties:
        side:
          type: string
          nullable: true
          description: >-
            The side profitable wallets hold, as a provider-backed display
            label. Canonical spelling of piled_side (#16310), same value: when
            provider group context is unavailable it may remain a bare
            Yes/No/Over/Under, so do not use it alone as participant identity.
        ranked_at:
          type: string
          format: date-time
          description: >-
            UTC time at which the snapshot that ranked this row was computed.
            Canonical spelling of signal_created_at (#16310), same value.
        backing_score:
          type: number
          description: >-
            Grade-weighted holders times the share of their money on the side:
            (5*s + 4*a + 3*b) * sharp_pct. Canonical spelling of
            conviction_score (#16310), same value.
        side_share:
          type: number
          nullable: true
          description: >-
            Signed share of graded money on the side, (yes_usd -
            no_usd)/(yes_usd + no_usd) in [-1, 1] (side-yes positive, side-no
            negative). Canonical spelling of smart_score (#16309, #16310), same
            value.
        condition_id:
          type: string
          description: Polymarket condition id.
        signal_created_at:
          deprecated: true
          type: string
          format: date-time
          description: >-
            UTC time at which the immutable signal snapshot was computed. Every
            row from one snapshot shares this value; it is not provider market
            creation time and is not rewritten at request time. Deprecated
            (#16310): `ranked_at` is the canonical spelling and carries the same
            value; this key stays on the wire.
        token_id:
          type: string
          nullable: true
          description: >-
            Polymarket CLOB token id (ERC1155 asset id, decimal string) for the
            PILED outcome; null when unavailable.
        category:
          type: string
          nullable: true
          description: >-
            Canonical sport bucket (e.g. Basketball, Tennis); null when the raw
            category has no canonical mapping.
        raw_category:
          type: string
          nullable: true
          description: Raw provider category as stored (e.g. NBA, EPL).
        title:
          type: string
          nullable: true
        event_slug:
          type: string
          nullable: true
        game_start_time:
          type: string
          format: date-time
          nullable: true
          description: >-
            Kickoff (UTC). In the future at SNAPSHOT time and within the
            requested horizon; because the response is served from a shared
            snapshot cached up to the ~180s TTL, a served kickoff can be up to
            ~180s in the past relative to the response time. Not a live
            guarantee that the game has not yet started.
        piled_side:
          deprecated: true
          type: string
          nullable: true
          description: >-
            Nullable provider-backed piled-outcome display label. When provider
            group context is unavailable, it may remain a bare
            Yes/No/Over/Under; do not use it alone as participant identity.
            Deprecated (#16310): `side` is the canonical spelling and carries
            the same value; this key stays on the wire.
        piled_outcome_index:
          type: integer
          description: >-
            Provider binary-column selector: 0 selects outcome_yes/token_id_yes;
            1 selects outcome_no/token_id_no. It does not identify home/away or
            a participant. Use piled_side together with title/event context for
            display.
        sharp_pct:
          type: number
          nullable: true
          description: >-
            Piled-side dollar concentration backed_usd / (yes_usd + no_usd), in
            (0.5, 1] for a real pile; null when there is no sharp USD.
        backed_sharp_usd:
          type: number
          description: Raw piled-side sharp-money USD.
        s_count:
          type: integer
          description: S-grade graded holders on the piled side.
        a_count:
          type: integer
          description: A-grade graded holders on the piled side.
        b_count:
          type: integer
          description: B-grade graded holders on the piled side.
        graded_holders:
          type: integer
          description: Piled-side graded holder count (s_count + a_count + b_count).
        top_grade:
          type: string
          nullable: true
          enum:
            - S
            - A
            - B
          description: Best grade present on the piled side; null when none.
        smart_score:
          deprecated: true
          type: number
          nullable: true
          description: >-
            Canonical sharp-money score (yes_usd - no_usd)/(yes_usd + no_usd) in
            [-1, 1] (piled-yes positive, piled-no negative); a lower-order
            ranking tiebreak (after directional_rank_score and
            conviction_score). Deprecated (#16310): `side_share` is the
            canonical spelling and carries the same value; this key stays on the
            wire.
        volume:
          type: number
          nullable: true
          description: Market volume (USD).
        net_side:
          type: string
          nullable: true
          enum:
            - BUY
            - SELL
          description: >-
            Aggregate recent flow direction on the market; null when
            unavailable.
        conviction_score:
          deprecated: true
          type: number
          description: >-
            Grade-weighted pile score (5*s + 4*a + 3*b) * sharp_pct; the raw
            conviction input to the ranking (see directional_rank_score).
            Deprecated (#16310): `backing_score` is the canonical spelling and
            carries the same value; this key stays on the wire.
        one_way_holder_count:
          type: integer
          nullable: true
          description: >-
            Piled-side graded holders read one-way: their fresh open legs across
            the signal game's markets (cross-market within the one game;
            moneyline+spread family only) all back the same team, or, when the
            market's holder scan was complete, Polymarket's currentValue shows
            no opposite leg on this market worth 10% of the backed leg and no
            fresh leg opposes it. Null when the directional read was not
            computed (no groupable game, no holder-level data on this ranking
            path, or the enrichment read failed) or classified nobody.
        hedged_holder_count:
          type: integer
          nullable: true
          description: >-
            Piled-side graded holders classified HEDGED across the game by fresh
            legs (they back two or more distinct teams). A wallet long both
            outcomes of this market is not one-way and not counted here. Null
            when the directional read was not computed or classified nobody.
        one_way_graded_usd:
          type: number
          nullable: true
          description: >-
            Piled-side graded USD held by one-way wallets (share-weighted
            allocation of backed_sharp_usd). Null when the directional read was
            not computed or classified nobody.
        directional_confidence:
          type: number
          nullable: true
          description: >-
            One-way fraction of the piled graded dollars, in [0, 1] -- the
            metric orthogonal to sharp_pct. Stale, unknown, hedged, and
            two-sided dollars dilute it toward zero (conservative). Null when
            the directional read was not computed or classified nobody.
        directional_rank_score:
          type: number
          description: >-
            The ranking key, descending: conviction_score * (1 + 0.25 *
            directional_confidence). Equals conviction_score when the
            directional read is null/zero, so signals without the read rank
            exactly as before.
        category_skill:
          $ref: '#/components/schemas/PreGameSideCategorySkill'
        rank:
          type: integer
          description: 1-based rank within the (min_grade-filtered) ranked result.
    ResponseMeta:
      type: object
      required:
        - request_id
        - cached
        - cost
      properties:
        request_id:
          type: string
          description: >-
            Unique request ID (req_ prefix). The same value as the X-Request-Id
            response header, the request's usage accounting row and its log
            lines.
        cached:
          type: boolean
        cache_age_s:
          type: integer
          description: >-
            Cache age in seconds. Omitted when the response was not cached, and
            also when it was cached but its age cannot be established (an entry
            stored before its cache carried a computed instant). Never a
            placeholder: an unknown age is reported as no value rather than as
            the cache TTL.
        cost:
          type: integer
          description: >-
            Advisory request weight (relative compute cost). 1 for simple reads;
            higher for heavier endpoints. Not a credit/price.
        ranking_generation:
          type: integer
          description: >-
            Committed PostgreSQL-owned leaderboard generation for the returned
            rows and cursor. Present on GET /api/v1/leaderboard; omitted on
            endpoints that do not read this ranking.
        ranking_as_of:
          type: string
          format: date-time
          description: >-
            Authoritative RFC3339 timestamp from cache_generations.updated_at
            for ranking_generation. It is read in the same repeatable-read
            snapshot as the leaderboard rows and is not request time, cache
            write time, or row insertion order.
        directional_source:
          type: string
          enum:
            - live
            - degraded
          description: >-
            Which path produced the team-directional read on this response. Only
            present on endpoints that compute one (today: GET
            /api/v1/sports-edge-signals). "live" means the read RAN. "degraded"
            means it FAILED, so nothing was measured and the ranking fell back
            to raw conviction. The flag describes the READ, not its consequence:
            a read that ran and found nothing groupable also leaves the
            directional fields null, and that is honestly "live" -- the
            per-signal nulls already say "nothing to enrich here", so this
            snapshot-level flag carries only what they cannot, namely whether
            the read ran at all. A degraded response is cached on the shorter
            degraded TTL so it self-heals. Reported SEPARATELY from
            ranking_source because the two degradations are independent -- a
            sharp-money DB miss weakens the ranking DATA, a directional failure
            removes a ranking WEIGHT -- and a consumer down-weighting a degraded
            response needs to know which input it lost. Omitted on endpoints
            that compute no directional read.
        ranking_source:
          type: string
          enum:
            - live
            - db_only
          description: >-
            Which ranking-data path produced this response. Only present on
            endpoints that can degrade a ranking (today: GET
            /api/v1/sports-edge-signals). "live" is the normal path (the current
            holder pile from the provider batch); "db_only" is the degraded
            fallback (a truthful but weaker trader_markets ranking) served when
            the live sharp-money ranking batch is unavailable (a sharp-money DB
            read failure, not a Polymarket outage) and cached on a shorter TTL,
            so a consumer can down-weight or skip it. Omitted on endpoints that
            never degrade.
        category_skill_source:
          type: string
          enum:
            - live
            - partial
            - degraded
            - unavailable
          description: >-
            Whole filtered snapshot category-evidence status before pagination.
            Operational live always remains partial source coverage.
        category_skill_model_version:
          type: string
        category_skill_taxonomy_version:
          type: string
        category_skill_platform:
          type: string
          const: polymarket
        category_skill_scope:
          type: string
          const: observed_goldsky_primary_taker_fill
        category_skill_source_coverage:
          type: string
          enum:
            - partial_whale_threshold_fills
            - graded_wallet_fills
        category_skill_observation_started_at:
          type: string
          format: date-time
        category_skill_model_operationally_degraded:
          type: boolean
          description: >-
            Whole-model operational readiness captured with the category model
            snapshot. Present on category-enriched responses even when the
            filtered signal list is empty. When true, category_skill_source is
            degraded and sports-edge-signals uses the shorter degraded cache
            TTL.
        category_skill_status_counts:
          type: object
          required:
            - live
            - insufficient
            - stale
            - unknown
            - degraded
          properties:
            live:
              type: integer
              minimum: 0
            insufficient:
              type: integer
              minimum: 0
            stale:
              type: integer
              minimum: 0
            unknown:
              type: integer
              minimum: 0
            degraded:
              type: integer
              minimum: 0
        category_skill_base_payload_hash:
          type: string
          pattern: ^[0-9a-f]{64}$
          description: >-
            SHA-256 of the funded signal membership/order/rank/cursor vector
            immediately before category-skill enrichment. Sports-edge-signals
            only.
        category_skill_enriched_base_payload_hash:
          type: string
          pattern: ^[0-9a-f]{64}$
          description: >-
            Independent SHA-256 recomputation over the same base fields
            immediately after category-skill enrichment. Equality with
            category_skill_base_payload_hash proves shadow enrichment did not
            change funded inputs. Sports-edge-signals only.
    ApiError:
      type: object
      required:
        - object
        - error
        - meta
      properties:
        object:
          type: string
          const: error
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              description: >-
                FROZEN: an existing value never changes meaning. request_timeout
                (408, #16146) was added the way insufficient_scope was: the
                handler did not answer inside the server's 30-second timeout.
                Retry-After and retry_at ride on it only for a safe method (GET,
                HEAD); a timed-out mutation may have completed, so check its
                state and reuse its Idempotency-Key.
              enum:
                - bad_request
                - invalid_api_key
                - subscription_required
                - forbidden
                - insufficient_scope
                - not_found
                - account_locked
                - rate_limited
                - rate_limit_unavailable
                - internal_error
                - request_timeout
            message:
              type: string
            doc_url:
              type: string
            param:
              type: string
            retry_at:
              type: string
              format: date-time
              description: >-
                The recommended next request instant (RFC3339), always in the
                future. Present on every retryable error: `pick_not_released`,
                `rate_limited`, `rate_limit_unavailable`, and
                `read_model_warming`. Omitted otherwise. The absolute twin of
                `Retry-After`; prefer the header for the sleep duration. For
                `pick_not_released`, the earliest of the next scheduled release,
                the next automatic selector attempt, the operating-window start,
                or about 60 seconds. See that response.
            freshness:
              $ref: '#/components/schemas/FreshnessFailure'
            reason:
              type: string
              enum:
                - cursor_expired
                - unknown_endpoint
                - pick_not_released
                - trader_not_tracked
                - read_model_warming
                - database_unavailable
                - request_accounting_unavailable
                - idempotency_in_progress
                - webhook_delivery_in_progress
                - webhook_secret_rotation_not_prepared
                - webhook_secret_rotation_overlap_active
                - sandbox_api_key
                - api_key_in_query
                - subscription_inactive
                - monthly_quota_exceeded
                - invalid_query
                - unknown_query_parameter
                - invalid_path
                - invalid_body
                - unsupported_media_type
                - payload_too_large
                - method_not_allowed
                - ip_rate_limited
                - ip_throttled
                - export_expired
                - freshness_ceiling_unsatisfied
              description: >-
                ADDITIVE (#7209). The specific, actionable cause behind `code`,
                when there is one more specific than the code itself. `code`
                keeps its published values, so existing clients are unaffected;
                new clients branch on `reason`. Omitted when the code already
                says everything we know. pick_not_released: no Pick of the Day
                is published for the current product day; schedule one request
                against retry_at instead of polling. unknown_endpoint: the PATH
                is not a route on this API -- read GET /api/v1, do not retry.
                trader_not_tracked: the wallet is real and the URL is right, but
                the trader is outside the HOT/WARM sync tiers -- stop asking for
                this wallet. cursor_expired: pagination went stale mid-walk --
                re-request the first page and continue. read_model_warming: the
                requested endpoint cannot serve its read model yet; exact causes
                are endpoint-specific and can include a cold or contended
                refresh or a dependency that prevented refresh.
                database_unavailable: the API's database or its connection pool
                is temporarily unreachable (a connection-class failure, not a
                query fault); code stays rate_limit_unavailable, nothing is
                rate-limited, retry after Retry-After / retry_at.
                idempotency_in_progress: retain the exact Idempotency-Key and
                request body, then retry shortly. webhook_delivery_in_progress:
                retry the URL or signing-secret configuration change after the
                destination's active request completes.
                request_accounting_unavailable: accounting capacity is
                unavailable before the handler executes; retry after Retry-After
                / retry_at. sandbox_api_key: the credential is a sandbox key
                (oxi_sk_test_) from POST /api/v1/agents/register, which only the
                sandbox server accepts -- call the sandbox base URL with it, or
                get a live key or OAuth access token; do not retry it here.
                api_key_in_query: the key was sent as a ?token= query parameter,
                which no route reads because URLs land in logs and history; the
                key itself was not checked -- resend it as Authorization:
                Bearer. subscription_inactive: the key is valid but the
                account's Pro subscription has lapsed (402
                subscription_required); permanent until a person reactivates at
                https://0xinsider.com/billing, which the message names -- stop
                retrying on a schedule and surface the link. The key owner is
                emailed once per lapse. monthly_quota_exceeded: the account has
                used the requests Pro includes for the UTC calendar month (429
                rate_limited); retry_at and Retry-After name the first of next
                month, the only retry that can succeed, and the message names
                https://0xinsider.com/developers, where pay as you go for
                requests over the quota is turned on. The X-Monthly-Quota-Limit,
                X-Monthly-Quota-Remaining and X-Monthly-Quota-Reset headers on
                every authenticated response say how close the account is.
                invalid_query, invalid_path, invalid_body (400 bad_request,
                #16146): a query parameter, a path segment or the JSON body did
                not parse or does not fit the route's schema, so no handler ran;
                param names the field when the parser named one (a query key, a
                path segment, a JSON path such as traders[0], or body); fix the
                request, never retry it as sent. unsupported_media_type (415
                bad_request, param content-type): send the body with
                Content-Type: application/json. payload_too_large (413
                bad_request, param body): the body is over 1048576 bytes.
                method_not_allowed (405 bad_request): the path is a route but
                not with this method; the Allow header names the methods it
                serves. ip_rate_limited (429 rate_limited, #16380): the
                per-address budget every caller behind one IP shares, counted
                before authentication, is spent; not the key's own window, and
                the RateLimit-* headers describe that bucket. ip_throttled (429
                rate_limited): the address is in a cooldown after sustained
                over-limit traffic; Retry-After is minutes to days, and a
                request before it does not shorten the cooldown.
        meta:
          $ref: '#/components/schemas/ResponseMeta'
    PreGameSideCategorySkill:
      type: object
      description: >-
        Shadow-only category evidence over the full uncapped piled-side S/A/B
        holder allocation. It never changes signal membership, ordering,
        routing, or sizing.
      required:
        - status
        - model_version
        - taxonomy_version
        - platform
        - scope
        - source_coverage
        - observation_started_at
        - as_of
        - canonical_category
        - eligible_holders
        - covered_holders
        - backed_sharp_usd
        - covered_backed_usd
        - coverage_pct
        - weighted_edge_mean
        - weighted_holder_lower_mean
        - specialist_backed_usd
        - specialist_backed_usd_pct
        - largest_holder_backed_usd_pct
        - minimum_holder_event_count
      properties:
        status:
          type: string
          enum:
            - live
            - insufficient
            - stale
            - unknown
            - degraded
        model_version:
          type: string
        taxonomy_version:
          type: string
          nullable: true
        platform:
          type: string
          const: polymarket
        scope:
          type: string
          const: observed_goldsky_primary_taker_fill
        source_coverage:
          type: string
          enum:
            - partial_whale_threshold_fills
            - graded_wallet_fills
        observation_started_at:
          type: string
          format: date-time
        as_of:
          type: string
          format: date-time
        canonical_category:
          type: string
          nullable: true
        eligible_holders:
          type: integer
          minimum: 0
        covered_holders:
          type: integer
          minimum: 0
        backed_sharp_usd:
          type: number
          nullable: true
          minimum: 0
        covered_backed_usd:
          type: number
          nullable: true
          minimum: 0
        coverage_pct:
          type: number
          nullable: true
          minimum: 0
          maximum: 1
        weighted_edge_mean:
          type: number
          nullable: true
          minimum: -1
          maximum: 1
        weighted_holder_lower_mean:
          type: number
          nullable: true
        specialist_backed_usd:
          type: number
          nullable: true
          minimum: 0
        specialist_backed_usd_pct:
          type: number
          nullable: true
          minimum: 0
          maximum: 1
        largest_holder_backed_usd_pct:
          type: number
          nullable: true
          minimum: 0
          maximum: 1
        minimum_holder_event_count:
          type: integer
          nullable: true
          minimum: 0
    FreshnessFailure:
      type: object
      required:
        - max_age_s
        - data_quality_status
      properties:
        max_age_s:
          type: integer
          format: int64
          minimum: 0
          description: The caller's requested whole-response freshness ceiling in seconds.
        actual_age_s:
          type: integer
          format: int64
          minimum: 0
          description: >-
            Age in seconds of the oldest stored data_quality.as_of clock, when
            one is available.
        as_of:
          type: string
          format: date-time
          description: >-
            The oldest stored data-quality clock used to calculate actual_age_s,
            when one is available.
        data_quality_status:
          type: string
          enum:
            - fresh
            - partial
            - unknown
            - untracked
            - unavailable
          description: >-
            The trader body's whole-response data-quality status. Only fresh can
            satisfy max_age_s.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Legacy default or named integration API key, or OAuth 2.1 access token,
        in the Authorization header as `Bearer oxi_sk_live_...` or `Bearer
        oxi_at_...`. Default keys retain full access; integration keys are
        limited to their approved read, webhooks, export and usage scopes and
        expire within 90 days. All credentials share the owner's account limits.
        Data calls require an active Pro subscription and return live data. A
        401 carries WWW-Authenticate: Bearer
        resource_metadata="https://api.0xinsider.com/.well-known/oauth-protected-resource"
        (RFC 6750 section 3, RFC 9728).
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.1 authorization code flow with PKCE S256 for apps and MCP
        clients acting for a user. Public clients only (no client secret):
        register with RFC 7591 at https://api.0xinsider.com/oauth/register or
        present an https client ID metadata document URL as client_id.
        Authorization server metadata:
        https://api.0xinsider.com/.well-known/oauth-authorization-server. The
        access token (oxi_at_..., one hour) is sent as `Authorization: Bearer`;
        refresh tokens rotate on every use. A route outside the token's scopes
        answers 403 insufficient_scope. Walkthrough:
        https://0xinsider.com/auth.md.
      flows:
        authorizationCode:
          authorizationUrl: https://0xinsider.com/oauth/authorize
          tokenUrl: https://api.0xinsider.com/oauth/token
          refreshUrl: https://api.0xinsider.com/oauth/token
          scopes:
            read: >-
              Read markets, traders, large trades, positions, reports, search,
              the event stream and every MCP tool
            webhooks: Create, list, verify, rotate and delete webhook endpoints
            export: Start, poll and download trader exports
            usage: Read the caller's API usage counters

````