
Connecting External APIs Securely with $.Http
Standard JavaScript runtimes like Node.js or browsers rely on global functions like fetch or axios to interact with external web services. However, in secure algorithmic environments, accessing unmanaged networking interfaces can introduce significant latency, security risks, or memory overhead.
In Code Strategies, external network communication is handled through the built-in $.Http object.
$.Http provides a streamlined, secure utility for sending HTTP requests, managing caching automatically, and generating cryptographic signatures for authenticated exchange endpoints—all from inside your strategy loop.
The Basics of $.Http
The $.Http interface supports standard REST methods (get, post, put, delete). Every request runs under strict performance boundaries to keep your continuous strategy execution fast and predictable:
- Maximum Timeout: 1750 ms per request.
- Automatic Caching: All GET requests are cached for 5 seconds by default.
Here is a basic example fetching current ticker data from an exchange:
const params = { symbol: "BTCUSDT" };
// 1. Send GET request to exchange API
const response = await $.Http.get(
"https://api.binance.com/api/v3/ticker/price",
params
);
// 2. Process status and parse payload
if (response.status === 200) {
const data = JSON.parse(response.text);
console.log(`Current price: ${data.price}`);
}
Understanding Response Caching
Because Code Strategies execute continuously, firing off raw network requests on every pass can quickly hit strict exchange rate limits.
To protect your strategies, $.Http automatically caches duplicate GET requests for 5 seconds. You can check whether a payload was retrieved live or served from cache by reading the cache property on the response:
const response = await $.Http.get("https://api.exchange.com/data");
if (response.cache) {
// Response was served from the local 5-second cache
} else {
// Response was freshly retrieved from the remote server
}
Secure API Signing with generateSignature
Interacting with authenticated exchange endpoints or custom webhook servers requires signing your request payloads using a secret key. Since standard crypto modules are restricted inside sandboxed environments, $.Http includes a built-in cryptographic utility: generateSignature.
generateSignature supports both standard HMAC and post-quantum ML-DSA44 signing algorithms.
Example: Signing an Authenticated Payload
const API_SECRET = $.Env.MY_API_SECRET; // Loaded securely from environment variables
const timestamp = Math.floor(Date.now() / 1000).toString();
const method = "POST";
const path = "/api/v2/strategy/signal";
const body = { action: "BUY", symbol: "BTCUSDT" };
// 1. Construct payload string
const payload = method + path + JSON.stringify(body) + timestamp;
// 2. Generate HMAC signature securely
const signature = await $.Http.generateSignature(payload, API_SECRET, "HMAC");
// 3. Send authenticated request with signature header
const response = await $.Http.post(
`https://api.your-endpoint.com${path}`,
body,
{
"X-Signature": signature,
"X-Timestamp": timestamp
}
);
By leveraging $.Env alongside $.Http.generateSignature, your secret keys remain hidden and secure, ensuring your API credentials are never hardcoded into strategy source code.
Best Practices for External Network Calls
- Combine with Time Gates: Always wrap external HTTP calls inside a Time Gate to prevent reaching out to external services on every single loop pass.
- Handle Non-200 Statuses Gracefully: Always verify
response.status === 200before parsingresponse.textwithJSON.parse(). - Use Environment Variables: Never hardcode private API keys or secrets directly into your strategy script—use
$.Envto load stored environment variables securely.


