Skip to content

Cover the SDK surface: webhooks, breadth, CVD, levels, and replay - #9

Merged
0xFantomMenace merged 3 commits into
masterfrom
feat/surface-parity
Sep 29, 2026
Merged

0xFantomMenace merged 3 commits into
masterfrom
feat/surface-parity

Conversation

@0xFantomMenace

@0xFantomMenace 0xFantomMenace commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Brings the CLI to parity with what @0xarchive/sdk 1.12.0 exposes. Everything lands in the unreleased 1.10.0 (no version bump); the CHANGELOG entries are under ## 1.10.0 - 2026-09-28.

Added

Command SDK method
oxa breadth current|history --exchange hyperliquid|hip3 hyperliquid.breadth.current()/history(), hyperliquid.hip3.breadth.current()/history()
oxa cvd <symbol> --exchange hyperliquid|hip3 hyperliquid.cvd.history(), hyperliquid.hip3.cvd.history()
oxa liquidations levels / levels-history liquidations.levels() / levelsHistory() (core and HIP-3)
oxa orders trigger-levels / trigger-levels-history orders.triggerLevels() / triggerLevelsHistory() (core and HIP-3)
oxa hip3 oracle external-price / discovery-bounds hyperliquid.hip3.oracle.externalPrice() / discoveryBounds()
oxa hip4 questions list / get hyperliquid.hip4.questions.list() / get()
oxa wallets classify --exchange hyperliquid|hip3 wallets.classify()
oxa symbols [--exchange] [--symbol] symbols.list(), filtered locally
oxa webhooks event-types, limits webhooks.eventTypes(), limits()
oxa webhooks endpoints list|create|delete|enable|rotate-secret|test|deliveries listEndpoints(), createEndpoint(), deleteEndpoint(), enableEndpoint(), rotateSecret(), testEndpoint(), listDeliveries()
oxa webhooks redeliver redeliver()
oxa webhooks subscriptions list|create|update|delete|resume|resume-all listSubscriptions(), createSubscription(), updateSubscription(), deleteSubscription(), resumeSubscription(), resumeAllSubscriptions()
oxa webhooks estimate, dry-run estimate(), dryRun()
oxa webhooks addresses list|add|delete listAddresses(), addAddress(), deleteAddress()
oxa webhooks verify constructWebhookEvent() (with parseWebhookSignatureHeader() for the signing time)
oxa stream replay <channel> <symbol> --start --end [--speed] [--interval] OxArchiveWs.replay()
oxa stream subscribe orderbook_full|hip3_orderbook_full|hip4_trades|hip4_l4_diffs|hip4_l4_orders live channels added to the allow-list
oxa data-quality status|coverage|incidents|incident|latency|sla|positions-freshness dataQuality.status(), coverage() / exchangeCoverage() / symbolCoverage(), listIncidents(), getIncident(), latency(), sla(), positionsFreshness()
oxa spot l4-diffs|l4-history <symbol> spot.l4Orderbook.diffs() / history()
oxa hip4 outcomes by-slug <slug> (also oxa outcomes by-slug) hyperliquid.hip4.outcomes.getBySlug()
--account on oxa l3 get / history, --timestamp on oxa l3 get lighter.l3Orderbook.get() / history() account, timestamp
  • Webhook deletes and rotate-secret ask for confirmation in a terminal, take --yes in scripts, and change nothing without either. Filters and preview configurations are wire-shaped JSON, inline or from a file.
  • verify reads the raw body from --body-file or stdin, accepts repeated --secret (or OXA_WEBHOOK_SECRET) for rotations, and supports --tolerance / --ignore-timestamp. It needs no API key, never prints the secret, and scrubs it from any error.
  • stream replay writes every server message as NDJSON and exits 0 on replay_completed. Live-only channels are refused before a socket opens: full-depth, HIP-3/HIP-4/Spot L4 with the SDK's own error plus a pointer to the CLI's REST command; Spot, ticker and all_tickers by the CLI.
  • HIP-4 WebSocket channels (subscribe and replay) take bare numerics and send the #<n> form the API expects; 0 returns "symbol does not exist" on the socket today. hip4_orderbook / hip4_open_interest are refused on subscribe with a pointer to replay.
  • Order flow paging (from HELD until the API returns next_cursor on order flow: page order flow with --cursor #6): --cursor / --limit help, README, and has_more / nextCursor in the --out summary.
  • Breadth (reworked from feat: add HIP-3 breadth commands and align stream behavior #2): both venues, valuePct stays null in JSON and prints null in pretty output.

Removed / changed

  • Flags the API ignores: --depth on oxa l2 history and oxa l3 history, --user / --status / --order-type on oxa spot orders, --user on oxa spot trades. They are now unknown-option errors.
  • No command reaches a route the API does not serve (HIP-4 L2 and trigger levels, Spot flow/TP-SL/trigger levels, HIP-3 liquidations by user); those combinations were already refused before a request, and the new level commands accept hyperliquid and hip3 only. The CLI never had a trades --side.
  • Fixed: JSON output over the pipe buffer (64 KiB) was cut off when piped (for example oxa trades fetch ... --limit 1000 | jq returned 80 KB of a 600 KB document) because process.exit() ran before stdout drained. stdout and stderr are now blocking, and an early-closed pipe (| head) exits 0 instead of an EPIPE trace.
  • src/bin.ts is the executable (still bundled as dist/cli.js); src/cli.ts exports the command tree so tests parse real argument vectors against it.

Notes

  • oxa data-quality coverage covers every venue by default, one venue with --exchange, and one symbol with --exchange and --symbol (gaps and cadence; --from / --to bound the gap search).
  • HIP-4 slugs can contain spaces, colons, and braces; by-slug encodes the slug before handing it to the SDK, which puts it in the path as given.
  • Existing HIP-4 commands still use the CLI's own HIP-4 HTTP helper; only the new hip4 questions commands use the SDK's HIP-4 client.
  • CI installs the newest published SDK (1.8.0) until 1.12.0 is on npm. The code type-checks against both; with 1.8.0 the five tests that run the SDK's real signature verifier on the published test vectors are skipped, and the rest run.

Testing

  • Local, with the SDK built from sdk-typescript master and installed from its tarball: npm run typecheck, npm test (327 passed), npm run build, npm run check:pack on Node 20.20.2 and 22.23.1.
  • CI configuration simulated (SDK 1.8.0): typecheck clean, 322 passed and 5 skipped on Node 20 and 22; build and pack check pass.
  • Read-only runs against the live API: breadth (both venues), every data-quality command, Spot L4 diffs and history, outcome by slug (including a slug with a space), L3 --timestamp, CVD, oracle, questions, wallets, symbols, liquidation and trigger levels, L3 --account, webhook event-types / limits / list commands / estimate / dry-run, a trades replay, and orderbook_full, hip3_orderbook_full, and HIP-4 live subscriptions. No webhook write command was run against the API; those are covered by tests with the SDK stubbed.

Supersedes #2 and #6.

New commands, each on the matching @0xarchive/sdk method:
- oxa breadth current|history for Hyperliquid and HIP-3 (valuePct stays null)
- oxa cvd <symbol>, cursor paged, for Hyperliquid and HIP-3
- oxa liquidations levels|levels-history and oxa orders trigger-levels|trigger-levels-history
- oxa hip3 oracle external-price|discovery-bounds and oxa hip4 questions list|get
- oxa wallets classify with the classification filters and offset paging
- oxa symbols, filtered locally by --exchange and --symbol
- oxa webhooks: event-types, limits, endpoints, deliveries, redeliver,
  subscriptions, estimate, dry-run, addresses, and verify. Deleting and
  rotating ask for confirmation or --yes; verify never prints the secret.
- oxa stream replay through the SDK replay client, refusing live-only channels
- oxa stream subscribe accepts orderbook_full, hip3_orderbook_full,
  hip4_trades, hip4_l4_diffs and hip4_l4_orders; HIP-4 coins go out as #<n>
- --account on oxa l3 get and oxa l3 history

Order flow paging: help, README and the --out summary describe --cursor
and nextCursor.

Removed flags the API ignores: --depth on l2 history and l3 history,
--user/--status/--order-type on spot orders, and --user on spot trades.

Fixed: large JSON output piped to another program was cut off at the pipe
buffer, and closing the pipe early ended with an EPIPE stack trace.

src/bin.ts is now the executable entry (bundled as dist/cli.js); src/cli.ts
exports the command tree so tests parse real argument vectors.
- oxa breadth --exchange hyperliquid reads client.hyperliquid.breadth; the
  workaround that built the breadth resource on the core routes is gone
- oxa data-quality status|coverage|incidents|incident|latency|sla|positions-freshness
  on the SDK dataQuality resource; coverage takes --exchange and --symbol,
  with --from/--to bounding a symbol's gap search
- oxa spot l4-diffs and l4-history on spot.l4Orderbook.diffs()/history()
- oxa hip4 outcomes by-slug and oxa outcomes by-slug on
  hip4.outcomes.getBySlug(), with the slug encoded for the path
- --timestamp on oxa l3 get
@0xFantomMenace
0xFantomMenace merged commit cb19da8 into master Sep 29, 2026
2 checks passed
@0xFantomMenace
0xFantomMenace deleted the feat/surface-parity branch September 29, 2026 04:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant