List Crypto Withdrawal Requests
POST https://trade-uk.sandbox.zodiamarkets.com/api/3/withdrawal/crypto/list
Every client-initiated crypto withdrawal request on every account group where you hold ROLE_OPERATIONS, newest first by creation date.
Scope, and what it does not return
Section titled “Scope, and what it does not return”The response spans every account group where you hold ROLE_OPERATIONS and silently omits the rest. There is no account-group parameter, and an accountGroupUuid in the body is ignored.
- Requests raised by other members of the same account group are included.
- Requests raised by Zodia Markets Operations on your behalf are not included.
- An empty array can mean you hold
ROLE_OPERATIONSon nothing, rather than that you have no requests.
There is no pagination and no filtering. Page and filter client-side.
How a crypto row differs from a fiat one
Section titled “How a crypto row differs from a fiat one”| Crypto | Fiat | |
|---|---|---|
| Destination | coinAddress plus wallet |
bankAccount |
withdrawalMethod |
absent | BANK_WIRE |
state vocabulary |
five values, including FAILED |
four values |
coinAddress is the address the funds are destined for, copied from the whitelisted wallet when the request was submitted. state is derived rather than stored, which is why its vocabulary is a superset of the fiat one; see Request states.
Amounts are strings. Fields with no value are omitted rather than returned as null, and the address and alias fields inside wallet are omitted when the participants service is unavailable, while wallet.uuid remains.
This is a POST because the nonce or tonce travels in the signed body. It changes nothing.
Domain: Withdrawals
Request
Section titled “Request”POST https://trade-uk.sandbox.zodiamarkets.com/api/3/withdrawal/crypto/listHeaders
Section titled “Headers”| Header | Required | Description |
|---|---|---|
Rest-Key |
yes | API key for authentication |
Rest-Sign |
yes | Calculated API Signature |
| Field | Type | Required | Description |
|---|---|---|---|
tonce |
integer (int64) | yes | The current Unix time in microseconds. Accepted only within two minutes of server time. Send either tonce or nonce. |
nonce |
integer (int64) | Alternative to tonce, and takes precedence when both are sent. Must be a whole number and strictly increasing for a given API key: a reused or lower value is rejected. A request carrying neither nonce nor tonce is rejected with 401. |
Responses
Section titled “Responses”200 OK
Section titled “200 OK”Every crypto withdrawal request you can see, newest first by creation date. No pagination and no filtering, so page and filter client-side.
| Field | Type | Required | Description |
|---|---|---|---|
[].uuid |
string | Pass this to the cancel endpoint. | |
[].amount |
string | Exact decimal as a string, never a float. Parse it as a decimal. | |
[].ccy |
string | Currency or asset code. | |
[].coinAddress |
string | The destination address, copied from the whitelisted wallet at submit time. | |
[].state |
string (enum) | PENDING_APPROVAL awaiting acceptance by Zodia Markets Operations, and the only state a request can be cancelled from. PENDING accepted by Operations and in progress. PROCESSED funds sent. FAILED is part of this vocabulary but no current processing flow produces it; tolerate it rather than expect it, and contact your relationship manager if you see it. CANCELLED cancelled by you or declined by Operations - the two are not distinguished. This vocabulary is derived differently from the fiat one and is a superset of it. — One of: PENDING_APPROVAL, PENDING, PROCESSED, FAILED, CANCELLED |
|
[].accountGroup |
string | Duplicate of accountGroupName, carrying exactly the same value. Read accountGroupName instead. |
|
[].accountGroupUuid |
string | UUID of the account group the request belongs to. | |
[].accountGroupOwner |
string | Username of the account group’s owner. | |
[].accountGroupOwnerUuid |
string | UUID of the account group’s owner. | |
[].accountGroupName |
string | Name of the account group the request belongs to. | |
[].clientName |
string | The client the request belongs to. For a subordinate user this is the parent, not the submitter. | |
[].requestor |
string | The user who actually submitted the request, which need not be you. | |
[].beneficiary |
object | Your own onboarded entity, as registered with Zodia Markets. | |
[].beneficiary.uuid |
string | ||
[].beneficiary.name |
string | ||
[].wallet |
object | The whitelisted wallet the funds are destined for. | |
[].wallet.uuid |
string | ||
[].wallet.address |
string | ||
[].wallet.alias |
string | ||
[].clientComment |
string | As submitted, up to 1024 characters. Absent when none was sent. | |
[].dateCreated |
string | When the request was raised. ISO-8601 with milliseconds and a zone offset, e.g. 2026-08-04T10:15:30.451+01:00. |
|
[].lastUpdated |
string | Changes on every state transition. Same format as dateCreated. |
401 Unauthorized
Section titled “401 Unauthorized”Authentication failed: unknown key, bad signature, a missing, malformed, reused or decreasing nonce or out-of-window tonce, a body that is not parseable JSON, or a throttled caller. Rate limiting surfaces here as 401, not 429.
| Field | Type | Required | Description |
|---|---|---|---|
success |
boolean | ||
message |
string |
403 Forbidden
Section titled “403 Forbidden”Body missing or malformed (Invalid signed params), or the API key lacks the Move Funds permission (MOVE FUNDS permission required), which these read-only endpoints require too.
| Field | Type | Required | Description |
|---|---|---|---|
success |
boolean | ||
message |
string |
500 Internal Server Error
Section titled “500 Internal Server Error”Unexpected error. The outcome is undefined - for a submit, use the list endpoint to establish whether the request was created before resending.
| Field | Type | Required | Description |
|---|---|---|---|
success |
boolean | ||
message |
string |
