> ## Documentation Index
> Fetch the complete documentation index at: https://developers.fhsc.com.vn/llms.txt
> Use this file to discover all available pages before exploring further.

# Thống kê lệnh mua/bán chủ động (phiên gần nhất)

> Đây KHÔNG phải lệnh chờ trong sổ lệnh: là **lệnh đã khớp, phân loại theo bên chủ động** — mua chủ động (lifted the offer) và bán chủ động (hit the bid), bao gồm cả thoả thuận.

Nguồn chỉ có dữ liệu **sau khi đóng phiên**: trong giờ giao dịch, endpoint trả về phiên đã đóng gần nhất, không phải hôm nay — hãy đọc `date` trong kết quả trước khi coi đó là số liệu hôm nay.

`avg_volume_per_order` là `null` khi `order_count = 0`; `net_volume` có thể âm.




## OpenAPI

````yaml /openapi.yaml get /market/stocks/{symbol}/trading/orders
openapi: 3.1.0
info:
  title: Finhay Securities Open API
  version: 0.2.0-preview.3
  description: |
    Đặc tả chính thức của Finhay Securities Open API, dùng chung cho SDK
    codegen, Redoc docs, và (sau này) mock server / contract test.

    ## Authentication — 2 tier

    - **Tier 1 — chỉ cần API key**: các endpoint đọc dữ liệu thị trường
      (`GET /market/**`, `GET /trading/market/**`). Gửi kèm header
      `X-FH-APIKEY` là đủ.
    - **Tier 2 — HMAC signing**: các endpoint liên quan đến account /
      trading / user. Gửi kèm 4 header `X-FH-APIKEY` + `X-FH-TIMESTAMP` +
      `X-FH-NONCE` + `X-FH-SIGNATURE`; thêm `X-FH-BODYHASH` khi request có
      body. Chi tiết thuật toán xem extension `x-finhay-signing` ở root
      spec hoặc phần README.

    ## Bootstrap flow

    Gọi 2 endpoint tag **Khởi tạo** (`GET /users/v1/users/me` và
    `GET /users/v1/users/{userId}/sub-accounts`) **1 lần khi khởi tạo
    client** để lấy thông tin `user_id` và `subAccountId`. Mọi endpoint thuộc
    tag **Tổng tài sản / Tiểu khoản / Danh mục đầu tư / Sổ lệnh / Lãi-lỗ /
    Quyền cổ đông** đều cần 2 giá trị này để truyền vào path parameter.
  contact: {}
servers:
  - url: https://open-api.fhsc.com.vn
    description: Production
security:
  - FinhayApiKey: []
tags:
  - name: Khởi tạo
    description: >-
      Khởi tạo client — lấy `user_id` và `subAccountId`. Gọi 1 lần khi khởi tạo
      SDK rồi cache lại.
  - name: Bảng giá thị trường
    description: >-
      Giá realtime, lịch sử và sổ lệnh thống nhất cho stocks / indices / forex /
      crypto / hàng hoá / quỹ mở / trái phiếu / ETF.
  - name: Phân tích cơ bản
    description: >-
      Chỉ số tài chính cơ bản của doanh nghiệp — chỉ số tổng quan, phân tích
      theo kỳ và báo cáo tài chính chuẩn (income statement / balance sheet /
      cash flow).
  - name: Tin tức-sự kiện
    description: >-
      Sự kiện doanh nghiệp (cổ tức, quyền mua, ĐHCĐ, …), tin tức stock, tin tức
      tài chính toàn cầu (forex / commodities / economic-indicators /
      stock-market / cryptocurrency) và báo cáo khuyến nghị từ analyst.
  - name: Kinh tế vĩ mô
    description: >-
      Chỉ số kinh tế vĩ mô (CPI, PMI, PCE, GDP, …), lãi suất tiền gửi ngân hàng
      và lịch sự kiện kinh tế.
  - name: Tổng tài sản
    description: >-
      Tổng quan tài sản cấp user — cross-product (stock, fund, bond, hay0) kèm
      cash, debt, PnL.
  - name: Tiểu khoản
    description: Thông tin tiểu khoản — số dư, margin, dư nợ và ngân hàng liên kết.
  - name: Danh mục đầu tư
    description: Danh mục stock đang nắm giữ kèm giá realtime và PnL theo vị thế.
  - name: Sổ lệnh
    description: >-
      Quản lý lệnh — sổ lệnh trong ngày, danh sách đầy đủ hoặc chi tiết theo
      `orderId`.
  - name: Lãi-lỗ
    description: PnL và analytics cá nhân — lãi / lỗ trong ngày tổng hợp theo user.
  - name: Quyền cổ đông
    description: Quyền cổ đông (cổ tức, quyền mua, bỏ phiếu, …) của tiểu khoản.
  - name: Phiên giao dịch
    description: >-
      Hạ tầng trading — trạng thái phiên giao dịch và order type khả dụng của
      mỗi exchange.
  - name: Thực thi lệnh
    description: |
      ⚠️ Nhóm endpoint này đang ở giai đoạn **preview**.

      Đặt / sửa / huỷ lệnh trên sàn — write operation nhạy cảm, yêu cầu
      Tier 2 HMAC đầy đủ + `X-FH-BODYHASH` + `X-FH-2FA-TOKEN` (daily 2FA
      session).
paths:
  /market/stocks/{symbol}/trading/orders:
    get:
      tags:
        - Bảng giá thị trường
      summary: Thống kê lệnh mua/bán chủ động (phiên gần nhất)
      description: >
        Đây KHÔNG phải lệnh chờ trong sổ lệnh: là **lệnh đã khớp, phân loại theo
        bên chủ động** — mua chủ động (lifted the offer) và bán chủ động (hit
        the bid), bao gồm cả thoả thuận.


        Nguồn chỉ có dữ liệu **sau khi đóng phiên**: trong giờ giao dịch,
        endpoint trả về phiên đã đóng gần nhất, không phải hôm nay — hãy đọc
        `date` trong kết quả trước khi coi đó là số liệu hôm nay.


        `avg_volume_per_order` là `null` khi `order_count = 0`; `net_volume` có
        thể âm.
      operationId: stocksGetOrderStatistic
      parameters:
        - name: symbol
          in: path
          required: true
          description: >-
            Mã cổ phiếu niêm yết (3–10 ký tự chữ/số, không phân biệt hoa
            thường). VD: VNM, FPT.
          schema:
            type: string
            example: HPG
      responses:
        '200':
          description: '`data` là thống kê lệnh chủ động của phiên.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StockOrderStatisticResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
      x-codeSamples:
        - lang: bash
          label: cURL
          source: |
            curl -H "X-FH-APIKEY: $FINHAY_API_KEY" \
              "https://open-api.fhsc.com.vn/market/stocks/HPG/trading/orders"
components:
  schemas:
    StockOrderStatisticResponse:
      allOf:
        - $ref: '#/components/schemas/EnvelopeBase'
        - type: object
          required:
            - data
          properties:
            data:
              $ref: '#/components/schemas/StockOrderStatistic'
    EnvelopeBase:
      type: object
      description: |
        Các field chung của envelope trong mọi response của Finhay API.

        - `error_code` là `"0"` (string) khi thành công, mã khác `"0"` khi lỗi.
        - `message` là thông điệp ngắn từ server.
      properties:
        error_code:
          type: string
          description: '`"0"` khi thành công, khác `"0"` khi lỗi.'
          example: '0'
        message:
          type: string
          description: Thông điệp trạng thái dễ đọc.
          example: success
    StockOrderStatistic:
      type: object
      description: Thống kê lệnh mua / bán chủ động của một mã trong một phiên.
      required:
        - symbol
        - date
        - buy
        - sell
        - net_volume
      properties:
        symbol:
          type: string
          description: Mã cổ phiếu.
          example: HPG
        date:
          type: string
          format: date
          description: Ngày của phiên (`YYYY-MM-DD`).
          example: '2026-05-27'
        buy:
          allOf:
            - $ref: '#/components/schemas/OrderSideStatistic'
          description: Mua chủ động (lifted the offer).
        sell:
          allOf:
            - $ref: '#/components/schemas/OrderSideStatistic'
          description: Bán chủ động (hit the bid).
        net_volume:
          type: number
          description: >-
            `buy.volume − sell.volume`. Âm khi bên bán chủ động hơn — đây là số
            liệu bình thường, không phải lỗi.
          example: -412700
        updated_at:
          type: string
          format: date-time
          description: Thời điểm phiên được ghi lần cuối (ISO 8601 kèm offset).
          example: '2026-05-27T18:05:11+07:00'
    ErrorBody:
      type: object
      description: Body của response khi 4xx / 5xx.
      properties:
        error_code:
          type: string
          description: >-
            Mã lỗi khác `"0"` (ví dụ `AUTH_SIGNATURE_INVALID`,
            `RATE_LIMIT_EXCEEDED`, …).
          example: '400'
        message:
          type: string
          description: Thông điệp lỗi (tiếng Anh, từ server).
          example: Invalid parameter
      required:
        - error_code
        - message
    OrderSideStatistic:
      type: object
      description: Thống kê một chiều lệnh khớp chủ động trong phiên.
      required:
        - order_count
        - volume
      properties:
        order_count:
          type: number
          description: Số lệnh khớp về phía này.
          example: 18422
        volume:
          type: number
          description: Tổng khối lượng khớp về phía này (số cổ phiếu).
          example: 9871300
        avg_volume_per_order:
          type:
            - number
            - 'null'
          description: >-
            Khối lượng trung bình mỗi lệnh. `null` khi `order_count = 0` (không
            có trung bình để tính).
          example: 535.8
  responses:
    BadRequest:
      description: Request không hợp lệ — thiếu hoặc sai tham số.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '400'
            message: Invalid parameter
    Unauthorized:
      description: Không xác thực — thiếu, sai hoặc không hợp lệ chữ ký / API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '401'
            message: Invalid signature
    NotFound:
      description: >-
        Tài nguyên không tồn tại — `error_code` mô tả cụ thể loại tài nguyên
        không tìm thấy.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '404'
            message: Not found
    RateLimited:
      description: >-
        Vượt giới hạn rate limit. Chờ đến thời điểm `X-RateLimit-Reset` rồi thử
        lại.
      headers:
        X-RateLimit-Reset:
          $ref: '#/components/headers/XRateLimitReset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '429'
            message: Too many requests
    InternalError:
      description: Lỗi server nội bộ.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '500'
            message: Internal server error
  headers:
    XRateLimitReset:
      description: |
        Unix timestamp (giây) — thời điểm window rate limit reset. Client nhận
        `429 Too Many Requests` nên chờ đến thời điểm này rồi retry.
      schema:
        type: integer
        format: int64
        example: 1713441600
  securitySchemes:
    FinhayApiKey:
      type: apiKey
      in: header
      name: X-FH-APIKEY
      description: >
        API key dài hạn của client. Cấu hình 1 lần lúc khởi tạo; có thể wire
        thẳng

        vào static setter của SDK tự-gen. Đi kèm với `FINHAY_API_SECRET` —
        secret

        này chỉ dùng ở phía client để tính `X-FH-SIGNATURE`, **không** bao giờ

        gửi qua mạng.

````