curl \
-H "X-FH-APIKEY: $FINHAY_API_KEY" \
-H "X-FH-TIMESTAMP: $TIMESTAMP_MS" \
-H "X-FH-NONCE: $NONCE_UUID" \
-H "X-FH-SIGNATURE: $SIGNATURE_HEX" \
"https://open-api.fhsc.com.vn/trading/v1/accounts/$SUB_ACCOUNT_NORMAL/order-book"import requests
url = "https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book"
headers = {
"X-FH-APIKEY": "<api-key>",
"X-FH-TIMESTAMP": "<api-key>",
"X-FH-NONCE": "<api-key>",
"X-FH-SIGNATURE": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {
'X-FH-APIKEY': '<api-key>',
'X-FH-TIMESTAMP': '<api-key>',
'X-FH-NONCE': '<api-key>',
'X-FH-SIGNATURE': '<api-key>'
}
};
fetch('https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-FH-APIKEY: <api-key>",
"X-FH-NONCE: <api-key>",
"X-FH-SIGNATURE: <api-key>",
"X-FH-TIMESTAMP: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-FH-APIKEY", "<api-key>")
req.Header.Add("X-FH-TIMESTAMP", "<api-key>")
req.Header.Add("X-FH-NONCE", "<api-key>")
req.Header.Add("X-FH-SIGNATURE", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book")
.header("X-FH-APIKEY", "<api-key>")
.header("X-FH-TIMESTAMP", "<api-key>")
.header("X-FH-NONCE", "<api-key>")
.header("X-FH-SIGNATURE", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-FH-APIKEY"] = '<api-key>'
request["X-FH-TIMESTAMP"] = '<api-key>'
request["X-FH-NONCE"] = '<api-key>'
request["X-FH-SIGNATURE"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"error_code": "0",
"message": "success",
"result": [
{
"custodycd": "0123456",
"txdate": "2024-04-18",
"custid": "123456",
"afacctno": "0001234567",
"orderid": "ORD123456",
"odorderid": "0001",
"txtime": "09:15:23",
"symbol": "VNM",
"allowcancel": "Y",
"allowamend": "Y",
"side_code": "NB",
"side": "BUY",
"price": 72000,
"pricetype": "LO",
"via_code": "WEB",
"via": "Web",
"qtty": 100,
"execqtty": 0,
"execamt": 0,
"execprice": 0,
"remainqtty": 100,
"remainamt": 7200000,
"status_code": "01",
"status": "SENT",
"tlname": "Finhay",
"username": "cuong@finhay",
"hosesession": "PROGRESS",
"cancelqtty": 0,
"adjustqtty": 0,
"isdisposal": "N",
"rootorderid": "ORD123456",
"timetype": "0",
"timetypevalue": "",
"feedbackmsg": "",
"quoteqtty": 0,
"limitprice": 72000,
"odtimestamp": "2024-04-18T09:15:23",
"matchtype_code": "",
"producttypename": "STOCK",
"afacctno_ext": "0001234567.01",
"side_": "BUY",
"via_": "Web",
"status_": "SENT",
"matchtype_": "",
"strategy_id": null
}
]
}{
"error_code": "400",
"message": "Invalid parameter"
}{
"error_code": "401",
"message": "Invalid signature"
}{
"error_code": "429",
"message": "Too many requests"
}{
"error_code": "500",
"message": "Internal server error"
}Lấy sổ lệnh trong ngày
Sổ lệnh (orderbook) đầy đủ trong ngày (bao gồm cả lệnh từ broker-signal và HayBond).
curl \
-H "X-FH-APIKEY: $FINHAY_API_KEY" \
-H "X-FH-TIMESTAMP: $TIMESTAMP_MS" \
-H "X-FH-NONCE: $NONCE_UUID" \
-H "X-FH-SIGNATURE: $SIGNATURE_HEX" \
"https://open-api.fhsc.com.vn/trading/v1/accounts/$SUB_ACCOUNT_NORMAL/order-book"import requests
url = "https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book"
headers = {
"X-FH-APIKEY": "<api-key>",
"X-FH-TIMESTAMP": "<api-key>",
"X-FH-NONCE": "<api-key>",
"X-FH-SIGNATURE": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {
'X-FH-APIKEY': '<api-key>',
'X-FH-TIMESTAMP': '<api-key>',
'X-FH-NONCE': '<api-key>',
'X-FH-SIGNATURE': '<api-key>'
}
};
fetch('https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-FH-APIKEY: <api-key>",
"X-FH-NONCE: <api-key>",
"X-FH-SIGNATURE: <api-key>",
"X-FH-TIMESTAMP: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-FH-APIKEY", "<api-key>")
req.Header.Add("X-FH-TIMESTAMP", "<api-key>")
req.Header.Add("X-FH-NONCE", "<api-key>")
req.Header.Add("X-FH-SIGNATURE", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book")
.header("X-FH-APIKEY", "<api-key>")
.header("X-FH-TIMESTAMP", "<api-key>")
.header("X-FH-NONCE", "<api-key>")
.header("X-FH-SIGNATURE", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://open-api.fhsc.com.vn/trading/v1/accounts/{subAccountId}/order-book")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-FH-APIKEY"] = '<api-key>'
request["X-FH-TIMESTAMP"] = '<api-key>'
request["X-FH-NONCE"] = '<api-key>'
request["X-FH-SIGNATURE"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"error_code": "0",
"message": "success",
"result": [
{
"custodycd": "0123456",
"txdate": "2024-04-18",
"custid": "123456",
"afacctno": "0001234567",
"orderid": "ORD123456",
"odorderid": "0001",
"txtime": "09:15:23",
"symbol": "VNM",
"allowcancel": "Y",
"allowamend": "Y",
"side_code": "NB",
"side": "BUY",
"price": 72000,
"pricetype": "LO",
"via_code": "WEB",
"via": "Web",
"qtty": 100,
"execqtty": 0,
"execamt": 0,
"execprice": 0,
"remainqtty": 100,
"remainamt": 7200000,
"status_code": "01",
"status": "SENT",
"tlname": "Finhay",
"username": "cuong@finhay",
"hosesession": "PROGRESS",
"cancelqtty": 0,
"adjustqtty": 0,
"isdisposal": "N",
"rootorderid": "ORD123456",
"timetype": "0",
"timetypevalue": "",
"feedbackmsg": "",
"quoteqtty": 0,
"limitprice": 72000,
"odtimestamp": "2024-04-18T09:15:23",
"matchtype_code": "",
"producttypename": "STOCK",
"afacctno_ext": "0001234567.01",
"side_": "BUY",
"via_": "Web",
"status_": "SENT",
"matchtype_": "",
"strategy_id": null
}
]
}{
"error_code": "400",
"message": "Invalid parameter"
}{
"error_code": "401",
"message": "Invalid signature"
}{
"error_code": "429",
"message": "Too many requests"
}{
"error_code": "500",
"message": "Internal server error"
}Authorizations
API key dài hạn của client. Cấu hình 1 lần lúc khởi tạo; có thể wire thẳng
vào static setter của SDK tự-gen. Đi kèm với FINHAY_API_SECRET — secret
này chỉ dùng ở phía client để tính X-FH-SIGNATURE, không bao giờ
gửi qua mạng.
Unix time hiện tại tính bằng milliseconds, đưới dạng chuỗi số thập phân.
Được tính per-request bởi signing middleware. Không set thủ công — dùng middleware mẫu trong README.
UUIDv4 duy nhất per-request (ví dụ crypto.randomUUID()). Server cache
cặp (apiKey, nonce) trong 5 phút; nếu nonce được reuse với cùng apiKey
trong window này, request sẽ bị từ chối với AUTH_NONCE_REUSED (401).
Server chấp nhận chuỗi opaque bất kỳ về mặt kỹ thuật, nhưng nên dùng UUIDv4 để đảm bảo tính unique.
Được tính per-request bởi signing middleware. Không set thủ công — xem middleware mẫu trong tài liệu Authentication.
HMAC-SHA256 của canonical signing payload, encode hex (lowercase).
Signing payload:
{X-FH-TIMESTAMP}\n{METHOD}\n{REQUEST_PATH}[?{QUERY}]\n{BODYHASH}
?{QUERY}chỉ nối vào path khi request có query string.{BODYHASH}là chuỗi rỗng khi body rỗng (vẫn không có newline sau đó).
Được tính per-request bởi signing middleware. Không set thủ công — dùng middleware mẫu trong README.
Path Parameters
subAccountId được lấy từ bootstrap flow
(GET /users/v1/users/{userId}/sub-accounts), chọn NORMAL hoặc MARGIN
tuỳ mục đích.
"0001234567"
Response
Trả về result mảng các lệnh trong ngày của tiểu khoản; mỗi item là 1 lệnh kèm trạng thái khớp / chờ / huỷ.
Các field chung của envelope trong mọi response của Finhay API.
error_codelà"0"(string) khi thành công, mã khác"0"khi lỗi.messagelà thông điệp ngắn từ server.