> ## Documentation Index
> Fetch the complete documentation index at: https://developers.fhsc.com.vn/llms.txt
> Use this file to discover all available pages before exploring further.

# Giao dịch nội bộ / cổ đông lớn

> Giao dịch công bố của người nội bộ, cổ đông lớn và người có liên quan của 1 mã: ai giao dịch, chức vụ, khối lượng đăng ký / đã thực hiện, tỷ lệ sở hữu sau giao dịch.

Đây là DANH SÁCH SỰ KIỆN công bố, không phải chuỗi số liệu theo phiên. `from`/`to` (dạng `YYYY-MM-DD`) lọc theo ngày công bố; bỏ trống → 1 năm gần nhất. Phân trang qua `page`/`page_size` (tối đa 50).




## OpenAPI

````yaml /openapi.yaml get /market/stocks/{symbol}/trading/insider
openapi: 3.1.0
info:
  title: Finhay Securities Open API
  version: 0.2.0-preview.3
  description: |
    Đặc tả chính thức của Finhay Securities Open API, dùng chung cho SDK
    codegen, Redoc docs, và (sau này) mock server / contract test.

    ## Authentication — 2 tier

    - **Tier 1 — chỉ cần API key**: các endpoint đọc dữ liệu thị trường
      (`GET /market/**`, `GET /trading/market/**`). Gửi kèm header
      `X-FH-APIKEY` là đủ.
    - **Tier 2 — HMAC signing**: các endpoint liên quan đến account /
      trading / user. Gửi kèm 4 header `X-FH-APIKEY` + `X-FH-TIMESTAMP` +
      `X-FH-NONCE` + `X-FH-SIGNATURE`; thêm `X-FH-BODYHASH` khi request có
      body. Chi tiết thuật toán xem extension `x-finhay-signing` ở root
      spec hoặc phần README.

    ## Bootstrap flow

    Gọi 2 endpoint tag **Khởi tạo** (`GET /users/v1/users/me` và
    `GET /users/v1/users/{userId}/sub-accounts`) **1 lần khi khởi tạo
    client** để lấy thông tin `user_id` và `subAccountId`. Mọi endpoint thuộc
    tag **Tổng tài sản / Tiểu khoản / Danh mục đầu tư / Sổ lệnh / Lãi-lỗ /
    Quyền cổ đông** đều cần 2 giá trị này để truyền vào path parameter.
  contact: {}
servers:
  - url: https://open-api.fhsc.com.vn
    description: Production
security:
  - FinhayApiKey: []
tags:
  - name: Khởi tạo
    description: >-
      Khởi tạo client — lấy `user_id` và `subAccountId`. Gọi 1 lần khi khởi tạo
      SDK rồi cache lại.
  - name: Bảng giá thị trường
    description: >-
      Giá realtime, lịch sử và sổ lệnh thống nhất cho stocks / indices / forex /
      crypto / hàng hoá / quỹ mở / trái phiếu / ETF.
  - name: Phân tích cơ bản
    description: >-
      Chỉ số tài chính cơ bản của doanh nghiệp — chỉ số tổng quan, phân tích
      theo kỳ và báo cáo tài chính chuẩn (income statement / balance sheet /
      cash flow).
  - name: Tin tức-sự kiện
    description: >-
      Sự kiện doanh nghiệp (cổ tức, quyền mua, ĐHCĐ, …), tin tức stock, tin tức
      tài chính toàn cầu (forex / commodities / economic-indicators /
      stock-market / cryptocurrency) và báo cáo khuyến nghị từ analyst.
  - name: Kinh tế vĩ mô
    description: >-
      Chỉ số kinh tế vĩ mô (CPI, PMI, PCE, GDP, …), lãi suất tiền gửi ngân hàng
      và lịch sự kiện kinh tế.
  - name: Tổng tài sản
    description: >-
      Tổng quan tài sản cấp user — cross-product (stock, fund, bond, hay0) kèm
      cash, debt, PnL.
  - name: Tiểu khoản
    description: Thông tin tiểu khoản — số dư, margin, dư nợ và ngân hàng liên kết.
  - name: Danh mục đầu tư
    description: Danh mục stock đang nắm giữ kèm giá realtime và PnL theo vị thế.
  - name: Sổ lệnh
    description: >-
      Quản lý lệnh — sổ lệnh trong ngày, danh sách đầy đủ hoặc chi tiết theo
      `orderId`.
  - name: Lãi-lỗ
    description: PnL và analytics cá nhân — lãi / lỗ trong ngày tổng hợp theo user.
  - name: Quyền cổ đông
    description: Quyền cổ đông (cổ tức, quyền mua, bỏ phiếu, …) của tiểu khoản.
  - name: Phiên giao dịch
    description: >-
      Hạ tầng trading — trạng thái phiên giao dịch và order type khả dụng của
      mỗi exchange.
  - name: Thực thi lệnh
    description: |
      ⚠️ Nhóm endpoint này đang ở giai đoạn **preview**.

      Đặt / sửa / huỷ lệnh trên sàn — write operation nhạy cảm, yêu cầu
      Tier 2 HMAC đầy đủ + `X-FH-BODYHASH` + `X-FH-2FA-TOKEN` (daily 2FA
      session).
paths:
  /market/stocks/{symbol}/trading/insider:
    get:
      tags:
        - Tin tức-sự kiện
      summary: Giao dịch nội bộ / cổ đông lớn
      description: >
        Giao dịch công bố của người nội bộ, cổ đông lớn và người có liên quan
        của 1 mã: ai giao dịch, chức vụ, khối lượng đăng ký / đã thực hiện, tỷ
        lệ sở hữu sau giao dịch.


        Đây là DANH SÁCH SỰ KIỆN công bố, không phải chuỗi số liệu theo phiên.
        `from`/`to` (dạng `YYYY-MM-DD`) lọc theo ngày công bố; bỏ trống → 1 năm
        gần nhất. Phân trang qua `page`/`page_size` (tối đa 50).
      operationId: stocksGetInsiderTrades
      parameters:
        - name: symbol
          in: path
          required: true
          description: >-
            Mã cổ phiếu niêm yết (3–10 ký tự chữ/số, không phân biệt hoa
            thường). VD: VNM, FPT.
          schema:
            type: string
            example: VNM
        - name: from
          in: query
          required: false
          description: >-
            Ngày bắt đầu (bao gồm), dạng `YYYY-MM-DD`. Bỏ trống → `to` trừ 1
            năm.
          schema:
            type: string
            format: date
            example: '2026-01-01'
        - name: to
          in: query
          required: false
          description: Ngày kết thúc (bao gồm), dạng `YYYY-MM-DD`. Bỏ trống → hôm nay.
          schema:
            type: string
            format: date
            example: '2026-03-31'
        - name: side
          in: query
          required: false
          description: Lọc theo chiều giao dịch. Bỏ trống → mọi chiều.
          schema:
            $ref: '#/components/schemas/InsiderTradeSide'
        - name: status
          in: query
          required: false
          description: Lọc theo trạng thái. Bỏ trống → mọi trạng thái.
          schema:
            $ref: '#/components/schemas/InsiderTradeStatus'
        - name: page
          in: query
          required: false
          description: Trang cần lấy, bắt đầu từ 1. Mặc định `1`.
          schema:
            type: integer
            minimum: 1
            example: 1
        - name: page_size
          in: query
          required: false
          description: Số bản ghi mỗi trang, tối đa 50. Mặc định `20`.
          schema:
            type: integer
            minimum: 1
            maximum: 50
            example: 20
      responses:
        '200':
          description: '`data.data` là danh sách giao dịch nội bộ của trang hiện tại.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StockInsiderTradeListResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
      x-codeSamples:
        - lang: bash
          label: cURL
          source: |
            curl -H "X-FH-APIKEY: $FINHAY_API_KEY" \
              "https://open-api.fhsc.com.vn/market/stocks/VNM/trading/insider?from=2026-01-01&to=2026-03-31"
components:
  schemas:
    InsiderTradeSide:
      type: string
      description: >-
        Chiều giao dịch đã chuẩn hoá từ nhãn tiếng Việt của nguồn. Hậu tố cho
        biết hướng ghi nhận sở hữu: `_BUY`/`_IN` là ghi tăng, `_SELL`/`_OUT` là
        ghi giảm. `TRADE_BUY` mua, `TRADE_SELL` bán, `TRANSFER_IN` nhận chuyển
        quyền sở hữu, `TRANSFER_OUT` chuyển quyền sở hữu, `GIFT_IN` nhận
        cho/biếu/tặng, `GIFT_OUT` cho/biếu/tặng, `INHERITANCE_IN` nhận thừa kế.
      enum:
        - TRADE_BUY
        - TRADE_SELL
        - TRANSFER_IN
        - TRANSFER_OUT
        - GIFT_IN
        - GIFT_OUT
        - INHERITANCE_IN
      example: TRADE_BUY
    InsiderTradeStatus:
      type: string
      description: >-
        Trạng thái suy ra từ loại tin và khối lượng: `REGISTERED` mới đăng ký
        chưa có kết quả, `COMPLETED` khớp đủ khối lượng đăng ký, `PARTIAL` khớp
        một phần.
      enum:
        - REGISTERED
        - COMPLETED
        - PARTIAL
      example: COMPLETED
    StockInsiderTradeListResponse:
      allOf:
        - $ref: '#/components/schemas/EnvelopeBase'
        - type: object
          required:
            - data
          properties:
            data:
              $ref: '#/components/schemas/StockInsiderTradeList'
    EnvelopeBase:
      type: object
      description: |
        Các field chung của envelope trong mọi response của Finhay API.

        - `error_code` là `"0"` (string) khi thành công, mã khác `"0"` khi lỗi.
        - `message` là thông điệp ngắn từ server.
      properties:
        error_code:
          type: string
          description: '`"0"` khi thành công, khác `"0"` khi lỗi.'
          example: '0'
        message:
          type: string
          description: Thông điệp trạng thái dễ đọc.
          example: success
    StockInsiderTradeList:
      type: object
      description: Danh sách giao dịch nội bộ của một mã, đã phân trang.
      required:
        - symbol
        - data
      properties:
        symbol:
          type: string
          description: Mã cổ phiếu.
          example: VNM
        total:
          type: integer
          description: Tổng số giao dịch khớp bộ lọc.
          example: 37
        page:
          type: integer
          description: Trang hiện tại.
          example: 1
        page_size:
          type: integer
          description: Số bản ghi mỗi trang.
          example: 20
        data:
          type: array
          description: Các bản ghi của trang hiện tại.
          items:
            $ref: '#/components/schemas/StockInsiderTrade'
        updated_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >-
            Lần nguồn cập nhật gần nhất trong số các bản ghi trả về (ISO 8601
            kèm offset). `null` khi không bản ghi nào mang mốc thời gian.
          example: '2026-05-27T14:30:15+07:00'
    ErrorBody:
      type: object
      description: Body của response khi 4xx / 5xx.
      properties:
        error_code:
          type: string
          description: >-
            Mã lỗi khác `"0"` (ví dụ `AUTH_SIGNATURE_INVALID`,
            `RATE_LIMIT_EXCEEDED`, …).
          example: '400'
        message:
          type: string
          description: Thông điệp lỗi (tiếng Anh, từ server).
          example: Invalid parameter
      required:
        - error_code
        - message
    StockInsiderTrade:
      type: object
      description: >-
        Một giao dịch công bố của người nội bộ, cổ đông lớn hoặc người có liên
        quan.
      properties:
        person_name:
          type:
            - string
            - 'null'
          description: Tên cá nhân hoặc tổ chức thực hiện giao dịch.
          example: Nguyễn Văn A
        position:
          type:
            - string
            - 'null'
          description: Chức vụ / mối quan hệ với doanh nghiệp.
          example: Thành viên HĐQT
        side:
          anyOf:
            - $ref: '#/components/schemas/InsiderTradeSide'
            - type: 'null'
          description: >-
            Chiều giao dịch. `null` khi nhãn của nguồn không nằm trong tập đã
            biết.
        registered_volume:
          type:
            - number
            - 'null'
          description: >-
            Khối lượng đăng ký giao dịch (độ lớn, luôn không âm — chiều nằm ở
            `side`).
          example: 500000
        executed_volume:
          type:
            - number
            - 'null'
          description: Khối lượng đã thực hiện (độ lớn). `null` khi mới đăng ký.
          example: 320000
        ownership_after_percent:
          type:
            - number
            - 'null'
          description: Tỷ lệ sở hữu sau giao dịch (%).
          example: 2.15
        shares_before:
          type:
            - number
            - 'null'
          description: Số cổ phiếu nắm giữ trước giao dịch.
          example: 1200000
        shares_after:
          type:
            - number
            - 'null'
          description: Số cổ phiếu nắm giữ sau giao dịch.
          example: 1520000
        registered_from:
          type:
            - string
            - 'null'
          format: date
          description: Ngày bắt đầu khoảng đăng ký giao dịch.
          example: '2026-03-02'
        registered_to:
          type:
            - string
            - 'null'
          format: date
          description: Ngày kết thúc khoảng đăng ký giao dịch.
          example: '2026-03-28'
        executed_date:
          type:
            - string
            - 'null'
          format: date
          description: Ngày công bố kết quả thực hiện. `null` khi chưa có kết quả.
          example: '2026-03-25'
        status:
          anyOf:
            - $ref: '#/components/schemas/InsiderTradeStatus'
            - type: 'null'
          description: Trạng thái giao dịch.
  responses:
    BadRequest:
      description: Request không hợp lệ — thiếu hoặc sai tham số.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '400'
            message: Invalid parameter
    Unauthorized:
      description: Không xác thực — thiếu, sai hoặc không hợp lệ chữ ký / API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '401'
            message: Invalid signature
    NotFound:
      description: >-
        Tài nguyên không tồn tại — `error_code` mô tả cụ thể loại tài nguyên
        không tìm thấy.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '404'
            message: Not found
    RateLimited:
      description: >-
        Vượt giới hạn rate limit. Chờ đến thời điểm `X-RateLimit-Reset` rồi thử
        lại.
      headers:
        X-RateLimit-Reset:
          $ref: '#/components/headers/XRateLimitReset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '429'
            message: Too many requests
    InternalError:
      description: Lỗi server nội bộ.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error_code: '500'
            message: Internal server error
  headers:
    XRateLimitReset:
      description: |
        Unix timestamp (giây) — thời điểm window rate limit reset. Client nhận
        `429 Too Many Requests` nên chờ đến thời điểm này rồi retry.
      schema:
        type: integer
        format: int64
        example: 1713441600
  securitySchemes:
    FinhayApiKey:
      type: apiKey
      in: header
      name: X-FH-APIKEY
      description: >
        API key dài hạn của client. Cấu hình 1 lần lúc khởi tạo; có thể wire
        thẳng

        vào static setter của SDK tự-gen. Đi kèm với `FINHAY_API_SECRET` —
        secret

        này chỉ dùng ở phía client để tính `X-FH-SIGNATURE`, **không** bao giờ

        gửi qua mạng.

````