Production checklist
What to verify before launching a Lighter integration.
Environment
- Tested end to end on testnet (
https://testnet.zklighter.elliot.ai, chain ID300). See Environments & endpoints. - Mainnet config uses chain ID
304and the mainnet base URL - Market IDs and decimals are loaded from
orderBookDetails, not hard-coded -
wasm_exec.jsandlighter-signer.wasmcome from the same Go build
Keys & security
- Your app uses a dedicated API key index (4–254) that won't clash with others
- API private keys are encrypted at rest (keychain / KMS); never logged
- Your own keys never ship to a browser or mobile bundle
- The
bridge.lighter.xyzbuilder key is used server-side only - Read-only tokens are used wherever trading isn't needed (analytics, AI agents)
- Auth tokens are refreshed before their expiry (max 8 hours)
Orders
- Prices and sizes converted with the market's decimals, and checked against minimums
- Market orders use a sensible worst price (slippage limit)
-
clientOrderIndexvalues are unique across all markets -
orderExpiryis between 5 minutes and 30 days (or0for IOC) - Execution is confirmed via WebSocket or
txlookup, not assumed fromcode: 200
Nonces
- Sends per API key are serialized (or you use
skipNoncedeliberately) - Retries follow Retrying safely: check the tx status before re-signing
- Separate API keys for independent workloads
Reliability
- WebSocket keepalive (a frame at least every 2 minutes) and automatic reconnect + resubscribe
- Order book continuity check (
begin_nonce= previousnonce) - Exponential backoff on HTTP 429/405
- Requests authenticated to use L1-based rate limits
- Tier chosen deliberately (Standard's 60 req/min is easy to hit). See Account Types.
Money movement
- Deposit minimums shown to users (with slippage buffer)
- UDA
blockedflag respected - Transfer fees fetched from
transferFeeInforight before signing
Partner fees
- Clients are on Plus or Premium before non-zero integrator fees are attached
- Fees ≤ approved maximums ≤
systemConfigcaps - Re-approval flow before
approvalExpiry
Ops
- Subscribed to the API Telegram channel /
#api-updateson Discord - Contact channel with Lighter set up (Discord
#support)
Updated 2 days ago
Did this page help you?
