Overview
Four GET endpoints return your holdings, transactions, value history and net worth as JSON or CSV. The API reads only: there are no write endpoints, webhooks or scheduled exports. If you need one of those, write to [email protected]. To let Claude or ChatGPT read your portfolio, see Connect Claude or ChatGPT.
The API is part of Pro. Create a token in the app under Settings, Data, API Access. The full token appears once, when you create it, and is never stored or shown again, so copy it before you close the screen.
Authentication
Send the token as a bearer credential on every request:
curl https://<project-ref>.supabase.co/functions/v1/api-v1/positions \
-H "Authorization: Bearer pan_<your-token>"Revoking a token in the app takes effect on the next request. A token only ever reads the account that created it.
Endpoints
| Endpoint | Returns |
|---|---|
GET /positions | Every position you hold (watchlist items excluded), derivatives included, with expense ratios and fee columns. Quantity, cost basis and current value are signed: negative for a short derivative position. |
GET /transactions | Transaction history, newest first, including the corporate-action fields exchangeRatio, basisAllocationPct and targetAssetId on merger, spin-off and return-of-capital rows. |
GET /snapshots | Portfolio value snapshots over time, newest first. |
GET /net-worth | One object: total assets, total liabilities and net worth, converted to your base currency. Unvested equity compensation is left out. |
Query parameters
| Parameter | Effect |
|---|---|
format | json (the default) or csv. CSV responses carry Content-Disposition: attachment, so browsers and scripts save them as a file. |
portfolio_id | Limits /positions and /snapshots to one portfolio. Leave it out for every portfolio on the account. /transactions ignores it and always spans the whole account. |
limit | Caps /transactions and /snapshots, newest first. Default 100, maximum 1,000. There is no offset paging, so fetch a long history in one call with a higher limit. |
Example
Save every position as a CSV file:
curl "https://<project-ref>.supabase.co/functions/v1/api-v1/positions?format=csv" \
-H "Authorization: Bearer pan_<your-token>" \
-o positions.csvRate limit
1,000 requests per rolling 24 hours for each account. That covers a script polling every couple of minutes or a spreadsheet that refreshes all day. Over the limit, the API answers 429 with a Retry-After header.
Errors
| Status | Meaning |
|---|---|
401 | The token is missing, malformed or revoked. |
403 | The token lacks the read scope, or the account no longer has Pro. |
404 | The path is not one of the four endpoints. |
429 | Over the daily limit. Wait for the number of seconds in Retry-After. |
502 | Your data could not be read just then. Retry. |
503 | Your subscription could not be checked just then. Retry. |