Credentials
The trading surface is consumer-only: you bring your own keypairs and the SDK signs trades with them. Two self-service paths generate those keypairs and register them on-chain — both emit the same canonical TRIA_TRADE_* .env block, so your downstream config never changes.
The agent (HL) and delegate (Decibel) keys are trade-only — authorized via
approveAgent (HL) and delegateTradingTo (Decibel). Neither grants
withdrawal authority, and both are revocable any time from the Tria app.
What each credential is
- Name
TRIA_TRADE_HL_ACCOUNT_ADDRESS- Type
- 0x + 40 hex
- Description
Your HL master EVM address — where funds and positions live. Not used to sign anything.
- Name
TRIA_TRADE_HL_AGENT_KEY- Type
- 0x + 64 hex (secp256k1)
- Description
Agent private key, pre-approved by your master under the name
Tria SDK. Signs every order action. Cannot withdraw funds.
- Name
TRIA_TRADE_DECIBEL_APTOS_OWNER_ADDRESS- Type
- AIP-40, 64 hex
- Description
Your master Aptos wallet address. The SDK derives the primary subaccount from this at runtime — a hand-edited
.envcan't point trades at a non-primary subaccount.
- Name
TRIA_TRADE_DECIBEL_DELEGATE_KEY- Type
- 0x + 64 hex (Ed25519)
- Description
Delegate private key, pre-delegated on your subaccount with a 90-day expiry. Signs every Decibel trade. Cannot withdraw funds.
- Name
TRIA_TRADE_DECIBEL_NODE_API_KEY- Type
- Geomi Api key
- Description
Required — Decibel rejects anonymous reads with
401. Service typeApi(orAll).
- Name
TRIA_TRADE_DECIBEL_GAS_STATION_KEY- Type
- Geomi Gs key (optional)
- Description
When set, Aptos writes are sponsored and your account needs no APT. Service type
Gs— a distinct key from the node API key. Without it, writes need APT in the account or they fail withINSUFFICIENT_BALANCE_FOR_TRANSACTION_FEE— see Aptos gas for Decibel.
- Name
TRIA_TRADE_DECIBEL_SUBACCOUNT_ADDRESS- Type
- deprecated
- Description
Derived subaccount address, kept for backward compatibility. If set alongside the owner address it must match the derived primary, or the client refuses to start.
How to obtain them
A. In-app — Settings → API Keys (recommended)
Turnkey-signed; no seed phrase. In the Tria web wallet:
- Go to Settings → API Keys and pick a venue (Hyperliquid and/or Decibel), set a name + expiry (default 90 days, max 180, or "No expiry").
- Confirm — Turnkey signs the on-chain setup (builder-fee approval + agent / delegate registration).
- A one-time modal shows the keys. Click "Copy as … .env block" — already in canonical
TRIA_TRADE_*form:
# Decibel block (HL block is the analogous TRIA_TRADE_HL_* set)
TRIA_TRADE_NETWORK=mainnet
TRIA_TRADE_DECIBEL_DELEGATE_KEY=0x…
TRIA_TRADE_DECIBEL_APTOS_OWNER_ADDRESS=0x…
TRIA_TRADE_DECIBEL_SUBACCOUNT_ADDRESS=0x… # informational; SDK re-derives
TRIA_TRADE_DECIBEL_NODE_API_KEY=geomi-…
The keys are shown once — copy them then. The page also lists your existing agents / delegates (with expiry) and lets you revoke any of them.
The Decibel block has no TRIA_TRADE_DECIBEL_GAS_STATION_KEY — the app doesn't
run a shared gas station for SDK delegates. Decibel writes cost Aptos gas, so
add a gas-station key yourself or fund the account with APT. See
Aptos gas for Decibel.
B. CLI wizard — npx tria-trade-provision
Derives keys from a seed phrase. Interactive walkthrough with two personas:
- Tria user — paste your seed phrase from Settings → Account → Recover from Turnkey. The wizard derives HL (secp256k1) + Aptos (Ed25519) keys via standard BIP-44 paths and never touches your existing in-app agents.
- Fresh user — bring your own master keys; the wizard walks through Geomi signup, gas-station setup, and Aptos USDC bridging.
npx tria-trade-provision
It mints the agent / delegate, approves the Tria builder, funds collateral, and emits a ready-to-use .env.
Aptos gas for Decibel
Every Decibel action is an Aptos transaction that costs APT gas — including every placeOrder / cancelOrder at trade time, not just the one-time setup. The delegate key signs those transactions but does not fund their gas. If neither the signing account holds APT nor a gas station is configured, writes fail with INSUFFICIENT_BALANCE_FOR_TRANSACTION_FEE. Pick one of the two paths.
Manual trading in the Decibel web app hides this because that flow is gas-sponsored for you. SDK callers manage gas themselves.
Option A — Geomi gas station (recommended). Geomi sponsors every Aptos write, so your account needs zero APT. One-time setup:
- Sign up at geomi.dev (Google or email) and create a project.
- Sidebar → Gas stations → Create gas station.
- Basic: any name, Network = Mainnet → Next.
- Functions: Module address =
0x50ead22afd6ffd9769e3b3d6e0e64a2a350d68e8b102c4e72e33d0b8cfdfdb06(Decibel mainnet package), Module name = All Modules → click SELECT ALL FUNCTIONS → Configure functions. Defaults are correct for Decibel (per-tx max gas 28–250000, gas unit price 100–350 OCTA) → Save. - Create gas station.
- Fund the fee-payer: on the gas station's detail page, send ~0.5 APT to the Fee payer address (a Geomi-managed Aptos wallet) from a CEX. Geomi deducts each sponsored tx from this balance.
- Copy the gas-station API key from the gas station's API Keys panel →
TRIA_TRADE_DECIBEL_GAS_STATION_KEY(ordecibel.gasStationin code).
Option B — fund APT directly. Skip the gas station and send ~0.05 APT (plus a buffer for ongoing trading) to your Aptos account from a CEX. The SDK pays gas from that balance; you keep it topped up. Simpler to start, but you own the refills — Option A is hands-off.
The in-app Settings → API Keys .env block does not include a
gas-station key — the app doesn't run a shared gas station for SDK delegates.
Add TRIA_TRADE_DECIBEL_GAS_STATION_KEY yourself (Option A) or fund APT
(Option B). npx tria-trade-provision walks through this and writes the line
for you.
Importing the keys
However you generated the block, it imports the same way — the names match the SDK and MCP exactly.
import { TriaClient } from '@tria-sdk/api-trading'
const client = new TriaClient({
network: process.env.TRIA_TRADE_NETWORK as 'mainnet',
hl: {
agentPrivateKey: process.env.TRIA_TRADE_HL_AGENT_KEY!,
accountAddress: process.env.TRIA_TRADE_HL_ACCOUNT_ADDRESS!,
},
decibel: {
delegatePrivateKey: process.env.TRIA_TRADE_DECIBEL_DELEGATE_KEY!,
aptosOwnerAddress: process.env.TRIA_TRADE_DECIBEL_APTOS_OWNER_ADDRESS!,
nodeApiKey: process.env.TRIA_TRADE_DECIBEL_NODE_API_KEY!,
},
})
Expiry
Both venues support an expiry. The wizard and the in-app flow default to 90 days; pass a custom window 1–180, or none/0 for no expiry.
- Decibel —
--decibel-delegate-ttl-days <1–180 | none>. An explicit timestamp ondelegate_trading_to. - Hyperliquid —
--hl-agent-ttl-days <1–180 | none>. HL has no expiry field onapproveAgent; the expiry is encoded in the agent name as<name> valid_until <unix-seconds>.
You can always revoke early from Settings → API Keys.
Keys are revocable any time and revocation propagates to the venue within
seconds. HL allows 3 named + 2 unnamed agent slots per account; the Tria SDK
named slot is used here and your existing in-app agents stay intact. Decibel
allows multiple delegates per subaccount natively.