Summary
Coinbase is integrating Deribit, with cutover coming soon. Your existing Deribit users are unaffected. They keep their Deribit accounts and credentials, and you keep receiving rebates from them. What changes is your new users — after cutover they arrive with Coinbase credentials. Therefore, you will need to cover a mix — existing users on Deribit credentials, new users on Coinbase credentials. This will require some integration work: route each user to the correct endpoint, and add the auth path for new (Coinbase) users.What changes — and what doesn’t
Route per user
Existing and new users hold different credentials, so your integration selects the base URL and auth model per user, based on how they onboarded.Authentication
- Existing users keep their native Deribit authentication (Deribit OAuth or Deribit API key) — unchanged from today.
- New users authenticate with Coinbase credentials — either a CDP API key or OAuth2 — by calling
public/authto obtain a Deribit access token (HTTP) or an authenticated session (WebSocket).
Authenticate over the transport you will use: an HTTP token cannot authenticate a WebSocket, and vice versa.
API Keys - Private Access Sequence
- HTTP
- WebSocket
- You create a JWT, no round-trip to Coinbase. See creating a JWT.
- It lasts only ~120s, use a fresh JWT for every
public/authcall. - You need to provide the Deribit access token on each private method call.
- Refresh the Deribit access token every 15 minutes.
OAuth2 - Private Access Sequence
- HTTP
- WebSocket
- Retrieve an OAuth2 access token from
POST login.coinbase.com/oauth2/token. - It expires in 60 mins, use an unexpired OAuth2 access token with every
public/authcall. - You need to provide the Deribit access token on each private method call.
- Refresh the Deribit access token every 15 minutes.
- Refresh the OAuth2 access token every 1 hour.
POST login.coinbase.com/oauth2/tokenwithgrant_type=refresh_tokenand your refresh token; you get back a new access and refresh token.
Notes
- On WebSocket, the connection is the credential.
public/authreturns no token — private method calls are authorized by the authenticated socket itself. Re-sendpublic/authon the same socket to extend. If the socket drops, you’ll need to re-authenticate from scratch. - Request
offline_accessto get a refresh token (OAuth2). Coinbase only issues a refresh token if theoffline_accessscope was in your authorize request. Without it, the 1-hour access token cannot be refreshed and the user must re-authorize. See OAuth2 scopes and access & refresh tokens. - CDP keys can use Ed25519 or ECDSA algorithms. Ed25519 is recommended and works with direct API calls. ECDSA keys are only required for legacy / third party SDKs.
- Send
public/authas aPOSTso credentials stay out of the URL. Deribit acceptspublic/authover bothGETandPOST; usePOSTso the CDP JWT or OAuth2 access token travels in the request body, not the query string — keeping it out of URLs, browser history, and access logs. See OAuth2 security best practices.
Migration Checklist
1
Keep your existing Deribit integration as-is
Existing users are unaffected and rebates continue.
2
Add a per-user routing branch
Existing Deribit users → native Deribit; new Coinbase users → new Coinbase endpoints.
3
Implement the Coinbase auth path for new users
CDP key or OAuth2 via
public/auth token exchange.4
Validate the new path
Before onboarding live Coinbase-credentialed users.
5
Deribit Advanced Trading gateway is live
New Coinbase users can trade from cutover.
Help
- Further assistance and timing — your Coinbase account manager.
- Method-level API detail — the Advanced Trade API reference.
- Best practices and detailed guides — Deribit’s documentation.