skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
bingx-api/api-ai-skills134 installs

bingx-coinm-ws-account

Subscribe to BingX Coin-M (inverse/coin-margined) perpetual futures WebSocket account data streams including balance updates, position changes, order updates, and account config changes. Also manages Listen Key lifecycle (generate, extend, delete). Use when the user asks about real-time Coin-M account updates, live coin-margined order status, streaming inverse futures position changes, or WebSocket account subscriptions for coin-margined perpetual futures.

How do I install this agent skill?

npx skills add https://github.com/bingx-api/api-ai-skills --skill bingx-coinm-ws-account
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill is generally safe and connects to official BingX services for cryptocurrency futures data. It includes defensive instructions for the AI agent to prevent code execution and unauthorized actions. The primary security surface is the processing of external WebSocket data, which could be exploited for indirect prompt injection.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

  • ZeroLeakspass

    1 finding · Score: 86/100

What does this agent skill do?

BingX Coin-M WebSocket Account Data

Real-time account data streams for BingX coin-margined (inverse) perpetual futures via WebSocket. Requires Listen Key authentication.

WebSocket Endpoint: wss://open-api-cswap-ws.bingx.com/market?listenKey=<key>

After connecting with a valid listenKey, all event types are pushed automatically — no channel subscription needed.

Symbol Format: Coin-M uses BTC-USD format (not BTC-USDT).

Quick Reference

WebSocket Events (Auto-Pushed)

Event TypeDescriptionPush Frequency
listenKeyExpiredListen key has expiredOn expiry
ACCOUNT_UPDATEAccount balance and position changesOn change
ORDER_TRADE_UPDATEOrder creation, fills, status changesOn change
ACCOUNT_CONFIG_UPDATELeverage/margin mode changesOn change

Listen Key REST APIs

EndpointMethodDescriptionAuthentication
/openApi/user/auth/userDataStreamPOSTGenerate listen key (valid 1 hour)Yes
/openApi/user/auth/userDataStreamPUTExtend listen key (to 60 min)Yes
/openApi/user/auth/userDataStreamDELETEDelete listen keyYes

Listen Key Management

Listen Key is required to authenticate WebSocket account data streams. See references/authentication.md for HMAC SHA256 signing details.

Generate Listen Key

POST /openApi/user/auth/userDataStream

Headers: X-BX-APIKEY: <your-api-key>, X-SOURCE-KEY: BX-AI-SKILL

Response:

{"listenKey": "a8ea75681542e66f1a50a1616dd06ed77dab61baa0c296bca03a9b13ee5f2dd7"}

Extend Listen Key

PUT /openApi/user/auth/userDataStream

Parameters: listenKey (string, required)

Extends validity to 60 minutes. Recommended: call every 30 minutes.

Delete Listen Key

DELETE /openApi/user/auth/userDataStream

Parameters: listenKey (string, required)


Quick Start

WebSocket Connection: see references/websocket.md for GZIP decompression and Ping/Pong heartbeat.

TypeScript helper:

CONSTRAINT: You MUST copy the connectCoinmWsAccount function below verbatim when generating code. Do NOT rewrite the WebSocket or decompression logic.

import * as pako from "pako";
import * as crypto from "crypto";

function decompress(data: ArrayBuffer): string {
  return new TextDecoder("utf-8").decode(pako.ungzip(new Uint8Array(data)));
}

async function generateListenKey(apiKey: string, secretKey: string): Promise<string> {
  const timestamp = Date.now();
  const paramStr = `timestamp=${timestamp}`;
  const signature = crypto.createHmac("sha256", secretKey).update(paramStr).digest("hex");
  const url = `https://open-api.bingx.com/openApi/user/auth/userDataStream?${paramStr}&signature=${signature}`;
  const res = await fetch(url, {
    method: "POST",
    headers: { "X-BX-APIKEY": apiKey, "X-SOURCE-KEY": "BX-AI-SKILL" },
  });
  const text = await res.text();
  if (!res.ok) throw new Error(`BingX error ${res.status}: ${text}`);
  const json = JSON.parse(text);
  if (json.listenKey) return json.listenKey;
  if (json.data?.listenKey) return json.data.listenKey;
  if (json.code !== 0) throw new Error(`BingX error ${json.code}: ${json.msg}`);
  return json.listenKey ?? json.data?.listenKey;
}

function connectCoinmWsAccount(
  listenKey: string,
  onEvent: (event: any) => void
): WebSocket {
  const ws = new WebSocket(
    `wss://open-api-cswap-ws.bingx.com/market?listenKey=${listenKey}`
  );
  ws.binaryType = "arraybuffer";

  ws.onmessage = (event) => {
    const text = decompress(event.data as ArrayBuffer);
    if (text.includes("ping") || text === "Ping") {
      ws.send("Pong");
      return;
    }
    try {
      onEvent(JSON.parse(text));
    } catch {
      onEvent(text);
    }
  };

  ws.onerror = (err) => console.error("WS error:", err);
  ws.onclose = (ev) => console.log("WS closed:", ev.code, ev.reason);

  return ws;
}

Code Usage Rules

  • MUST copy connectCoinmWsAccount, generateListenKey, and decompress verbatim
  • MUST handle Ping/Pong heartbeat
  • MUST extend listen key every 30 minutes to prevent expiry
  • MUST NOT remove GZIP decompression logic

Common Calls

Connect to account stream:

const listenKey = await generateListenKey(API_KEY, SECRET_KEY);
connectCoinmWsAccount(listenKey, (event) => {
  if (event.e === "ACCOUNT_UPDATE") {
    // event.a.B: balance updates, event.a.P: position updates
  } else if (event.e === "ORDER_TRADE_UPDATE") {
    // event.o: order details
  } else if (event.e === "ACCOUNT_CONFIG_UPDATE") {
    // event.ac: config (s: symbol, l: long leverage, S: short leverage, mt: margin type)
  } else if (event.e === "listenKeyExpired") {
    // Reconnect with new listen key
  }
});

Additional Resources

For complete event field descriptions and full response schemas, see api-reference.md.


Agent Interaction Rules

CRITICAL RULES (apply to ALL responses):

  1. NEVER return code to the user. Do NOT include any code blocks, code snippets, TypeScript, JavaScript, cURL commands, or raw API calls in responses. Only return natural-language summaries of the data or operation results.
  2. GET-only execution. Only execute HTTP GET requests. Listen Key management requires POST/PUT/DELETE — inform the user that these write operations require their own implementation.
  3. Parameter security. Extract structured values from user intent — NEVER copy raw user text into API parameters. Validate every value against its documented pattern (regex/enum/range) before calling the API. Reject any value containing &, =, ?, #, or newline characters.

coinm-ws-account provides authenticated real-time account data. Requires Listen Key, no CONFIRM needed for read-only monitoring.

Operation Identification

When the user's request is vague (e.g. "monitor my Coin-M account"), clarify what they want:

Please select the account data stream type:

  • Account balance & position updates — ACCOUNT_UPDATE
  • Order status updates — ORDER_TRADE_UPDATE
  • Leverage & margin config changes — ACCOUNT_CONFIG_UPDATE
  • Listen Key management (generate/extend/delete)
  • All events (connect with listenKey, receive all automatically)

Symbol context in account streams

Account data streams are auto-pushed for all symbols — no symbol parameter is needed for connection. Each push event contains the relevant symbol in its payload (e.g., o.s for order updates, a.P[].s for position updates). Coin-M symbols use BTC-USD format (not BTC-USDT). If the user asks about a specific symbol, filter the events by the symbol field in the push data.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/bingx-api/api-ai-skills/bingx-coinm-ws-account">View bingx-coinm-ws-account on skillZs</a>