Summary
Coinbase is integrating Deribit, with cutover on September 9, 2026. Your existing Deribit users are unaffected. They keep their Deribit accounts and credentials, and you keep receiving rebates from them. What changes is your new users — after cutover they arrive with Coinbase credentials. Therefore, you will need to cover a mix — existing users on Deribit credentials, new users on Coinbase credentials. This will require some integration work: route each user to the correct endpoint, and add the auth path for new (Coinbase) users.What changes — and what doesn’t
| Cohort | What happens at cutover |
|---|---|
| Your existing Deribit users | Unaffected. They keep their Deribit accounts, credentials, and UX. No migration. You keep receiving rebates from them. |
| Your new users (after cutover) | Can no longer self-serve at deribit.com. They onboard through Coinbase and arrive with Coinbase credentials. |
Route per user
Existing and new users hold different credentials, so your integration selects the base URL and auth model per user, based on how they onboarded.| End-user cohort | Account type | Base URL (REST / WebSocket) | Auth model |
|---|---|---|---|
| Existing users | Deribit-native | https://www.deribit.com/api/v2 · wss://www.deribit.com/ws/api/v2 | Deribit OAuth / Deribit API key |
| New users | Coinbase | https://drb.coinbase.com/api/v2 · wss://drb.coinbase.com/ws/api/v2 | Coinbase CDP key or OAuth2 via token exchange |
Authentication
- Existing users keep their native Deribit authentication (Deribit OAuth or Deribit API key) — unchanged from today.
- New users authenticate with Coinbase credentials — either a CDP API key or OAuth2 — by calling
public/authto obtain a Deribit access token (HTTP) or an authenticated session (WebSocket).
| Token | What it is | Issued by | Lifetime | Reference |
|---|---|---|---|---|
cdp jwt | short-lived JWT signed with the user’s CDP API key | you, signed locally | ~120s | API key auth |
oauth2 access token | the user’s Coinbase OAuth2 access token | POST login.coinbase.com/oauth2/token | 1 hour | Access & refresh tokens |
deribit access token | Deribit bearer token from public/auth, HTTP only; on WebSocket the socket itself is authenticated (no token) | Deribit public/auth | ~15m (HTTP) · ~50m session (WS) | Deribit API docs |
Authenticate over the transport you will use: an HTTP token cannot authenticate a WebSocket, and vice versa.
API Keys - Private Access Sequence
- HTTP
- WebSocket
- You create a JWT, no round-trip to Coinbase. See creating a JWT.
- It lasts only ~120s, use a fresh JWT for every
public/authcall. - You need to provide the Deribit access token on each private method call.
- Refresh the Deribit access token every 15 minutes.
OAuth2 - Private Access Sequence
- HTTP
- WebSocket
- Retrieve an OAuth2 access token from
POST login.coinbase.com/oauth2/token. - It expires in 60 mins, use an unexpired OAuth2 access token with every
public/authcall. - You need to provide the Deribit access token on each private method call.
- Refresh the Deribit access token every 15 minutes.
- Refresh the OAuth2 access token every 1 hour.
POST login.coinbase.com/oauth2/tokenwithgrant_type=refresh_tokenand your refresh token; you get back a new access and refresh token.
Notes
- On WebSocket, the connection is the credential.
public/authreturns no token — private method calls are authorized by the authenticated socket itself. Re-sendpublic/authon the same socket to extend. If the socket drops, you’ll need to re-authenticate from scratch. - Request
offline_accessto get a refresh token (OAuth2). Coinbase only issues a refresh token if theoffline_accessscope was in your authorize request. Without it, the 1-hour access token cannot be refreshed and the user must re-authorize. See OAuth2 scopes and access & refresh tokens. - CDP keys can use Ed25519 or ECDSA algorithms. Ed25519 is recommended and works with direct API calls. ECDSA keys are only required for legacy / third party SDKs.
- Send
public/authas aPOSTso credentials stay out of the URL. Deribit acceptspublic/authover bothGETandPOST; usePOSTso the CDP JWT or OAuth2 access token travels in the request body, not the query string — keeping it out of URLs, browser history, and access logs. See OAuth2 security best practices.
Migration Checklist
Add a per-user routing branch
Existing Deribit users → native Deribit; new Coinbase users → new Coinbase endpoints.
Help
- Further assistance and timing — your Coinbase account manager.
- Method-level API detail — the Advanced Trade API reference.
- Best practices and detailed guides — Deribit’s documentation.