> ## Documentation Index
> Fetch the complete documentation index at: https://docs.portfobit.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Start an internal CEX transfer

> Requires `transfer:write`, an active Plus or Pro subscription, explicit user confirmation, `Idempotency-Key`, and a current `otp_code`. The transfer is restricted to two account partitions of the same CEX account.



## OpenAPI

````yaml /openapi/portfobit-openapi.yaml post /accounts/{account_id}/internal-transfers
openapi: 3.1.0
info:
  title: Portfobit Open API
  version: 0.1.0
  description: >
    Public REST API for direct API clients, CI, scripts, service accounts,
    third-party agents, and developer integrations.

    Public REST requests use scoped Portfobit Open API keys. OAuth access tokens
    issued for the Portfobit MCP resource are not accepted by `/api/v1/*`
    endpoints.

    Portfobit is crypto-CEX-only. Financial values are decimal strings and
    timestamps are RFC 3339 UTC strings.

    The API never supports withdrawals, external-address transfers,
    cross-exchange transfers, or P2P transfers.
servers:
  - url: https://api.portfobit.com/api/v1
security:
  - bearerAuth: []
tags:
  - name: Context
  - name: Accounts
  - name: Portfolios
  - name: Valuation
  - name: Activity
  - name: Trading
  - name: Market data
  - name: Support
paths:
  /accounts/{account_id}/internal-transfers:
    post:
      tags:
        - Trading
      summary: Start an internal CEX transfer
      description: >-
        Requires `transfer:write`, an active Plus or Pro subscription, explicit
        user confirmation, `Idempotency-Key`, and a current `otp_code`. The
        transfer is restricted to two account partitions of the same CEX
        account.
      operationId: startInternalTransfer
      parameters:
        - $ref: '#/components/parameters/AccountId'
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        $ref: '#/components/requestBodies/InternalTransferRequest'
      responses:
        '200':
          $ref: '#/components/responses/InternalTransferResponse'
        '400':
          $ref: '#/components/responses/InvalidProtectedActionResponse'
        '403':
          $ref: '#/components/responses/ProtectedActionForbiddenResponse'
        '409':
          $ref: '#/components/responses/IdempotencyConflictResponse'
        '429':
          $ref: '#/components/responses/ActionRateLimitedResponse'
        default:
          $ref: '#/components/responses/ErrorResponse'
components:
  parameters:
    AccountId:
      name: account_id
      in: path
      required: true
      schema:
        type: string
      description: Connected CEX account ID.
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      schema:
        type: string
        minLength: 1
        maxLength: 255
      description: Opaque retry key, unique to the same user, method, and path.
  requestBodies:
    InternalTransferRequest:
      required: true
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/InternalTransferRequest'
  responses:
    InternalTransferResponse:
      description: Protected same-CEX internal-transfer response.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/InternalTransferResponseSchema'
    InvalidProtectedActionResponse:
      description: Order or internal-transfer parameters are invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/InvalidProtectedActionResponseSchema'
    ProtectedActionForbiddenResponse:
      description: >-
        The action is blocked by subscription, trading OTP, CEX permission, or
        risk policy. `risk_blocked` responses include the standard risk object
        in `error.details.risk`.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ProtectedActionForbiddenResponseSchema'
    IdempotencyConflictResponse:
      description: The idempotency key was previously used with a different request body.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/IdempotencyConflictResponseSchema'
    ActionRateLimitedResponse:
      description: The protected-action rate or quota limit has been reached.
      headers:
        Retry-After:
          schema:
            type: integer
          description: Seconds until another request may be attempted.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ActionRateLimitedResponseSchema'
    ErrorResponse:
      description: Error response
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
  schemas:
    InternalTransferRequest:
      type: object
      required:
        - from_account_type
        - to_account_type
        - asset
        - amount
        - otp_code
      properties:
        from_account_type:
          type: string
        to_account_type:
          type: string
        asset:
          type: string
        amount:
          type: string
        otp_code:
          type: string
          pattern: ^[0-9]{6}$
          writeOnly: true
        client_order_id:
          type: string
      additionalProperties: false
    InternalTransferResponseSchema:
      type: object
      required:
        - data
        - meta
      properties:
        data:
          type: object
          required:
            - id
            - action_type
            - status
            - action_summary
            - provider_reference_id
            - failure_code
            - failure_message
            - risk
            - requested_at
            - completed_at
          properties:
            id:
              type: string
            action_type:
              type: string
            status:
              type: string
            action_summary:
              type: object
              required:
                - account_id
                - from_account_type
                - to_account_type
                - asset
                - amount
              properties:
                account_id:
                  type: string
                from_account_type:
                  type: string
                to_account_type:
                  type: string
                asset:
                  type: string
                amount:
                  type: string
            provider_reference_id:
              type:
                - string
                - 'null'
            failure_code:
              type:
                - string
                - 'null'
            failure_message:
              type:
                - string
                - 'null'
            risk:
              type: object
              required:
                - status
                - level
                - model_version
                - as_of
                - reasons
                - metrics
              properties:
                status:
                  type: string
                level:
                  type: string
                model_version:
                  type:
                    - string
                    - 'null'
                as_of:
                  type:
                    - string
                    - 'null'
                  format: date-time
                reasons:
                  type: array
                  items:
                    type: object
                metrics:
                  type: object
                  required:
                    - gross_exposure
                    - gross_leverage
                    - margin_utilization
                  properties:
                    gross_exposure:
                      type: string
                    gross_leverage:
                      type: string
                    margin_utilization:
                      type: string
            requested_at:
              type: string
              format: date-time
            completed_at:
              type: string
              format: date-time
        meta:
          type: object
          required:
            - request_id
            - generated_at
          properties:
            request_id:
              type: string
            generated_at:
              type: string
              format: date-time
      example:
        data:
          id: act_01J2K8X
          action_type: internal_transfer
          status: succeeded
          action_summary:
            account_id: acc_01H8XFK9A
            from_account_type: spot
            to_account_type: swap
            asset: USDT
            amount: '1000'
          provider_reference_id: transfer_123
          failure_code: null
          failure_message: null
          risk:
            status: available
            level: low
            model_version: risk_v1
            as_of: '2026-08-07T08:05:00Z'
            reasons: []
            metrics:
              gross_exposure: '120000'
              gross_leverage: '1.94'
              margin_utilization: '0.32'
          requested_at: '2026-08-07T08:05:00Z'
          completed_at: '2026-08-07T08:05:01Z'
        meta:
          request_id: req_01J2K8B7QW
          generated_at: '2026-08-07T08:05:01Z'
    InvalidProtectedActionResponseSchema:
      type: object
      required:
        - error
        - meta
      properties:
        error:
          type: object
          required:
            - code
            - message
            - details
          properties:
            code:
              type: string
              enum:
                - invalid_order_parameters
                - invalid_internal_transfer
            message:
              type: string
            details:
              type: object
              required: []
              properties: {}
        meta:
          type: object
          required:
            - request_id
            - generated_at
          properties:
            request_id:
              type: string
            generated_at:
              type: string
              format: date-time
      example:
        error:
          code: invalid_order_parameters
          message: A limit order requires a price.
          details: {}
        meta:
          request_id: req_01J2K8B7QW
          generated_at: '2026-08-08T08:00:00Z'
    ProtectedActionForbiddenResponseSchema:
      type: object
      required:
        - error
        - meta
      properties:
        error:
          type: object
          required:
            - code
            - message
            - details
          properties:
            code:
              type: string
              enum:
                - plan_required
                - trading_otp_required
                - trading_otp_invalid
                - provider_permission_denied
                - risk_blocked
            message:
              type: string
            details:
              type: object
              required: []
              properties:
                risk:
                  $ref: '#/components/schemas/Risk'
        meta:
          type: object
          required:
            - request_id
            - generated_at
          properties:
            request_id:
              type: string
            generated_at:
              type: string
              format: date-time
      example:
        error:
          code: trading_otp_required
          message: A current trading OTP is required before this action can run.
          details: {}
        meta:
          request_id: req_01J2K8B7QW
          generated_at: '2026-08-08T08:00:00Z'
    IdempotencyConflictResponseSchema:
      type: object
      required:
        - error
        - meta
      properties:
        error:
          type: object
          required:
            - code
            - message
            - details
          properties:
            code:
              type: string
            message:
              type: string
            details:
              type: object
              required: []
              properties: {}
        meta:
          type: object
          required:
            - request_id
            - generated_at
          properties:
            request_id:
              type: string
            generated_at:
              type: string
              format: date-time
      example:
        error:
          code: idempotency_conflict
          message: This Idempotency-Key was already used for a different request.
          details: {}
        meta:
          request_id: req_01J2K8B7QW
          generated_at: '2026-08-08T08:00:00Z'
    ActionRateLimitedResponseSchema:
      type: object
      required:
        - error
        - meta
      properties:
        error:
          type: object
          required:
            - code
            - message
            - details
          properties:
            code:
              type: string
            message:
              type: string
            details:
              type: object
              required: []
              properties: {}
        meta:
          type: object
          required:
            - request_id
            - generated_at
          properties:
            request_id:
              type: string
            generated_at:
              type: string
              format: date-time
      example:
        error:
          code: action_rate_limited
          message: This protected action is temporarily rate limited.
          details: {}
        meta:
          request_id: req_01J2K8B7QW
          generated_at: '2026-08-08T08:00:00Z'
    ErrorEnvelope:
      type: object
      required:
        - error
        - meta
      properties:
        error:
          $ref: '#/components/schemas/Error'
        meta:
          $ref: '#/components/schemas/Meta'
    Risk:
      type: object
      required:
        - status
        - level
        - reasons
        - metrics
      properties:
        status:
          type: string
          enum:
            - available
            - partial
            - unavailable
            - not_applicable
          description: >-
            `not_applicable` means there was no applicable specialized risk
            assessment; it does not mean low risk.
        level:
          type: string
          enum:
            - low
            - medium
            - high
            - critical
            - unknown
        model_version:
          type:
            - string
            - 'null'
        as_of:
          type:
            - string
            - 'null'
          format: date-time
        reasons:
          type: array
          items:
            type: object
            required:
              - code
              - severity
              - message
            properties:
              code:
                type: string
              severity:
                type: string
              message:
                type: string
        metrics:
          type: object
          additionalProperties:
            type:
              - string
              - 'null'
          description: >-
            Includes applicable derived exposure, margin, leverage,
            concentration, and liquidation-distance metrics.
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
        message:
          type: string
        details:
          type: object
          additionalProperties: true
    Meta:
      type: object
      required:
        - request_id
        - generated_at
      properties:
        request_id:
          type: string
        generated_at:
          type: string
          format: date-time
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Portfobit Open API key

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.