# Develop with Gunbot

Gunbot exposes a REST API from each user-operated Gunbot installation. The API is not hosted at `gunbot.com`: replace the example server in the API description with the hostname and GUI port of the Gunbot instance you are authorized to control. Use HTTPS for non-local connections.

## Choose an integration path

- Use the [JavaScript and TypeScript SDK](https://www.npmjs.com/package/gunbot-sdk-js) for typed Node.js, browser, or TypeScript integrations.
- Use the [Python SDK](https://github.com/gunthardeniro/gunbot-sdk-python) for Python automation and analysis.
- Use the [OpenAPI 3.0 specification](https://www.gunbot.com/openapi.yaml) to inspect the full schema, generate a client, or create function-calling tools.
- Use [custom JavaScript strategies](https://www.gunbot.com/support/docs/custom-strategies/what-are-custom-strategies/) when logic should execute inside Gunbot.

## REST API quickstart

1. Install and run Gunbot on a machine controlled by the user.
2. Configure HTTPS before connecting over a network.
3. Authenticate through `/api/v1/auth/login` and retain the returned JWT securely.
4. Send the JWT as `Authorization: Bearer <token>` to protected endpoints.
5. Start with read operations such as authentication status, balances, market data, or PNL before attempting configuration changes or orders.

The API covers authentication, balances and assets, configuration, files, market and chart data, PNL, system control, license management, and trading orders. Consult the [REST API introduction](https://www.gunbot.com/support/docs/rest-api/gunbot-api-intro/), [authentication guide](https://www.gunbot.com/support/docs/rest-api/api-auth/), and [one-page reference](https://www.gunbot.com/support/docs/rest-api/onepage/) for operational details and examples.

## Safety and agent use

Never send exchange secrets, wallet private keys, license keys, passwords, or bearer tokens to `gunbot.com`. Credentials belong only in the user's authorized Gunbot installation and exchange configuration. Treat endpoints that place or cancel orders, alter configuration, manage licenses, write files, or start and stop trading as consequential actions: show the intended instance and parameters and obtain user confirmation before execution.

The OpenAPI file is mirrored byte-for-byte from the [official Gunbot JavaScript SDK repository](https://github.com/gunthardeniro/gunbot-sdk-js/blob/main/openapi.yaml), which is generated from that specification.
