> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.crisscross.money/api-reference/collect/rate-locks/list-rate-locks/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.crisscross.money/_mcp/server. # List rate locks GET https://api.crisscross.money/v1/rate-locks Returns your rate locks, most recent first. Reference: https://docs.crisscross.money/api-reference/collect/rate-locks/list-rate-locks ## Authentication - `Authorization` header (bearer token, required) — Token obtained via the login flow. ## Request ### Query parameters - `status` (list of enum, optional) — Filter by one or more statuses. Repeatable — e.g. `?status=active`. - Allowed values: `active`, `expired`, `cancelled` - `base` (string, optional) — Filter by base currency (ISO 4217). - `quote` (string, optional) — Filter by quote currency (ISO 4217). - `limit` (integer, optional, default: 20) — Maximum number of results to return. Default 20, max 200. - `cursor` (string, optional) — Opaque cursor from `nextCursor` of a previous response. ## Response ### 200 A page of rate locks. - `rateLocks` (list of RateLock, required) - `nextCursor` (string, required, nullable) — Opaque cursor for the next page. `null` when the list is exhausted. - `hasMore` (boolean, required) — Convenience flag. `false` when `nextCursor` is `null`. ## Errors ### 400 Bad Request Error Bad request — validation or malformed request. - `message` (string, required) — Human-readable description of what went wrong. For logs and display — do not parse. - `error` (string, required) — Error category, typically the HTTP reason phrase (e.g. "Bad Request", "Unauthorized", "Not Found", "Unprocessable Entity", "Service Unavailable"). - `statusCode` (integer, required) — HTTP status code, mirroring the response header. The response header is the source of truth. ### 401 Unauthorized Error Unauthorized — missing or invalid token. - `message` (string, required) — Human-readable description of what went wrong. For logs and display — do not parse. - `error` (string, required) — Error category, typically the HTTP reason phrase (e.g. "Bad Request", "Unauthorized", "Not Found", "Unprocessable Entity", "Service Unavailable"). - `statusCode` (integer, required) — HTTP status code, mirroring the response header. The response header is the source of truth. ## Types ### RateLock - `rateLockId` (string, required) - `status` (enum, required) — - `active` — usable. - `expired` — past `expiresAt`. Terminal. - `cancelled` — invalidated before expiry; see `cancellationReason`. Terminal. `expired` and `cancelled` are permanent — a lock never returns to `active`. A lock at or past `expiresAt` is invalid even if `status` still reads `active`. - Allowed values: `active`, `expired`, `cancelled` - `base` (string, required) — Base currency (ISO 4217). - `quote` (string, required) — Quote currency (ISO 4217). - `midRate` (string, required) — Reference mid-market rate the lock was priced from. `1 base = quote`. - `markupBps` (integer, required) — The markup applied over the mid, in basis points (100 bps = 1%). - `allInRate` (string, required) — The rate you transact at: mid plus markup. This is the rate carried onto every transaction that uses the lock. `1 base = quote`. - `createdAt` (datetime, required) - `expiresAt` (datetime, required) — End of the lock's validity window. The lock is invalid from this time even if `status` still reads `active`. - `cancellationReason` (enum, optional) — Why the lock was cancelled. Present only when `status` is `cancelled`. `market_drift` — the rate moved beyond the allowed tolerance. `requested` — you cancelled the lock yourself via the cancel endpoint. - Allowed values: `market_drift`, `requested` ## Examples **Response** ```json { "rateLocks": [ { "rateLockId": "rlk_550e8400-e29b-41d4-a716-446655440000", "status": "active", "base": "USD", "quote": "KES", "midRate": "130.00", "markupBps": 200, "allInRate": "132.60", "createdAt": "2026-06-24T10:30:00Z", "expiresAt": "2026-06-24T22:30:00Z" } ], "nextCursor": null, "hasMore": false } ``` **SDK Code** ```python listRateLocks_example import requests url = "https://api.crisscross.money/v1/rate-locks" headers = {"Authorization": "Bearer "} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript listRateLocks_example const url = 'https://api.crisscross.money/v1/rate-locks'; const options = {method: 'GET', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go listRateLocks_example package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.crisscross.money/v1/rate-locks" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby listRateLocks_example require 'uri' require 'net/http' url = URI("https://api.crisscross.money/v1/rate-locks") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java listRateLocks_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api.crisscross.money/v1/rate-locks") .header("Authorization", "Bearer ") .asString(); ``` ```php listRateLocks_example request('GET', 'https://api.crisscross.money/v1/rate-locks', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ``` ```csharp listRateLocks_example using RestSharp; var client = new RestClient("https://api.crisscross.money/v1/rate-locks"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", "Bearer "); IRestResponse response = client.Execute(request); ``` ```swift listRateLocks_example import Foundation let headers = ["Authorization": "Bearer "] let request = NSMutableURLRequest(url: NSURL(string: "https://api.crisscross.money/v1/rate-locks")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```