Personal portfolio access
Explicit permission
Section titled “Explicit permission”Use a personal access token (csf_pat_…) with portfolio:read, not a project key (csf_live_…). The owner must select specific portfolios and consent to read-only access. A shared portfolio URL, Steam ID or portfolio ID does not grant this permission.
Tokens are revocable, expire within 90 days, and are shown only at creation or rotation. Rotation invalidates the previous secret immediately without extending its expiry. Store the token in a server-side secret, never in prompts or browser code.
Read the connected portfolio
Section titled “Read the connected portfolio”GET /v1/me/portfolioslists only the token’s selected portfolios that still belong to its owner.GET /v1/me/portfolios/{portfolio_id}returns settings.- Add
/holdingsfor inventory lots or/transactionsfor ledger rows. - Add
/history?from=2026-09-01&to=2026-09-28for available daily valuation snapshots.
List methods return meta.next_page; pass it unchanged as after. Keep the same filters while paginating. History and transactions accept windows up to 366 days, defaulting to the last 31 days. Unauthorized, unselected and nonexistent portfolio IDs all return 404 to an otherwise valid personal token. Project keys receive 403 on private methods.
Keep financial meaning intact
Section titled “Keep financial meaning intact”- Monetary fields are integer USD cents, even if
display_currencyis RUB. - A holding’s
unit_cost_centsis its per-item purchase basis, not its current market price. Null means unknown;cost_estimatedremains explicit. - Transactions are this owner’s stored ledger entries, not marketplace-wide executed sales. They are not a complete realized-profit calculation.
- History retains the actual
price_sourceon each point. Null identifies unknown legacy sources; never replace it with the portfolio’s current provider. - Changes in total portfolio value are not investment returns: deposits, withdrawals and inventory changes can affect totals. Do not label these snapshots TWR or IRR.
Notes, Steam account identifiers and external integration references are excluded from these API responses. All portfolio methods share the same account quota as market methods.