Odos moved to read-only mode on July 27, 2026 and all company-operated services shut down permanently on July 30, 2026. This SDK is retained only for archival and reference use.
Do not use this crate for new live trading integrations. Existing users should migrate away from Odos-dependent flows and assume API-backed SDK functionality can fail or disappear.
No versions are actively supported.
Support Policy:
- Feature work, chain updates, endpoint fixes, and new integration support are closed.
- Security reports may still be reviewed on a best-effort basis, but there is no response SLA and no guarantee of a patched release.
To check the current version and release notes, see Releases or crates.io.
If you discover a security issue in the archived code, please report it responsibly.
DO NOT open a public GitHub issue for security vulnerabilities.
Instead, please report security vulnerabilities through:
- GitHub Security Advisories: Report a vulnerability
This is the preferred and most secure method for reporting vulnerabilities.
Include in your report:
- Description: Clear description of the vulnerability
- Impact: What could an attacker achieve?
- Reproduction: Step-by-step instructions to reproduce
- Version: Affected version(s) of odos-sdk
- Proposed Fix: (Optional) Suggestions for fixing the issue
- Acknowledgment: We will acknowledge receipt within 48 hours
- Assessment: We will assess the report and determine severity within 5 business days
- Updates: We will provide regular updates on our progress
- Fix Timeline:
- Critical: Patch within 7 days
- High: Patch within 30 days
- Medium: Patch within 90 days
- Low: Addressed in next regular release
- Disclosure: We will coordinate with you on public disclosure timing
Security advisories will be published through:
- GitHub Security Advisories
- RUSTSEC advisory database
- Release notes and CHANGELOG.md
CRITICAL: Never expose your Odos API key in public repositories, logs, or error messages.
use odos_sdk::{OdosClient, ClientConfig, ApiKey};
use std::env;
// ✅ GOOD: Load from environment variable
let api_key = env::var("ODOS_API_KEY")
.ok()
.and_then(|k| k.parse::<ApiKey>().ok());
let config = ClientConfig {
api_key,
..Default::default()
};
let client = OdosClient::with_config(config)?;// ❌ BAD: Hardcoded API key
let config = ClientConfig {
api_key: Some("your-api-key".parse().unwrap()), // NEVER DO THIS
..Default::default()
};Use dotenvy to load API keys from .env files:
use dotenvy::dotenv;
// Load .env file
dotenv().ok();
// Access API key
let api_key = std::env::var("ODOS_API_KEY")
.ok()
.and_then(|k| k.parse().ok());Important: Add .env to your .gitignore:
.env
.env.local
.env.*.localThe SDK implements client-side retry logic, but you should also implement application-level rate limiting:
use odos_sdk::{RetryConfig, RetryPredicate};
// Conservative retry configuration for production
let retry_config = RetryConfig {
max_retries: 3,
initial_backoff_ms: 200,
retry_server_errors: true,
retry_predicate: RetryPredicate::Default,
};
let client = OdosClient::with_retry_config(retry_config)?;Always validate user inputs before constructing API requests:
use odos_sdk::QuoteRequest;
use alloy_primitives::{Address, U256};
// Validate addresses
let token_address = address_str.parse::<Address>()
.map_err(|_| "Invalid token address")?;
// Validate amounts (prevent overflow)
let amount = U256::try_from(amount_str)
.map_err(|_| "Invalid amount")?;
// Validate slippage (prevent excessive slippage)
let slippage = slippage_percent.max(0.1).min(50.0);
let quote = QuoteRequest::builder()
.chain_id(chain_id)
.input_tokens(vec![(token_address, amount).into()])
// ... rest of request
.build();Never expose sensitive information in error messages:
use odos_sdk::OdosError;
match client.quote(&request).await {
Ok(quote) => {
// Handle success
}
Err(e) => {
// ✅ GOOD: Log internally, show generic message to users
tracing::error!("Quote request failed: {}", e);
return Err("Failed to get quote. Please try again.".into());
}
}// ❌ BAD: Exposing internal error details to users
match client.quote(&request).await {
Err(e) => panic!("Error: {}", e), // May leak trace IDs, URLs, etc.
}Configure appropriate timeouts to prevent resource exhaustion:
use std::time::Duration;
let config = ClientConfig {
timeout: Duration::from_secs(30),
connect_timeout: Duration::from_secs(10),
..Default::default()
};The SDK always uses HTTPS for API communication. The underlying reqwest client:
- Validates TLS certificates by default
- Uses system certificate store
- Enforces secure cipher suites
Never disable certificate validation in production.
We regularly audit and update dependencies. Users should:
- Update frequently: Run
cargo updateregularly - Monitor advisories: Use
cargo auditto check for vulnerabilities - Review changes: Read CHANGELOG.md before updating
Check for known vulnerabilities:
# Install cargo-audit
cargo install cargo-audit
# Run audit
cargo audit
# Check for specific advisories
cargo audit --deny warningsWe maintain a minimal dependency footprint to reduce attack surface. See DEPENDENCIES.md for detailed rationale for each dependency.
This SDK does not perform cryptographic operations directly. It relies on:
- alloy ecosystem: For Ethereum-related cryptography (signing, address derivation)
- reqwest + rustls: For TLS/HTTPS connections
Users performing transaction signing should:
- Use hardware wallets when possible
- Never expose private keys in logs or error messages
- Use
alloy-signerbest practices for key management
The SDK connects to:
https://api.odos.xyz(Public API)https://enterprise-api.odos.xyz(Enterprise API)
Important: The SDK does not support custom endpoints to prevent MitM attacks via endpoint injection.
The SDK uses connection pooling for performance. Default settings:
- Maximum 20 connections
- 90-second idle timeout
- Automatic cleanup of stale connections
If using HTTP proxies, ensure:
- Proxy connection uses TLS
- Proxy is trusted and properly configured
- Sensitive data is not logged by proxy
If you suspect your application using odos-sdk has been compromised:
- Isolate: Immediately isolate affected systems
- Rotate Keys: Rotate any API keys that may have been exposed
- Investigate: Determine scope of compromise
- Notify: Report via GitHub Security Advisories if the SDK itself is implicated
- Update: Update to latest patched version if vulnerability was in SDK
Before deploying applications using odos-sdk to production:
- API keys loaded from environment variables, never hardcoded
-
.envfiles added to.gitignore - Input validation implemented for all user inputs
- Error messages do not expose sensitive information
- Appropriate timeouts configured
- Rate limiting implemented at application level
- TLS certificate validation enabled (default)
- Dependencies audited with
cargo audit - Logging configured to exclude sensitive data
- Monitoring and alerting configured for error rates
- Incident response plan documented
For security-related questions or concerns:
- Security Reports: GitHub Security Advisories
- General Questions: GitHub Discussions
- Project Issues: https://github.com/suchapalaver/odos-sdk/issues