API Reference
The 30 operations are listed below, grouped by tag.
Schemas model the responses as Steam returns them, including the structured endpoints that answer with literal null, the routes that answer with HTML instead of JSON, and the optional asset, fee, property, and accessory fields whose presence depends on the application and item class.
Search filters are documented in full under Search filters .
Discovery Search, autocomplete, and the filter metadata that drives them.
Search is expressed two ways. `GET /market/search` takes the selection as a query string and
returns a page; `POST /market/search` takes the same selection as JSON and returns data.
The query-string form is shareable but cannot express price bounds, numeric asset-property
ranges, or paging, so non-trivial searches belong on the POST form.
Filters come in three kinds:
- **Catalog tags** — `category_{Category}` in the query string, `filters` in the body.
Selected by tag internal name, such as `CSGO_Type_SniperRifle` or `WearCategory0`.
- **Applied accessories** — `accessory_{Category}` in the query string, `accessoryFilters`
in the body. Selected by display name, such as `Charm | Stitch-Loaded`, with `$any$` and
`$none$` sentinels.
- **Numeric asset properties** — `propertyFilters` in the body only, as inclusive ranges.
Repeating a query parameter, or listing several values in one body array, ORs those values.
Different categories are ANDed. Categories, tags, and accessory names are per-application
and change with game updates; `GET /market/appfacets/{appid}` and
`GET /market/appaccessories/{appid}` return the current vocabulary with localized labels
and match counts.
Listings Listing pages, listing data, order depth, and recent activity. Pricing Current and historical Market prices. Account Market eligibility, billing state, and active listings. Mutations Buying and selling: purchase a listing outright, place and cancel buy orders, list an owned
asset, and remove a listing.
Every operation here is a form POST authenticated by session cookies and guarded by a
`sessionid` CSRF field. Steam also checks browser-shaped headers; see
[Mutation headers](/guide/mutations) for the set a non-browser client has to send.
Confirmations Steam Guard mobile confirmations. A sell listing is not live until confirmed, so this is part
of the sell path rather than a separate concern.
These routes live under `/mobileconf`, not `/market`, and authenticate with an HMAC of the
account's `identity_secret` rather than the `sessionid` CSRF field.