All articles
Brokers

Broker API Access in India: What It Is and What It Costs

What broker API access actually provides, the four credentials involved and how long each lasts, what brokers typically charge, and the limits that affect multi-leg strategies.

Arthalab6 min read
Broker API access is permission for software to do what you could already do by hand: read your account and place orders in it. It is not a different kind of account and it does not change your brokerage, your margin or your rights.

The four pieces

Understanding which credential does what explains most of the setup and most of the failures.
PieceWhat it provesHow long it lasts
API keyWhich application is callingUntil you regenerate it
API secretThat the call came from that applicationUntil you regenerate it
Access tokenThat a human logged in todayOne trading day
Whitelisted IPThat the call came from a known placeUntil the address changes
Three of the four are stable. The access token is the one that expires daily, which is why the morning login exists and why it cannot be skipped.

What API access permits

  • Reading. Positions, orders, balance, and market data where the broker provides it.
  • Placing orders. New orders of the types the broker permits through the API.
  • Modifying and cancelling. Existing orders, subject to the broker's rules.
  • Nothing else. No withdrawals, no changes to your bank details, no transfers.
That last line is structural rather than a policy. Money leaves a broker account through a channel API credentials do not reach.

What brokers charge

This varies and it changes, so the only reliable answer is your broker's current API pricing page.

The questions to ask

What to check when you look:
  • Is API access included in the account or charged separately?
  • Is it a one-off, monthly, or per-order charge?
  • Does the charge differ for market data versus order placement?
  • Are there limits on the number of API apps?
  • Is there a separate historical data charge?

Rate limits, which matter more than people expect

Brokers cap how many API requests you can make per second and per day. For a single strategy placing two legs this never comes up. For several strategies entering simultaneously, it can.
The symptom is subtle: legs arriving out of sequence, or a leg failing while others succeed, on days when several strategies act at once. It rarely shows up in testing with one strategy and becomes visible the day you run three.

Why it matters for multi-leg strategies

A multi-leg entry fires several orders at once. A rejected leg leaves a different position than the one you designed, and a rate limit is one of the less obvious ways that happens.

Order types through the API

Not every order type available in a broker's app is available through its API, and some brokers restrict certain types specifically for automated flow.
Market orders are the common restriction. The reasoning is sound — a market order from a misbehaving algo can execute at a price nobody intended — and using limit orders is the normal answer.

Check before you build

Check which types your broker permits before building a strategy that depends on one. A strategy requiring an order type the API does not offer is not a strategy you can run there.

Which brokers offer it

Most major Indian brokers now provide API access in some form. What differs is documentation quality, reliability under load, and what is charged.
Arthalab supports Zerodha, Upstox, Groww and Dhan for self-serve connection, with XTS available on request. The broker guide covers what to weigh between them.

A useful proxy

Documentation quality is a better proxy than it sounds. A broker with clear, current API docs usually treats the API as a product rather than an obligation, and that correlates with it working on busy mornings.

Security, briefly

  • Generate credentials yourself in the broker's portal
  • Whitelist a specific address, not a broad range
  • Never send credentials over chat, email or an unredacted screenshot
  • Create one API app per platform where possible
  • Review and remove unused API apps periodically
The credentials guide covers what a leaked key could and could not do, and what to do if you suspect exposure.

The short version

  • API access lets software read your account and place orders, nothing more
  • Four credentials: key, secret, daily token and whitelisted address
  • Charges vary by broker and change — check theirs directly
  • Rate limits can affect multi-leg entries, especially with several strategies
  • Not every order type is available through the API; market orders are often restricted
  • Documentation quality is a reasonable proxy for reliability

Frequently asked questions

Permission for software to read your account and place orders in it. It is not a separate account type and does not change your brokerage, margin or rights.

No. Some include it and some charge separately, as a monthly fee or otherwise. Check your broker's current API pricing directly, since it changes.

No. It covers reading and order placement only. Withdrawals go through a separate channel that API credentials do not reach.

Caps on how many requests you can make per second or per day. They rarely matter for one strategy and can affect multi-leg entries when several strategies act at once.

Some brokers restrict them for automated flow, because a market order from a misbehaving algo can execute at a price nobody intended. Limit orders are the normal answer.

This changes, and documentation quality is a reasonable proxy — a broker treating the API as a product usually has clear, current docs and better behaviour under load.

It depends on the broker. Where several are allowed, one per platform is good practice so you can revoke one without disrupting the others.

Start with a free 3-day trial

Build a strategy, backtest it and run it on paper — no broker, no IP and no money needed to try it.

Ask us on Telegram
Broker API Access in India: What It Is and What It Costs | Arthalab — Algo Trading India