The four pieces
| Piece | What it proves | How long it lasts |
|---|---|---|
| API key | Which application is calling | Until you regenerate it |
| API secret | That the call came from that application | Until you regenerate it |
| Access token | That a human logged in today | One trading day |
| Whitelisted IP | That the call came from a known place | Until the address changes |
What API access permits
- Reading. Positions, orders, balance, and market data where the broker provides it.
- Placing orders. New orders of the types the broker permits through the API.
- Modifying and cancelling. Existing orders, subject to the broker's rules.
- Nothing else. No withdrawals, no changes to your bank details, no transfers.
What brokers charge
The questions to ask
- Is API access included in the account or charged separately?
- Is it a one-off, monthly, or per-order charge?
- Does the charge differ for market data versus order placement?
- Are there limits on the number of API apps?
- Is there a separate historical data charge?
Rate limits, which matter more than people expect
Why it matters for multi-leg strategies
Order types through the API
Check before you build
Which brokers offer it
A useful proxy
Security, briefly
- Generate credentials yourself in the broker's portal
- Whitelist a specific address, not a broad range
- Never send credentials over chat, email or an unredacted screenshot
- Create one API app per platform where possible
- Review and remove unused API apps periodically
The short version
- API access lets software read your account and place orders, nothing more
- Four credentials: key, secret, daily token and whitelisted address
- Charges vary by broker and change — check theirs directly
- Rate limits can affect multi-leg entries, especially with several strategies
- Not every order type is available through the API; market orders are often restricted
- Documentation quality is a reasonable proxy for reliability
Frequently asked questions
Permission for software to read your account and place orders in it. It is not a separate account type and does not change your brokerage, margin or rights.
No. Some include it and some charge separately, as a monthly fee or otherwise. Check your broker's current API pricing directly, since it changes.
No. It covers reading and order placement only. Withdrawals go through a separate channel that API credentials do not reach.
Caps on how many requests you can make per second or per day. They rarely matter for one strategy and can affect multi-leg entries when several strategies act at once.
Some brokers restrict them for automated flow, because a market order from a misbehaving algo can execute at a price nobody intended. Limit orders are the normal answer.
This changes, and documentation quality is a reasonable proxy — a broker treating the API as a product usually has clear, current docs and better behaviour under load.
It depends on the broker. Where several are allowed, one per platform is good practice so you can revoke one without disrupting the others.
Start with a free 3-day trial
Build a strategy, backtest it and run it on paper — no broker, no IP and no money needed to try it.

