All articles
Brokers

Broker Token Expired: What To Do Right Now

Your broker session has expired and orders are failing. The fix takes under a minute, and this page covers it first, then how to tell it apart from an IP problem.

Arthalab5 min read
Open Broker Setup and complete your broker's login again. That is the fix, and it takes under a minute. Everything below is for after you have done it.

The fix, step by step

1

Open Broker Setup

The connection will show as expired or disconnected.
2

Complete the broker login

Most brokers redirect you to authenticate and return you with a fresh session.
3

Confirm the connection shows as active

Do not assume — look.
4

Start your bots

Renewing the session does not start them. That is a separate action.
5

Check the logs after your entry time

Confirm the strategy actually evaluated rather than assuming it did.
Step four catches people repeatedly. Deploying, starting and logging in are three different things, and fixing one does not do the others.

Why it expired

Indian broker API sessions expire daily by design. A permanent token would be a permanent key to your account, so expiry limits how long a leaked one stays useful.
Tokens reset in the early morning. In practice the window traders use runs from around 6:00 am to the 9:15 open, and logging in at 9:14 for a 9:20 entry leaves no margin for a slow login page.

The exception

On Arthalab, XTS is the exception — its session is renewed server-side, so there is no daily step for you there.

Is it actually the token?

Session and address problems produce similar errors, and the fixes are completely different. The error text usually separates them.
ClueTokenIP address
Error names a session or loginLikelyUnlikely
Error says unauthorised or forbidden onlyPossibleLikely
Broke overnight with nothing changedVery likelyPossible
Broke after changing network or routerNoVery likely
Fixed by logging in againConfirms itNo effect
Check the token first when it is ambiguous. It expires every single day, which makes it the higher-probability cause, and the fix takes a minute. If logging in changes nothing, the address is the next place to look.

What not to do

  • Do not regenerate your API key. It does not expire on its own, and regenerating introduces a second problem on top of the first.
  • Do not re-enter credentials before confirming the login was the issue.
  • Do not retry the order repeatedly. It will keep failing until the session is renewed.
  • Do not assume starting a bot renews the session. It does not.

The morning window, practically

Most people treat the login as something to do before the open. The sequence works better if you treat it as something to do before your first entry, with a margin.
TimeWhat should have happened
By 8:30Broker logged in, connection confirmed active
By 8:45Bots started, scheduler confirmed if you use one
By 9:10Nothing left to do
After your entry timeLogs checked — confirm it actually evaluated
If something failedFixed, or the day consciously skipped
The last row matters. A day you skip deliberately costs you one day's trades. A day you spend improvising at 9:18 can cost more than that, because a half-fixed setup produces entries without the exits you expected.

Preventing it tomorrow

  • Treat 8:30 as your deadline, not 9:10
  • Connect Telegram alerts — a morning message goes out when a token has expired
  • Bookmark the broker login page rather than searching for it
  • Decide in advance what you do if you cannot log in at all that day
  • Use the scheduler so the login is the only manual step
The fourth item is worth deciding once, calmly. If the honest answer is that you miss the day, that is fine — it should be a decision rather than an improvisation at 9:12.

The short version

  • Open Broker Setup and log in again — that is the fix
  • Then start your bots; renewing the session does not do it
  • Sessions expire daily by design, resetting in the early morning
  • If logging in changes nothing, check your whitelisted IP next
  • Never regenerate the API key first — it does not expire on its own

Frequently asked questions

Open Broker Setup and complete the broker login again. It takes under a minute. Then start your bots, because renewing the session does not start them.

Indian broker API sessions expire daily so that a leaked token stops being useful at the next reset. It is a security design rather than a platform limitation.

No. If your entry time has passed, that trade did not happen. Log in so the rest of the day works and adjust your morning deadline.

An expired session usually names the session or login in the error. An unregistered address usually reads as unauthorised or forbidden. If logging in fixes it, it was the token.

No. API keys do not expire on their own, and regenerating one that was fine adds a second problem to debug alongside the first.

On Arthalab, XTS does — its session is renewed server-side. The self-serve brokers all require a daily login.

Start with a free 3-day trial

Build a strategy, backtest it and run it on paper — no broker, no IP and no money needed to try it.

Ask us on Telegram
Broker Token Expired: What To Do Right Now | Arthalab — Algo Trading India