The fix, step by step
Open Broker Setup
Complete the broker login
Confirm the connection shows as active
Start your bots
Check the logs after your entry time
Why it expired
The exception
Is it actually the token?
| Clue | Token | IP address |
|---|---|---|
| Error names a session or login | Likely | Unlikely |
| Error says unauthorised or forbidden only | Possible | Likely |
| Broke overnight with nothing changed | Very likely | Possible |
| Broke after changing network or router | No | Very likely |
| Fixed by logging in again | Confirms it | No effect |
What not to do
- Do not regenerate your API key. It does not expire on its own, and regenerating introduces a second problem on top of the first.
- Do not re-enter credentials before confirming the login was the issue.
- Do not retry the order repeatedly. It will keep failing until the session is renewed.
- Do not assume starting a bot renews the session. It does not.
The morning window, practically
| Time | What should have happened |
|---|---|
| By 8:30 | Broker logged in, connection confirmed active |
| By 8:45 | Bots started, scheduler confirmed if you use one |
| By 9:10 | Nothing left to do |
| After your entry time | Logs checked — confirm it actually evaluated |
| If something failed | Fixed, or the day consciously skipped |
Preventing it tomorrow
- Treat 8:30 as your deadline, not 9:10
- Connect Telegram alerts — a morning message goes out when a token has expired
- Bookmark the broker login page rather than searching for it
- Decide in advance what you do if you cannot log in at all that day
- Use the scheduler so the login is the only manual step
The short version
- Open Broker Setup and log in again — that is the fix
- Then start your bots; renewing the session does not do it
- Sessions expire daily by design, resetting in the early morning
- If logging in changes nothing, check your whitelisted IP next
- Never regenerate the API key first — it does not expire on its own
Frequently asked questions
Open Broker Setup and complete the broker login again. It takes under a minute. Then start your bots, because renewing the session does not start them.
Indian broker API sessions expire daily so that a leaked token stops being useful at the next reset. It is a security design rather than a platform limitation.
No. If your entry time has passed, that trade did not happen. Log in so the rest of the day works and adjust your morning deadline.
An expired session usually names the session or login in the error. An unregistered address usually reads as unauthorised or forbidden. If logging in fixes it, it was the token.
No. API keys do not expire on their own, and regenerating one that was fine adds a second problem to debug alongside the first.
On Arthalab, XTS does — its session is renewed server-side. The self-serve brokers all require a daily login.
Start with a free 3-day trial
Build a strategy, backtest it and run it on paper — no broker, no IP and no money needed to try it.

