The five steps
| Step | Where it happens | What you get |
|---|---|---|
| 1. Create an API app | Your broker's developer portal | An API key and secret |
| 2. Whitelist your address | The same API app | Orders from that address are accepted |
| 3. Add credentials | Arthalab, Broker Setup | The connection is configured |
| 4. Complete the broker login | A redirect to your broker | Today's session token |
| 5. Validate | Arthalab, Network tab | Proof the whole path works |
Step 1 — the API app
Step 2 — whitelisting
Before you whitelist anything
Step 3 — adding credentials
Step 4 — the broker login
The exception
Step 5 — validation
How long to allow
- Day one. Create the API app. Some brokers approve instantly, some take a day.
- Day one. Get your dedicated address and whitelist it.
- Day two. Add credentials, log in, validate. Read any error rather than retrying blindly.
- Day two onwards. Paper trade while the morning routine beds in.
- Week two. Go live at minimum size.
What goes wrong, by step
| Step | Common failure | Fix |
|---|---|---|
| API app | Approval pending | Wait — nothing downstream works until it is active |
| Whitelisting | Private address used instead of public | Use the address your platform shows |
| Whitelisting | Trailing space when pasting | Re-copy and check the field |
| Credentials | Key and secret transposed | Re-enter from the portal |
| Login | Not completed today | Complete it — this is the most common cause of everything |
| Validation | Balance too low | Add funds; the test places a real order |
Connecting more than one
Before you start
- A dedicated IP address that is genuinely reserved for you
- An active plan
- Access to your broker's developer portal
- A small balance for validation
- A day or two before you intend to trade live
The short version
- Five steps: API app, whitelist, credentials, login, validate
- Steps one and two happen once; the login happens every trading day
- Use the public address your platform shows, never your router's
- Expect to fail validation once — do not regenerate the key first
- Allow a day or two rather than doing it the morning you want to trade
Frequently asked questions
Allow a day or two. The API app may need approval, whitelisting has to be done, and a first validation failure is close to guaranteed. Doing it the morning you want to trade is how it goes wrong.
The public address your platform displays. The address in your router or machine network settings is a private local address the broker never sees.
If your broker allows it, yes. It lets you revoke one platform's access without disrupting others and makes unexpected activity attributable.
Usually the daily login was not completed, a stray character got into the pasted address, or a whitelist change had not propagated. None of those require regenerating your API key.
On the self-serve brokers, yes — sessions expire daily and the login is interactive by design. XTS is the exception, as its session is renewed server-side.
Yes, and you choose which one a strategy deploys to. Each needs its own API app, whitelist entry and daily login, so two self-serve brokers means two logins every morning.
No. Neither sends an order to a broker, so neither needs a connection, an IP or any capital.
Start with a free 3-day trial
Build a strategy, backtest it and run it on paper — no broker, no IP and no money needed to try it.

