Skip to main content

Authentication

The Trade API authenticates a person with a password (the trader login). Your back-office integration should instead authenticate a machine with a client_credentials key, so no human password lives in your servers.

1. Mint a client secret​

Signed in as the account that will own the integration (typically your admin/dealer account), generate a secret:

curl --request POST \
--url https://api.onlytradeplatform.com/api/v1/accounts/me/client-secret \
--header "Authorization: Bearer $ADMIN_TOKEN"

The response returns a client_id and a client_secret. The secret is shown once — store it securely, it is not retrievable again. The client_id looks like <account_id>_<random>; it is not the bare account ID. Generating a new secret replaces the old one for new logins (sessions already open stay open).

Revoke it any time:

curl --request DELETE \
--url https://api.onlytradeplatform.com/api/v1/accounts/me/client-secret \
--header "Authorization: Bearer $ADMIN_TOKEN"

2. Exchange it for an access token​

Use the client_credentials grant with HTTP Basic auth (client_id:client_secret):

curl --request POST \
--url "https://api.onlytradeplatform.com/auth/v1/oauth2/token?grant_type=client_credentials" \
--header "Authorization: Basic $(printf 'YOUR_CLIENT_ID:YOUR_CLIENT_SECRET' | base64)"

The response is the standard login envelope:

{
"data": {
"account_id": 26100001,
"access_token": "…",
"refresh_token": "…",
"session_id": "…",
"expires_in": 3600,
"scope": "API_Admin"
}
}

Send access_token as Authorization: Bearer … on every Broker API call. Refresh with the refresh token flow before it expires.

Scopes​

A token from an API key gets an API scope, not the owner's interactive role:

Key ownerToken scopeBack-office capability
Admin accountAPI_Adminprovisioning, all groups, config, reports
Trader accountAPI_Traderits own account only — see the Trader API

Password logins (POST /auth/v1/oauth2/login) keep the account's own role (Admin, Dealer, …).

Keep keys server-side

The client_secret is a bearer credential for your whole book. Never ship it to a browser or mobile app — call the Broker API only from your backend.