Authentication
The Trade API authenticates a person with a password (the
trader login). Your back-office integration should instead
authenticate a machine with a client_credentials key, so no human
password lives in your servers.
1. Mint a client secret
Signed in as the account that will own the integration (typically your admin/dealer account), generate a secret:
curl --request POST \
--url https://api.onlytradeplatform.com/api/v1/accounts/me/client-secret \
--header "Authorization: Bearer $ADMIN_TOKEN"
The response returns a client_id and a client_secret. The secret is shown
once — store it securely, it is not retrievable again. The client_id looks
like <account_id>_<random>; it is not the bare account ID. Generating a new
secret replaces the old one for new logins (sessions already open stay open).
Revoke it any time:
curl --request DELETE \
--url https://api.onlytradeplatform.com/api/v1/accounts/me/client-secret \
--header "Authorization: Bearer $ADMIN_TOKEN"
2. Exchange it for an access token
Use the client_credentials grant with HTTP Basic auth (client_id:client_secret):
curl --request POST \
--url "https://api.onlytradeplatform.com/auth/v1/oauth2/token?grant_type=client_credentials" \
--header "Authorization: Basic $(printf 'YOUR_CLIENT_ID:YOUR_CLIENT_SECRET' | base64)"
The response is the standard login envelope:
{
"data": {
"account_id": 26100001,
"access_token": "…",
"refresh_token": "…",
"session_id": "…",
"expires_in": 3600,
"scope": "API_Admin"
}
}
Send access_token as Authorization: Bearer … on every Broker API call. Refresh
with the refresh token flow before it expires.
Scopes
A token from an API key gets an API scope, not the owner's interactive role:
| Key owner | Token scope | Back-office capability |
|---|---|---|
| Admin account | API_Admin | provisioning, all groups, config, reports |
| Trader account | API_Trader | its own account only — see the Trader API |
Password logins (POST /auth/v1/oauth2/login) keep the account's own role
(Admin, Dealer, …).
The client_secret is a bearer credential for your whole book. Never ship it to
a browser or mobile app — call the Broker API only from your backend.