Trader API — Getting Started
The Trader API lets you trade your own account from code: read prices, place and manage orders, watch positions and P/L in real time, and pull your trade history. It is the same API the OnlyTrade terminal uses, so anything you can do by hand you can automate.
Typical things people build with it:
- Trading bots — a strategy that reads prices and trades on its own.
- Signal copiers — take signals from TradingView, Telegram or another platform and place them as orders.
- Risk tools — close everything at a daily loss limit, trail stops, alert on margin.
Everything here acts on the account your token belongs to. If you run a brokerage or prop firm and want to manage client accounts, use the Broker API instead.
How it fits together
| You need to… | Use |
|---|---|
| Authenticate your bot | an API key → POST /auth/v1/oauth2/token (Authentication) |
| Know what you can trade | GET /api/v1/symbols/me (Instruments & prices) |
| Warm up indicators | GET /api/v1/market/history — OHLC candles |
| Get live prices | the WebSocket — ticks for every symbol (WebSocket) |
| Trade | POST /api/v1/orders/accounts/me (Orders, positions & deals) |
| Know what happened | the WebSocket — order, position, deal and balance events |
| Recover after a restart | GET /api/v1/positions/accounts/me, GET /api/v1/orders/accounts/me |
REST is for actions and snapshots; the WebSocket is for everything live. A bot needs both.
Base URL
OnlyTrade runs one deployment per broker, so your host is your broker's API host. The public reference deployment is:
https://api.onlytradeplatform.com
| Prefix | Purpose |
|---|---|
/auth/v1/oauth2 | tokens: API key exchange, password login, refresh, logout |
/api/v1 | REST, authenticated with Authorization: Bearer <access_token> |
/ws/v1/ | WebSocket: live prices and account events |
Your first calls
1. Get a token. For a quick test, log in with your account ID and password (bots should use an API key):
curl -X POST "https://api.onlytradeplatform.com/auth/v1/oauth2/login" \
-H "Authorization: Basic $(printf '26100003:MyPassword' | base64)"
{
"success": true,
"code": 200,
"data": {
"account_id": 26100003,
"access_token": "3d4d16824096e9c0…",
"refresh_token": "9f2b71c55a30e1d4…",
"session_id": "f6a1c2d3-…",
"expires_in": 3600,
"scope": "Trader"
},
"error": "",
"message": ""
}
2. Read your account.
TOKEN="3d4d16824096e9c0…"
curl https://api.onlytradeplatform.com/api/v1/accounts/me \
-H "Authorization: Bearer $TOKEN"
data.balance, data.equity, data.free_margin and data.leverage are what a
bot usually checks first.
3. Look up a symbol.
curl "https://api.onlytradeplatform.com/api/v1/symbols/me/by_name?symbol=EURUSD" \
-H "Authorization: Bearer $TOKEN"
Note its id, digits, and the lot limits min_value / max_value / step.
From here, follow Open & close a position or go straight to the complete Build a trading bot example.
Response envelope
Every REST response has the same shape:
{ "success": true, "code": 200, "data": {}, "error": "", "message": "" }
success—trueon 2xx. Branch on this (or the HTTP status).data— the payload: an object, an array, a string, ornull. List endpoints return a plain array.error— a short label ("Bad request","Unauthorized", …) on failure.message— the human-readable reason on failure. Log it.
Test on a demo account first
There is no separate sandbox — you test on a demo account, which trades against live prices with virtual money. Ask your broker for one, or open a free trial from their website. See Environments & testing.
Where next
- Authentication — API keys, token refresh, sessions.
- Orders, positions & deals — every field and enum you send and receive.
- Build a trading bot — a complete, runnable Python bot.
- Running a bot in production — reconnects, reconciliation, and the limits that bite.
- API Reference — every endpoint with a live Try It panel.