Authentication
Get and renew access tokens. Bots should use an API key (POST /auth/v1/oauth2/token, client_credentials); interactive apps log in with the account password. See the Authentication guide.
Log in with a password
Log in with HTTP Basic auth: `<account_id>:<password>`. Returns `access_token`, `refresh_token` and `session_id`. Pass `remember_me=true` — without it, a session idle for 5 minutes is logged out.
Log out
Logout
Refresh a token
Refresh account's Token
Get a token with an API key
Exchange an API key for tokens (OAuth2 `client_credentials`). Send HTTP Basic auth with `<client_id>:<client_secret>` and the query `grant_type=client_credentials&remember_me=true`. Create the key with `POST /api/v1/accounts/me/client-secret`. The token carries the `API_Trader` scope. Reuse and refresh tokens: each call opens a session, and an account has at most 5.