GET /health/live is public. The other 12 operations require authentication.
The token does not replace account verification: account queries and trading also
require an active verification for that same token and login.
Prepare the integration
- Store the token as a secret in your backend.
- Send the
Authorizationheader with every protected request. - Add
Content-Type: application/jsonwhen sending a JSON body. - Check the HTTP status and response content.
- Keep tracking identifiers without logging credentials.
mt5_... token, without the
Bearer prefix. Do not use Manager credentials or HTTP Basic to call these routes.
Permissions and validity
Permissions are assigned by method and route. A read-only token cannot submit opening or closing orders. Token validity and verification validity are independent: renewing a verification does not renew the token. A new token must verify its accounts. See integration permissions. A401 means the token is missing, invalid, expired, or revoked.
A 403 may indicate a disallowed route, an unverified account, or disabled trading.
A 429 requires reducing request frequency. There is no documented universal rate limit:
ask the provider for the limit assigned to your token.
If your integration is associated with a broker, use the token issued for that broker.
Partner route parameters do not select an MT5 connection.