> ## Documentation Index
> Fetch the complete documentation index at: https://api-trading-docs.vexprofx.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Bearer tokens, permissions, and credentials used by partners.

Request an integration token and the permissions you need from the provider.
The partner portal has no endpoint for creating or renewing tokens.

```http theme={"theme":{"light":"github-light","dark":"github-dark"}}
Authorization: Bearer YOUR_TOKEN
```

`GET /health/live` is public. The other 12 operations require authentication.
The token does not replace account verification: account queries and trading also
require an active verification for that same token and login.

## Prepare the integration

1. Store the token as a secret in your backend.
2. Send the `Authorization` header with every protected request.
3. Add `Content-Type: application/json` when sending a JSON body.
4. Check the HTTP status and response content.
5. Keep tracking identifiers without logging credentials.

In Swagger, open **Authorize** and enter only the `mt5_...` token, without the
`Bearer` prefix. Do not use Manager credentials or HTTP Basic to call these routes.

## Permissions and validity

Permissions are assigned by method and route. A read-only token cannot submit
opening or closing orders. Token validity and verification validity are independent:
renewing a verification does not renew the token. A new token must verify its accounts.
See [integration permissions](/access-control).

A `401` means the token is missing, invalid, expired, or revoked.
A `403` may indicate a disallowed route, an unverified account, or disabled trading.
A `429` requires reducing request frequency. There is no documented universal rate limit:
ask the provider for the limit assigned to your token.

If your integration is associated with a broker, use the token issued for that broker.
Partner route parameters do not select an MT5 connection.
