Skip to main content
Make calls from your backend over HTTPS. Store the token in a secret manager and avoid exposing it in browser JavaScript, distributed applications, URLs, screenshots, or repositories. The master password is used to verify the account and is not persisted by the API. Request it with consent and avoid storing it in your application, logs, or analytics. The investor password does not replace the master password in this process. Record the correlation identifiers needed for support while filtering out Authorization, passwords, and verification bodies. Do not disable TLS certificate checks to resolve connection errors. Ask the provider for permissions, validity, and request limits appropriate to your use. If the service restricts IPs, agree on the backend’s outbound IP. If a token is exposed, request revocation and replacement. Verify accounts again with the new token. Expiration or revocation removes access through that verification binding; it does not remove positions or orders. Complete their follow-up before ending authorization when you need to manage those trades. Broker account groups are internal metadata. The API filters Group, group, and group_name out of JSON responses, including nested objects and lists.