> ## Documentation Index
> Fetch the complete documentation index at: https://api-trading-docs.vexprofx.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Protect your integration

> Handle credentials and customer data when consuming the partner API.

Make calls from your backend over HTTPS. Store the token in a secret manager and
avoid exposing it in browser JavaScript, distributed applications, URLs, screenshots,
or repositories.

The master password is used to verify the account and is not persisted by the API.
Request it with consent and avoid storing it in your application, logs, or analytics.
The investor password does not replace the master password in this process.

Record the correlation identifiers needed for support while filtering out
`Authorization`, passwords, and verification bodies. Do not disable TLS certificate
checks to resolve connection errors.

Ask the provider for permissions, validity, and request limits appropriate to your use.
If the service restricts IPs, agree on the backend's outbound IP. If a token is exposed,
request revocation and replacement. Verify accounts again with the new token.

Expiration or revocation removes access through that verification binding;
it does not remove positions or orders. [Complete their follow-up](/trading/results)
before ending authorization when you need to manage those trades.

Broker account groups are internal metadata. The API filters `Group`, `group`, and
`group_name` out of JSON responses, including nested objects and lists.
