Management API
The Management API lets a program read and change the same trading settings you change in the CrossTrade web app: global controls and the master kill switch, the news lockout, NinjaTrader connection settings, Account Manager monitors, trade copiers, webhook account groups and Tradovate ATM templates.
Elite
The Management API requires an Elite subscription (active trials included). See Authentication.
How it differs from the trading API
Trading API (/v1/api/...) | Management API (/v1/api/manage/...) | |
|---|---|---|
| Plan | Pro and above | Elite |
| What it does | Places and manages orders, reads accounts and positions | Reads and changes your saved settings |
| Add-on | Most calls need the add-on connected | Reads and most changes work while the add-on is offline |
| Validation | Arguments are passed to the platform | Every request is checked against a strict schema before anything runs |
| Rate limits | Shared trading budget | Its own budgets, which never use up your trading budget |
Base URL
https://app.crosstrade.io/v1/api/manage
Every request is JSON over HTTPS and uses your existing API token:
curl https://app.crosstrade.io/v1/api/manage/controls \
-H "Authorization: Bearer YOUR_TOKEN"
Quick start
- Read the resource:
GET /v1/api/manage/controls. Keep theETagheader if you want to guard against lost updates. - Change only the fields you need:
PATCH /v1/api/manage/controlswith{"closingOnly": true}. - Check the response.
changedtells you whether anything was saved,changedFieldslists what changed, anddeliverytells you when the change takes effect (see Effect timing).
What you can manage
| Area | Endpoints |
|---|---|
| Global controls and kill switch | GET Controls, PATCH Controls, PUT Kill Switch |
| News lockout | GET News Lockout, PATCH News Lockout |
| NinjaTrader connection settings | GET Connection Settings, PATCH Connection Settings |
| Account Manager monitors | Monitors |
| Trade copiers | Copiers |
| Account groups | Account groups |
| Tradovate ATM templates | ATM templates |
| Change history | GET Audit |
The API never returns or changes your profile, billing, API tokens or any other credential.
Capability discovery
GET /v1/api/manage tells a program which areas it can use right now and what your budgets are:
{
"success": true,
"data": {
"version": "2026-10",
"elite": true,
"families": [
{ "id": "account_groups", "enabled": true, "writable": true },
{ "id": "audit", "enabled": true, "writable": false },
{ "id": "controls", "enabled": true, "writable": true },
{ "id": "kill_switch", "enabled": true, "writable": true },
{ "id": "news_lockout", "enabled": true, "writable": true },
{ "id": "nt8_connection_settings", "enabled": true, "writable": true },
{ "id": "nt8_copiers", "enabled": true, "writable": true },
{ "id": "nt8_monitors", "enabled": true, "writable": true },
{ "id": "tradovate_atm_templates", "enabled": true, "writable": true },
{ "id": "tradovate_copiers", "enabled": true, "writable": true },
{ "id": "tradovate_monitors", "enabled": true, "writable": true }
],
"limits": {
"token": { "perMinute": 120, "burst": 30 },
"read": { "perMinute": 60, "burst": 20 },
"write": { "perMinute": 20, "burst": 10 },
"resource": { "perMinute": 6, "burst": 3 },
"kill": { "perMinute": 10, "burst": 5 },
"stop": { "perMinute": 120, "burst": 60 },
"inFlight": { "max": 2 }
}
},
"meta": { "requestId": "req_9f2c1a0b7d3e4f51" }
}
enabled: falsemeans that area is temporarily off (503 family_unavailable).writable: falsemeans it can be read but not changed right now. The change history (audit) is always read-only.limitslists your budgets. See Rate limits.- The call costs one read and has no ETag.
Learn more
- Authentication
- Conventions: response format, PATCH rules, ETags
- Rate limits
- Errors
- Effect timing