Skip to main content

Authentication

The Management API uses the same API token as the trading API and your webhooks. You find it in the web app under My Account.

Sending the token​

Send it in the Authorization header, with exactly one space after Bearer:

Authorization: Bearer YOUR_TOKEN

The Management API accepts the token only in the Authorization header. The x-auth header, query-string tokens and cookies are not accepted here.

If you regenerate your token in the web app, the old token stops working here right away.

Who can use it​

The Management API is available on Elite plans, including an active Elite trial. Every request checks your plan, so a downgrade or an expired trial takes effect within about 30 seconds.

Authentication errors​

StatuserrorMeaning
401unauthorizedThe token is missing, malformed, revoked, or belongs to a disabled account
403elite_requiredYour plan does not include the Management API
403not_availableThe Management API is not open for your account yet
{
"success": false,
"error": "elite_required",
"detail": "The Management API requires an Elite subscription.",
"meta": { "requestId": "req_9f2c1a0b7d3e4f51" }
}

Keep your token safe​

Your API token can place trades through webhooks and, on Elite, change your risk settings through this API. Treat it like a password. If you think it leaked, regenerate it in My Account, then update your webhooks and scripts.

Every change made through the Management API is recorded and visible to you in GET Audit.