TradeLabs AILearn

Working With Exchange and Broker APIs

How trading APIs let programs get prices, place orders and read positions. Learn REST, WebSocket and FIX, authentication, rate limits and safe API key handling.

Intermediate3 min readUpdated 3 Oct 2026
Markdown
Lesson 5 of 27

A trading API (application programming interface) is how a program talks to a broker or exchange: asking for prices, sending orders, checking positions and receiving fills. Every trading bot, from a simple script to an institutional execution system, depends on one. Most brokers and crypto exchanges offer APIs today, usually in two flavours: REST for requests and responses, and WebSocket for live streams. Large institutions also use FIX, the industry's long standing messaging standard. Understanding how these work, and their limits, is the foundation of automated trading.

The three main API types#

TypeHow it worksTypical useLesson
RESTSend an HTTP request, get a responsePlace and cancel orders, account data, historical barsThis lesson
WebSocketA persistent connection that pushes updatesLive prices, order book updates, fill notificationsWebSocket Market Data Streams
FIXSession based messaging standardInstitutional order routing and executionFIX Protocol

Common API operations#

OperationExample
Get accountCash, buying power, margin used
Get positionsCurrent holdings and average prices
Get quotes and barsLatest price, historical candles
Place orderSymbol, side, quantity, type, price, time in force
Cancel or replace orderBy order ID
Get order statusOpen, partially filled, filled, cancelled, rejected

A REST order request#

Most REST APIs accept orders as JSON. The exact fields differ by broker, but a limit order typically looks like this:

POST /v2/orders
{
  "symbol": "AAPL",
  "side": "buy",
  "qty": 10,
  "type": "limit",
  "limit_price": 185.50,
  "time_in_force": "day",
  "client_order_id": "strat1-20261003-0007"
}

The client order ID is your own unique label. If the response is lost, you can ask the broker whether an order with that ID exists before resending, which prevents duplicates. See Alerts, Error Handling and Reconnection and Time in Force: Day, GTC and GTD Orders.

Authentication and API keys#

APIs use keys, secrets or tokens to identify you. Treat them like passwords:

  • Never put keys in code that is shared or committed to git. Use environment variables or a secrets manager.
  • Use the least permissions needed: read only keys for analysis, trading keys without withdrawal rights for bots.
  • Restrict by IP address where the broker allows it.
  • Rotate keys periodically and immediately if exposed.
  • Use separate keys for paper and live accounts.

Rate limits#

Every API limits how many requests you can make, for example a set number per minute. Exceeding the limit returns errors and can lead to temporary blocks. Good practice:

  • Use WebSocket streams for live prices instead of polling REST repeatedly.
  • Cache data you need often.
  • Back off when you receive rate limit errors.

Paper trading endpoints#

Many brokers provide a paper trading environment with the same API as live trading. Develop and test there first; switch to live by changing the base URL and keys. Be aware that paper fills are simulated and are usually more generous than reality. See Paper Trading.

Choosing a broker for API trading#

FactorQuestion
Asset coverageDoes it offer the markets you want?
DocumentationIs it clear, current and complete?
Official librariesAre there maintained Python packages?
Market dataIs real time data included or extra? See Market Data Fees
ReliabilityHow does it handle outages and maintenance?
CostsCommissions, spreads and API fees

See How to Choose a Broker.

Frequently asked questions#

What is a trading API?#

An interface that lets software request market data, place and manage orders and read account information from a broker or exchange.

What is the difference between REST and WebSocket APIs?#

REST answers individual requests, suited to orders and account queries; WebSocket keeps a connection open and streams live updates such as prices and fills.

How do I keep API keys safe?#

Store them outside your code, limit their permissions, restrict them by IP where possible, use separate paper and live keys and rotate them if exposed.

Next, learn how live data streams work in WebSocket Market Data Streams.

Check your understanding

3 quick questions on this lesson. Get them all right to finish it.

Turn on JavaScript to take the quiz.

Finished this lesson?Sign in to save your progress across devices.
Next lessonWebSocket Market Data StreamsHow WebSocket streams deliver live trades, quotes and order book updates. Learn subscriptions, heartbeats, reconnecting safely and handling gaps in Python.

Mentioned in