Working With Exchange and Broker APIs
How trading APIs let programs get prices, place orders and read positions. Learn REST, WebSocket and FIX, authentication, rate limits and safe API key handling.
A trading API (application programming interface) is how a program talks to a broker or exchange: asking for prices, sending orders, checking positions and receiving fills. Every trading bot, from a simple script to an institutional execution system, depends on one. Most brokers and crypto exchanges offer APIs today, usually in two flavours: REST for requests and responses, and WebSocket for live streams. Large institutions also use FIX, the industry's long standing messaging standard. Understanding how these work, and their limits, is the foundation of automated trading.
The three main API types#
| Type | How it works | Typical use | Lesson |
|---|---|---|---|
| REST | Send an HTTP request, get a response | Place and cancel orders, account data, historical bars | This lesson |
| WebSocket | A persistent connection that pushes updates | Live prices, order book updates, fill notifications | WebSocket Market Data Streams |
| FIX | Session based messaging standard | Institutional order routing and execution | FIX Protocol |
Common API operations#
| Operation | Example |
|---|---|
| Get account | Cash, buying power, margin used |
| Get positions | Current holdings and average prices |
| Get quotes and bars | Latest price, historical candles |
| Place order | Symbol, side, quantity, type, price, time in force |
| Cancel or replace order | By order ID |
| Get order status | Open, partially filled, filled, cancelled, rejected |
A REST order request#
Most REST APIs accept orders as JSON. The exact fields differ by broker, but a limit order typically looks like this:
POST /v2/orders
{
"symbol": "AAPL",
"side": "buy",
"qty": 10,
"type": "limit",
"limit_price": 185.50,
"time_in_force": "day",
"client_order_id": "strat1-20261003-0007"
}
The client order ID is your own unique label. If the response is lost, you can ask the broker whether an order with that ID exists before resending, which prevents duplicates. See Alerts, Error Handling and Reconnection and Time in Force: Day, GTC and GTD Orders.
Authentication and API keys#
APIs use keys, secrets or tokens to identify you. Treat them like passwords:
- Never put keys in code that is shared or committed to git. Use environment variables or a secrets manager.
- Use the least permissions needed: read only keys for analysis, trading keys without withdrawal rights for bots.
- Restrict by IP address where the broker allows it.
- Rotate keys periodically and immediately if exposed.
- Use separate keys for paper and live accounts.
Rate limits#
Every API limits how many requests you can make, for example a set number per minute. Exceeding the limit returns errors and can lead to temporary blocks. Good practice:
- Use WebSocket streams for live prices instead of polling REST repeatedly.
- Cache data you need often.
- Back off when you receive rate limit errors.
Paper trading endpoints#
Many brokers provide a paper trading environment with the same API as live trading. Develop and test there first; switch to live by changing the base URL and keys. Be aware that paper fills are simulated and are usually more generous than reality. See Paper Trading.
Choosing a broker for API trading#
| Factor | Question |
|---|---|
| Asset coverage | Does it offer the markets you want? |
| Documentation | Is it clear, current and complete? |
| Official libraries | Are there maintained Python packages? |
| Market data | Is real time data included or extra? See Market Data Fees |
| Reliability | How does it handle outages and maintenance? |
| Costs | Commissions, spreads and API fees |
Frequently asked questions#
What is a trading API?#
An interface that lets software request market data, place and manage orders and read account information from a broker or exchange.
What is the difference between REST and WebSocket APIs?#
REST answers individual requests, suited to orders and account queries; WebSocket keeps a connection open and streams live updates such as prices and fills.
How do I keep API keys safe?#
Store them outside your code, limit their permissions, restrict them by IP where possible, use separate paper and live keys and rotate them if exposed.
Next, learn how live data streams work in WebSocket Market Data Streams.
3 quick questions on this lesson. Get them all right to finish it.
Turn on JavaScript to take the quiz.
Mentioned in
- Python for TradingProgramming and Data
- Backtesting Libraries ComparedProgramming and Data
- Algorithmic Trading ExplainedAlgorithmic Trading
- Automated vs Semi-Automated TradingAlgorithmic Trading
- How to Choose a BrokerThe Trading Industry