# Working With Exchange and Broker APIs

> How trading APIs let programs get prices, place orders and read positions. Learn REST, WebSocket and FIX, authentication, rate limits and safe API key handling.

Source: https://learn.tradelabsai.com/programming/trading-apis/  
Track: Programming and Data · Level: Intermediate · Updated: 2026-10-03  
Publisher: TradeLabs AI (https://tradelabsai.com). Education, not financial advice.  
Cite as: TradeLabs Learn, "Working With Exchange and Broker APIs", https://learn.tradelabsai.com/programming/trading-apis/

A trading API (application programming interface) is how a program talks to a broker or exchange: asking for prices, sending orders, checking positions and receiving fills. Every trading bot, from a simple script to an institutional execution system, depends on one. Most brokers and crypto exchanges offer APIs today, usually in two flavours: REST for requests and responses, and WebSocket for live streams. Large institutions also use FIX, the industry's long standing messaging standard. Understanding how these work, and their limits, is the foundation of automated trading.

## The three main API types

| Type | How it works | Typical use | Lesson |
|---|---|---|---|
| REST | Send an HTTP request, get a response | Place and cancel orders, account data, historical bars | This lesson |
| WebSocket | A persistent connection that pushes updates | Live prices, order book updates, fill notifications | [WebSocket Market Data Streams](https://learn.tradelabsai.com/programming/websocket-market-data-streams/) |
| FIX | Session based messaging standard | Institutional order routing and execution | [FIX Protocol](https://learn.tradelabsai.com/programming/fix-protocol/) |

## Common API operations

| Operation | Example |
|---|---|
| Get account | Cash, buying power, margin used |
| Get positions | Current holdings and average prices |
| Get quotes and bars | Latest price, historical candles |
| Place order | Symbol, side, quantity, type, price, time in force |
| Cancel or replace order | By order ID |
| Get order status | Open, partially filled, filled, cancelled, rejected |

## A REST order request

Most REST APIs accept orders as JSON. The exact fields differ by broker, but a limit order typically looks like this:

```
POST /v2/orders
{
  "symbol": "AAPL",
  "side": "buy",
  "qty": 10,
  "type": "limit",
  "limit_price": 185.50,
  "time_in_force": "day",
  "client_order_id": "strat1-20261003-0007"
}
```

The client order ID is your own unique label. If the response is lost, you can ask the broker whether an order with that ID exists before resending, which prevents duplicates. See [Alerts, Error Handling and Reconnection](https://learn.tradelabsai.com/algo-trading/error-handling/) and [Time in Force: Day, GTC and GTD Orders](https://learn.tradelabsai.com/orders/time-in-force/).

## Authentication and API keys

APIs use keys, secrets or tokens to identify you. Treat them like passwords:

- **Never put keys in code** that is shared or committed to git. Use environment variables or a secrets manager.
- **Use the least permissions needed:** read only keys for analysis, trading keys without withdrawal rights for bots.
- **Restrict by IP address** where the broker allows it.
- **Rotate keys** periodically and immediately if exposed.
- **Use separate keys** for paper and live accounts.

## Rate limits

Every API limits how many requests you can make, for example a set number per minute. Exceeding the limit returns errors and can lead to temporary blocks. Good practice:

- **Use WebSocket streams** for live prices instead of polling REST repeatedly.
- **Cache data** you need often.
- **Back off** when you receive rate limit errors.

**Example: Polling versus streaming**
A bot checks prices for 50 symbols by calling a REST quote endpoint once per second each, which is 3,000 requests per minute. If the broker allows 200 requests per minute, the bot hits the limit within seconds. Switching to a WebSocket subscription for the same 50 symbols uses one connection and receives updates as they happen, while REST calls are kept for orders and occasional account checks. See [Real-Time, Delayed and Historical Data](https://learn.tradelabsai.com/programming/real-time-data/).

## Paper trading endpoints

Many brokers provide a paper trading environment with the same API as live trading. Develop and test there first; switch to live by changing the base URL and keys. Be aware that paper fills are simulated and are usually more generous than reality. See [Paper Trading](https://learn.tradelabsai.com/start-here/paper-trading/).

## Choosing a broker for API trading

| Factor | Question |
|---|---|
| Asset coverage | Does it offer the markets you want? |
| Documentation | Is it clear, current and complete? |
| Official libraries | Are there maintained Python packages? |
| Market data | Is real time data included or extra? See [Market Data Fees](https://learn.tradelabsai.com/orders/market-data-fees/) |
| Reliability | How does it handle outages and maintenance? |
| Costs | Commissions, spreads and API fees |

See [How to Choose a Broker](https://learn.tradelabsai.com/industry/how-to-choose-a-broker/).

## Frequently asked questions

### What is a trading API?

An interface that lets software request market data, place and manage orders and read account information from a broker or exchange.

### What is the difference between REST and WebSocket APIs?

REST answers individual requests, suited to orders and account queries; WebSocket keeps a connection open and streams live updates such as prices and fills.

### How do I keep API keys safe?

Store them outside your code, limit their permissions, restrict them by IP where possible, use separate paper and live keys and rotate them if exposed.

Next, learn how live data streams work in [WebSocket Market Data Streams](https://learn.tradelabsai.com/programming/websocket-market-data-streams/).

## Continue learning

- Next lesson: [WebSocket Market Data Streams](https://learn.tradelabsai.com/programming/websocket-market-data-streams/)
- Previous lesson: [Backtesting Libraries Compared](https://learn.tradelabsai.com/programming/backtesting-libraries-compared/)
- Related: [Backtesting Libraries Compared](https://learn.tradelabsai.com/programming/backtesting-libraries-compared/): Compare popular Python backtesting tools: vectorbt, Backtrader, backtesting.py, Zipline Reloaded, NautilusTrader and LEAN. Learn their styles, strengths and limits.
- Related: [WebSocket Market Data Streams](https://learn.tradelabsai.com/programming/websocket-market-data-streams/): How WebSocket streams deliver live trades, quotes and order book updates. Learn subscriptions, heartbeats, reconnecting safely and handling gaps in Python.
- Related: [FIX Protocol](https://learn.tradelabsai.com/programming/fix-protocol/): FIX is the standard messaging protocol for institutional trading. Learn how FIX sessions, messages and tags work, a sample order message and when traders use FIX.
- Related: [Building Trading Bots](https://learn.tradelabsai.com/programming/building-trading-bots/): How to build a trading bot that is safe to run: the main components, an event loop, state and position tracking, risk checks, logging and a staged path to live.
- Related: [Alerts, Error Handling and Reconnection](https://learn.tradelabsai.com/algo-trading/error-handling/): Trading systems face rejected orders, disconnects, bad data and partial fills. Learn how to classify errors, retry safely, use idempotent orders and fail closed.
- Related: [Direct Market Access and Sponsored Access](https://learn.tradelabsai.com/orders/direct-market-access/): Direct market access lets traders send orders straight to an exchange's order book through a broker's systems. Learn how DMA works, its benefits, costs and rules.
