Home › Legal centre › API Credentials and API Key Security Policy
API Credentials and API Key Security Policy
Two kinds of access
- Analytical access (Upstox Analytics Token): read-only. It lets the terminal read prices, option chains and past candles for your screen. It cannot place, change or cancel orders, move money or reach your funds.
- Broker app login (API key and secret): a broker application credential with a daily login. Brokers may allow such credentials to trade; TradeToday Terminal still uses them only to read market data and has no function to place orders. Whether members may use this method is controlled by the administrator and may be disabled; when it is disabled the server refuses it and does not use keys saved earlier.
How we protect credentials
- Encrypted on the server with a key that is not stored in the database; never shown again after saving (only a masked label).
- Never written to logs, URLs, browser storage or page source.
- Used only by our server, only for your account and only to read market data.
- You can delete them at any time in Account; you can also revoke the token or app on your broker's website.
Your responsibilities
Create credentials only on your broker's official website, never share them, revoke them if you suspect misuse, and follow your broker's terms for API use.
Grievance Officer: Amit Kumar Jain, Director, Tradetoday Multitrade Private Limited. Contact: WhatsApp message to +91 93033 05959 (Monday to Friday, 10 AM to 6 PM (IST)). Address: Indore, Madhya Pradesh 452010, India.
All legal documents · Next: Data Retention and Deletion Policy
All legal documents · Next: Data Retention and Deletion Policy