> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trdrs.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a Connect link

> Creates a Connect link for one of your traders, so they can connect an account, or open your white-label paper, in hosted Connect on your website without signing in to trdrs. Name the trader by your own id for them: the first link for an id makes them one of your traders at trdrs, every later link reaches the same trader, and the accounts they connect are theirs, apart from any trdrs account and from every other app's traders. The response's `link` carries its `token`, which you hand to your page, and its `id`, which you keep to read how it ended. The token opens hosted Connect on that one website until `expiresAt`, and once open, Connect stays usable for up to 30 minutes. The same `Idempotency-Key` and body answer the same link until it is opened, so send a new key for each new link. Your API key stays on your server. It takes your app's API key, sent from your server: a request that also carries a cookie or a browser's `Origin` is refused. Preview: served on the sandbox, where it is free.



## OpenAPI

````yaml /api/openapi.json post /api/connect/links
openapi: 3.1.0
info:
  title: trdrs Engine API
  version: 1.1.0
  description: >-
    ## API Reference


    Every route the trdrs engine serves, with what to send and what comes back.
    It covers market

    data and news, trading and account state for a trader's own software, the
    Connect API a Connect

    app's backend calls and the Connect dashboard's routes, Connect
    pre-registration, the statements

    that carry a Connect account between environments, the venue routes a prop
    firm or brokerage runs its

    accounts through, and a trader's own challenges.


    Start with the Quickstart for your first call. The API standards hold the
    rules every route

    shares: keys, errors, rate limits, idempotency, paging and streaming.
servers:
  - url: https://app.trdrs.co
    description: Production
  - url: /
    description: This engine
security: []
tags:
  - name: Venue platform preview
    description: >-
      Run your venue: its providers, instruments, conditions, groups, routes,
      stages, venue rules, keys, accounts, usage, balance receipts and webhooks.
      These routes are in preview. They are served on the sandbox to every
      venue, and production access is arranged when a venue qualifies. Every
      route here under `/api/venues/` takes a Venue key. The back office reaches
      the same routes under `/api/back-office/` with a verified owner’s session,
      because the Venue key stays on your server, and both run the same checks.
      The team’s routes under `/api/organizations` serve the back office and the
      Connect dashboard alike, since one organization can run venues and Connect
      apps with one team. Changes to these routes are additive only from here
      on.
  - name: Market data
    description: >-
      Search and look up symbols, read price history and quotes, check the
      server clock, and stream live bars. Crypto prices come from each
      provider’s public feed. Futures prices are licensed to each user and
      stream only from that trader’s own futures source: a login on their
      venue’s production Rithmic system, under their own market data
      subscription. A Rithmic Test login carries no market data. Without a
      source, a futures request answers 503 `feed_requires_connection` and the
      symbol search lists no futures.
  - name: News
    description: >-
      Market news and the economic calendar, from licensed and open sources,
      tagged with futures roots as they arrive. The content is the same for
      everyone, and these routes admit the same callers as market data: a
      licensed origin, a session or a Trading API key. Page headlines by publish
      time, filter them by instrument root, and stream them live over
      server-sent events. Thumbnails come through the image route.
  - name: Trading
    description: >-
      Place, change and cancel orders, set a position’s exits, and close or
      flatten positions. Every call that places an order takes a `clientOrderId`
      as its idempotency key.
  - name: Account
    description: >-
      Read an account a trader can trade: its balance, positions, working
      orders, fills, profit and loss history, and the live account stream. You
      don’t create accounts here. A trader connects their own account at a
      provider, or opens their own Demo on the paper book, in the trdrs app. A
      venue issues accounts on the paper book with Issue an account into a
      group, and a venue pre-registers accounts at a provider through Connect
      with Pre-register a trader’s account.
  - name: Connect
    description: >-
      Connect is the account picker a trader opens: in the trdrs app, where it
      lists the built-in providers and every listed venue, and in hosted Connect
      on a Connect app’s website, where it lists the tiles the app chose. The
      pre-registration routes let a venue fill Connect in the trdrs app ahead of
      time, for a trader who signs in to trdrs. You tell trdrs that a trader has
      an account at a built-in provider: their sign-in email, and optionally the
      account number and login name. When that trader signs in, Connect shows
      the account ready to link, and they sign in to the provider themselves,
      once. The trader types their own password, and access starts when their
      own login succeeds. You can list who you pre-registered and who has
      linked, and cancel a pre-registration that hasn’t been used. A
      pre-registration expires after 30 days, and sending it again refreshes it.
      These routes take the pre-registration key. The whole flow is in the
      **[Quick Start](/docs/guides/quick-start)**.
  - name: Connect apps preview
    description: >-
      Run a Connect app: your own trading interface, whose traders connect their
      accounts in hosted Connect on your website and trade them on your screens.
      The Connect API is what your backend calls with your app’s API key: Create
      a Connect link, read and close it, and the account, market and trading
      routes with your trader named in `x-trdrs-trader`. Hosted Connect calls
      its own routes with the frame session a Connect link opens. The Connect
      dashboard calls the rest with your Connect sign-in session: your apps,
      each app’s name and logo, API keys, websites, tiles, white-label paper and
      Demos, traders and active traders, invoices, conformance runs and its
      Connect pass. These routes are in preview, served on the sandbox, where
      they are free. Once production opens to Connect apps, it serves the route
      that records an app’s Connect pass, which opens the app’s production.
  - name: Connect accounts
    description: >-
      A Connect client's team signs in to the Connect dashboard with a Connect
      account of its own, never a trader's, and one login reaches both
      environments. Production answers a short statement for the signed-in
      account, naming its verified email and the Connect apps it owns, and
      sandbox exchanges it for a sandbox session and the counterpart app of
      each: the sandbox app that stands for the production one. The environments
      share no credential: production signs the statement with its own key, and
      sandbox checks it with production's public key alone. These routes take
      the Connect dashboard's own session, from the dashboard's origin; a
      trader's session and every key are refused, and a Connect account's
      session reaches no trading, account, market or AI route.
  - name: Challenges
    description: >-
      These routes list evaluation programs and a trader’s own enrollments.
      **Preview: the one group in this reference outside the additive-only
      guarantee.** Their shapes will change when challenges are rebuilt; see
      Stability. **They take a signed-in session, not a key**, and are served
      only where the engine runs with `CHALLENGES_ENABLED`. Without it, the
      routes don’t exist and every one answers `404`. The administration half
      isn’t documented here, because it is trdrs’s own tooling, not part of the
      API.
paths:
  /api/connect/links:
    post:
      tags:
        - Connect apps preview
      summary: Create a Connect link
      description: >-
        Creates a Connect link for one of your traders, so they can connect an
        account, or open your white-label paper, in hosted Connect on your
        website without signing in to trdrs. Name the trader by your own id for
        them: the first link for an id makes them one of your traders at trdrs,
        every later link reaches the same trader, and the accounts they connect
        are theirs, apart from any trdrs account and from every other app's
        traders. The response's `link` carries its `token`, which you hand to
        your page, and its `id`, which you keep to read how it ended. The token
        opens hosted Connect on that one website until `expiresAt`, and once
        open, Connect stays usable for up to 30 minutes. The same
        `Idempotency-Key` and body answer the same link until it is opened, so
        send a new key for each new link. Your API key stays on your server. It
        takes your app's API key, sent from your server: a request that also
        carries a cookie or a browser's `Origin` is refused. Preview: served on
        the sandbox, where it is free.
      parameters:
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            minLength: 1
            maxLength: 128
          description: >-
            A key you choose, 1 to 128 characters, that identifies this write.
            Send the same key when you retry it, so the write is never applied
            twice.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConnectLinkCreateRequest'
      responses:
        '201':
          description: >-
            Success. The response is sent with `Cache-Control: no-store`, so
            don't cache it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectLinkIssuedResponse'
        '400':
          description: >-
            `invalid_request`: a field is missing or unknown, `origin` isn't an
            exact origin, `trader` breaks its pattern, or `expiresInSeconds` is
            outside 60 to 600. `idempotency_key_required`: the `Idempotency-Key`
            header is missing. `credential_not_allowed`: the request carried a
            cookie or a browser's `Origin` beside your API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: >-
            `api_key_required`: the request carried no API key. `invalid_key`:
            the key is malformed, revoked or expired, belongs to the other
            environment, or its creator is no longer an owner of your app.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: >-
            `website_not_approved`: `origin` isn't one of your app's approved
            websites.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: >-
            `not_found`: the `Idempotency-Key` names a link that has already
            been opened.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '409':
          description: >-
            `idempotency_conflict`: the `Idempotency-Key` already created a link
            with a different body.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '413':
          description: The body is larger than this route accepts.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '415':
          description: 'Send the body as JSON, with `Content-Type: application/json`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: >-
            trdrs can't complete the request right now, because a part of the
            venue platform or its credential store is unavailable. Don't assume
            a write happened: retry it with the same `Idempotency-Key`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - connectApiKey: []
      servers:
        - url: https://sandbox.trdrs.co
          description: Sandbox only
      x-codeSamples:
        - lang: javascript
          label: TypeScript
          source: >-
            const res = await
            fetch('https://sandbox.trdrs.co/api/connect/links', {
              method: 'POST',
              headers: {
                'content-type': 'application/json',
                Authorization: `Bearer ${process.env.TRDRS_API_KEY}`,
                "Idempotency-Key": "example-request-1",
              },
              body: JSON.stringify({
                "origin": "https://app.example.com",
                "trader": "trader-8841",
                "expiresInSeconds": 300
              }),
            })

            const data = await res.json()
        - lang: shell
          label: cURL
          source: |-
            curl -X POST 'https://sandbox.trdrs.co/api/connect/links' \
              -H "Authorization: Bearer $TRDRS_API_KEY" \
              -H 'Idempotency-Key: example-request-1' \
              -H 'content-type: application/json' \
              -d '{"origin":"https://app.example.com","trader":"trader-8841","expiresInSeconds":300}'
components:
  schemas:
    ConnectLinkCreateRequest:
      type: object
      additionalProperties: false
      required:
        - origin
        - trader
        - expiresInSeconds
      properties:
        origin:
          type: string
          description: >-
            The website of the page that opens hosted Connect, exactly as you
            added it.
        trader:
          type: string
          pattern: ^[A-Za-z0-9][A-Za-z0-9._:-]{0,127}$
          description: >-
            Your own id for the trader, the same every time they connect:
            letters, digits, dot, underscore, colon and hyphen, up to 128
            characters, starting with a letter or a digit. Never an email or
            another personal detail.
        expiresInSeconds:
          type: integer
          minimum: 60
          maximum: 600
          description: How long the token can open hosted Connect, from 60 to 600 seconds.
      example:
        origin: https://app.example.com
        trader: trader-8841
        expiresInSeconds: 300
    ConnectLinkIssuedResponse:
      type: object
      additionalProperties: false
      properties:
        link:
          type: object
          additionalProperties: false
          properties:
            id:
              type: string
              format: uuid
            token:
              type: string
              description: >-
                The Connect link's token, `trdrs_cl_sandbox_…` or
                `trdrs_cl_production_…`. Your page opens hosted Connect with it.
            expiresAt:
              type: string
              format: date-time
            origin:
              type: string
            environment:
              type: string
              enum:
                - sandbox
                - production
          required:
            - id
            - token
            - expiresAt
            - origin
            - environment
      required:
        - link
      example:
        link:
          id: 00000000-0000-0000-0000-000000000001
          token: trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
          expiresAt: '2026-09-14T12:00:00.000Z'
          origin: https://app.example.com
          environment: sandbox
    ErrorResponse:
      type: object
      description: >-
        The body of every error response. It always carries `error`, an English
        sentence you can show. A refused trading request also carries `code`,
        one of the refusal codes, and `params`, the details of that refusal.
        Translate by `code` and `params`, and show a generic message for a code
        you don't recognize. Other errors may carry a `code` of their own.
      properties:
        error:
          type: string
          description: What went wrong, as an English sentence.
        code:
          type: string
          description: >-
            A stable machine code. On a refused trading request, it is one of
            the refusal codes.
        params:
          type: object
          description: >-
            The details of the refusal named by `code`, on a refused trading
            request.
      required:
        - error
      example:
        error: invalid_instrument
  securitySchemes:
    connectApiKey:
      type: http
      scheme: bearer
      description: >-
        A Connect app's API key (`trdrs_ck_sandbox_…` or
        `trdrs_ck_production_…`), in preview. It belongs to one app in one
        environment, has a name and an expiry, and carries the whole Connect
        API. An owner of the app creates it in the Connect dashboard. It
        creates, reads and closes the app's Connect links under
        `/api/connect/links`, and on the account, market and trading routes it
        reads the app's own traders' accounts and market data and routes their
        orders, each request naming its trader in `x-trdrs-trader`. It stops
        working when it is revoked or expires, or when the owner who created it
        stops being an owner. Keep it on your server.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.