TypeScript
// Runs in the browser with no credential. A request that carries a key is refused.
const res = await fetch('https://app.trdrs.co/api/connect-link/mount', {
method: 'POST',
headers: {
'content-type': 'application/json',
},
credentials: 'omit',
body: JSON.stringify({
"token": "trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
}),
})
const data = await res.json()curl -X POST 'https://app.trdrs.co/api/connect-link/mount' \
-H 'content-type: application/json' \
-d '{"token":"trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"}'import requests
url = "https://app.trdrs.co/api/connect-link/mount"
payload = { "token": "trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.trdrs.co/api/connect-link/mount",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'token' => 'trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.trdrs.co/api/connect-link/mount"
payload := strings.NewReader("{\n \"token\": \"trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.trdrs.co/api/connect-link/mount")
.header("Content-Type", "application/json")
.body("{\n \"token\": \"trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.trdrs.co/api/connect-link/mount")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"token\": \"trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"\n}"
response = http.request(request)
puts response.read_body{
"session": {
"id": "00000000-0000-0000-0000-000000000001",
"origin": "https://app.example.com",
"environment": "sandbox",
"expiresAt": "2026-09-14T12:00:00.000Z"
},
"frame": {
"token": "trdrs_cf_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
"expiresAt": "2026-09-14T12:00:00.000Z"
}
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}Hosted Connect's own routes
Mount a Connect link token
Exchanges a Connect link’s short-lived token, which your backend received when it created the link, for the link’s session and the frame session of its trader. Hosted Connect calls it when it opens on your page and keeps the frame session in memory. A retry returns the same frame session while it is live. A request that carries a cookie or a bearer credential is refused, so the mount never borrows authority it wasn’t given. Preview: served on the sandbox, where it is free.
POST
/
api
/
connect-link
/
mount
TypeScript
// Runs in the browser with no credential. A request that carries a key is refused.
const res = await fetch('https://app.trdrs.co/api/connect-link/mount', {
method: 'POST',
headers: {
'content-type': 'application/json',
},
credentials: 'omit',
body: JSON.stringify({
"token": "trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
}),
})
const data = await res.json()curl -X POST 'https://app.trdrs.co/api/connect-link/mount' \
-H 'content-type: application/json' \
-d '{"token":"trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"}'import requests
url = "https://app.trdrs.co/api/connect-link/mount"
payload = { "token": "trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.trdrs.co/api/connect-link/mount",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'token' => 'trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.trdrs.co/api/connect-link/mount"
payload := strings.NewReader("{\n \"token\": \"trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.trdrs.co/api/connect-link/mount")
.header("Content-Type", "application/json")
.body("{\n \"token\": \"trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.trdrs.co/api/connect-link/mount")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"token\": \"trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"\n}"
response = http.request(request)
puts response.read_body{
"session": {
"id": "00000000-0000-0000-0000-000000000001",
"origin": "https://app.example.com",
"environment": "sandbox",
"expiresAt": "2026-09-14T12:00:00.000Z"
},
"frame": {
"token": "trdrs_cf_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
"expiresAt": "2026-09-14T12:00:00.000Z"
}
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}Body
application/json
The Connect link's token, from creating its session.
Response
Success. The response is sent with Cache-Control: no-store, so don't cache it.
The response is of type object.