> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trdrs.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Issue an account into a group

> Private preview, disabled unless VENUE_CONFIGURATION_ENABLED is enabled and the vault is configured. This branch has not enabled these routes in the public sandbox. Existing trdrs_sk partner/tenant keys do not authorize these routes. Requires the named venue-key scope and current owner membership. account:issue. Runs the same operation the legacy Partner API route runs, and refuses the same things; this is the venue door onto it, not a second implementation. The venue must have adopted a firm (else `no_firm`, 404) and the group must have a route (else `group_has_no_route`, 409): an account that could never open a position is refused before anything is issued. An unknown trader email is `no_user_with_that_email` (404). The firm's referenceId makes the create idempotent; a retry with the same referenceId returns the same account with `created: false`.



## OpenAPI

````yaml /partner-platform/openapi.json post /api/partner/venues/{venueId}/accounts
openapi: 3.1.0
info:
  title: trdrs Engine API
  version: 1.1.0
  description: >-
    ## API Reference


    This is the served OpenAPI contract for the trdrs engine: market data,
    trading and account

    routes for your firm's traders, trdrs Connect account-registration handoff,
    and preview

    challenge routes.


    See Quick Start for the first integration path: key setup, market config,
    chart data, Connect

    account registrations, idempotency, stream reconnects, and conformance.


    See Overview and API Standards for the cross-cutting contract rules.
servers:
  - url: https://app.trdrs.co
    description: Production
  - url: /
    description: This engine
security: []
tags:
  - name: Venue platform preview
    description: >-
      Disabled private-preview venue configuration APIs.
      VENUE_CONFIGURATION_ENABLED and a vault are required. Every route
      documented here under /api/partner/ is also served under /api/operator/ to
      a verified owner session, by the same router with a different credential:
      a browser must never hold a venue key, so an operator console reaches the
      identical checks that way rather than through a second copy of this
      surface. Not part of the stable public contract until qualification and
      release; existing partner APIs remain unchanged.
  - name: Market data
    description: >-
      Symbol search and resolution, OHLCV history, quote snapshots, the server
      clock, and the live bar stream. Crypto rides each venue’s public feed;
      futures stream from the caller’s own connected Rithmic account. With none
      connected, futures requests answer 503 `feed_requires_connection`.
  - name: News
    description: >-
      Aggregated market news and the economic calendar, from licensed/open
      sources, keyword-tagged with futures roots at ingest. Platform-wide
      content (nothing per-user), admitted exactly like Market data: a licensed
      origin, a session, or a firm API key. Headlines page by published time,
      scope by instrument root, and stream live over SSE; thumbnails serve
      through the image proxy.
  - name: Trading
    description: >-
      The money surface: entries, exits, replaces, cancels, and position/account
      flattening. Every order-placing call uses `clientOrderId` as its
      idempotency key.
  - name: Account
    description: >-
      Reading a connected account. You do not create trading accounts here: a
      trader connects their own broker account (or creates a free demo account)
      in the app, and firms create evaluation accounts through the Partner API
      (Firm accounts → Create evaluation accounts) or register venue accounts
      through Connect (Create an account registration). Account state and the
      durable ledgers: balances, positions, working orders, fills, P&L history,
      and the live account stream.
  - name: Connect
    description: >-
      Connect is the account picker a trader opens, in our app or embedded on a
      partner’s site: the brokers we run, plus every listed venue. These three
      routes are how a firm PRE-FILLS it. You tell us a trader has an account at
      a broker we support (their sign-in email, and optionally the account
      number and login name); when that trader signs in, Connect shows the
      account ready to link and they type only their own password. Nothing here
      sends a password or grants access before the trader’s own login succeeds.
      You can list who you pre-registered and who has linked, and cancel a
      pre-registration that has not been used. Pre-registrations expire after 30
      days; repeating one refreshes it. These routes take the Partner API key
      today and are Connect’s own; they are not part of the legacy
      firm-operations surface. The end-to-end flow is **[Quick
      Start](/docs/guides/quick-start)**.
  - name: Firm accounts (legacy)
    description: >-
      Legacy. Every route in this group has a venue twin under
      `/api/partner/venues/{venueId}/accounts…`, reached with a venue key and a
      named scope, and new integrations use those; this group stays for firms
      that predate venues, and the same operation runs behind both doors.
      Evaluation accounts your firm issues on the trdrs venue, through your
      partner key — the other half of account setup. Connect registrations hand
      off accounts that exist on your venue; these routes create and manage
      accounts on ours: the trader trades them on trdrs, and your firm owns the
      lifecycle. Every route is scoped to accounts your firm created through
      this API — an account the same trader opened themselves is invisible and
      untouchable here, by construction. Creation is batched with per-item
      results, and every write carries your own `referenceId`, so a crashed
      pipeline retries safely. Served when the deployment runs the prop engine;
      without it, every route in this group answers `404`.
  - name: Billing
    description: >-
      Legacy, per firm. What your firm is billed for in a month, computed from
      the execution ledger, and the accounts behind the number. The venue
      platform will carry per-venue usage; until it does these two routes answer
      the Partner API key.
  - name: Webhooks
    description: >-
      Being replaced by the venue API: venue-scoped events are not built yet, so
      this is the one job a venue-only backend still needs a Partner key for;
      nothing here is removed until they are. The outbound event bus: register
      an https endpoint and the platform pushes events to it instead of your
      back office polling us. Every delivery is signed (`trdrs-signature:
      t=<unix>,v1=<hmac-sha256>` over `${t}.${rawBody}`) so you can prove it
      came from us and is fresh, and every delivery is durable — a failed
      attempt is retried with backoff for about nine hours and the whole log is
      readable, so an endpoint that was down is a delay rather than a lost
      event. Serves brokers and prop firms alike: the account-registration
      (`registration.*`) events fire wherever Connect does, and the account
      events fire where the prop engine runs.
  - name: Challenges
    description: >-
      Being replaced by the venue API: stage rules on the venue carry the firm’s
      half of this; the trader’s enroll flow has not moved yet. The prop
      evaluation surface: challenge programs and a trader’s own enrollments.
      **Preview: the one group on this page outside the additive-only
      guarantee** (the pre-contract v1 scaffold; the Phase-1 rebuild will change
      these shapes; see Stability). **Cookie-authenticated, not
      key-authenticated**, and served only when the engine runs with
      `CHALLENGES_ENABLED`; without that flag the bundle is absent and every
      route below returns `404`. The firm-console/admin half of this surface is
      deliberately not documented here. It is back office, not licensed surface.
paths:
  /api/partner/venues/{venueId}/accounts:
    post:
      tags:
        - Venue platform preview
      summary: Issue an account into a group
      description: >-
        Private preview, disabled unless VENUE_CONFIGURATION_ENABLED is enabled
        and the vault is configured. This branch has not enabled these routes in
        the public sandbox. Existing trdrs_sk partner/tenant keys do not
        authorize these routes. Requires the named venue-key scope and current
        owner membership. account:issue. Runs the same operation the legacy
        Partner API route runs, and refuses the same things; this is the venue
        door onto it, not a second implementation. The venue must have adopted a
        firm (else `no_firm`, 404) and the group must have a route (else
        `group_has_no_route`, 409): an account that could never open a position
        is refused before anything is issued. An unknown trader email is
        `no_user_with_that_email` (404). The firm's referenceId makes the create
        idempotent; a retry with the same referenceId returns the same account
        with `created: false`.
      parameters:
        - name: venueId
          in: path
          required: true
          schema:
            type: string
            format: uuid
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            minLength: 1
            maxLength: 128
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/VenueAccountIssueRequest'
      responses:
        '201':
          description: 'Scoped result. Cache-Control: no-store.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VenueAccountIssueResponse'
        '400':
          description: Invalid input, cursor or required request/version header.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Required credential missing or invalid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: >-
            Verified identity, current owner membership or required scope
            missing.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Disabled feature, unavailable resource or wrong venue/environment.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '409':
          description: Changed idempotent request or stale version.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '413':
          description: Request exceeds the bounded body size.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '415':
          description: JSON body required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: Service or credential vault unavailable; no success is implied.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - venueOperatorKey: []
      x-codeSamples:
        - lang: javascript
          label: TypeScript
          source: >-
            const res = await
            fetch('https://app.trdrs.co/api/partner/venues/{venueId}/accounts',
            {
              method: 'POST',
              headers: {
                'content-type': 'application/json',
                Authorization: `Bearer ${process.env.TRDRS_VENUE_KEY}`,
                "Idempotency-Key": "example-request-1",
              },
              body: JSON.stringify({
                "groupId": "firm-meridian-evaluation",
                "email": "trader@example.com",
                "startingBalance": 50000,
                "referenceId": "order-84117"
              }),
            })

            const data = await res.json()
        - lang: shell
          label: cURL
          source: >-
            curl -X POST
            'https://app.trdrs.co/api/partner/venues/{venueId}/accounts' \
              -H "Authorization: Bearer $TRDRS_VENUE_KEY" \
              -H 'Idempotency-Key: example-request-1' \
              -H 'content-type: application/json' \
              -d '{"groupId":"firm-meridian-evaluation","email":"trader@example.com","startingBalance":50000,"referenceId":"order-84117"}'
components:
  schemas:
    VenueAccountIssueRequest:
      type: object
      additionalProperties: false
      properties:
        groupId:
          type: string
        email:
          type: string
        startingBalance:
          type: integer
          minimum: 1000
          maximum: 10000000
        referenceId:
          type: string
          maxLength: 80
      required:
        - groupId
        - email
        - startingBalance
        - referenceId
      example:
        groupId: firm-meridian-evaluation
        email: trader@example.com
        startingBalance: 50000
        referenceId: order-84117
    VenueAccountIssueResponse:
      type: object
      additionalProperties: false
      properties:
        account:
          $ref: '#/components/schemas/VenueIssuedAccount'
      required:
        - account
      example:
        account:
          accountId: example-account
          accountNumber: EVAL-7C21A9
          email: trader@example.com
          groupId: firm-meridian-evaluation
          balance: '50000'
          created: true
    ErrorResponse:
      type: object
      properties:
        error:
          type: string
      required:
        - error
      example:
        error: invalid_instrument
    VenueIssuedAccount:
      type: object
      additionalProperties: false
      properties:
        accountId:
          type: string
        accountNumber:
          type: string
        email:
          type: string
        groupId:
          type: string
        balance:
          type: string
          description: >-
            Exact base-ten decimal string, at most 18 fractional digits. No
            exponent notation or binary floating-point conversion.
        created:
          type: boolean
      required:
        - accountId
        - accountNumber
        - email
        - groupId
        - balance
        - created
      description: >-
        The account as the venue now knows it. `created` false means the firm's
        referenceId already owned this account and nothing new was issued.
  securitySchemes:
    venueOperatorKey:
      type: http
      scheme: bearer
      description: >-
        Private-preview venue operator key (trdrs_vk_sandbox_… or
        trdrs_vk_production_…). Bound to one venue/environment and explicit
        scopes. Issued by a verified owner session; accepted only on documented
        /api/partner/venues/{venueId} routes. Existing trdrs_sk keys are not
        interchangeable. Never grants trader, login or key-management authority.

````