> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trdrs.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Pin a published release to your venue

> Preview: served on the sandbox to every venue, and production availability is arranged when a venue qualifies. Trading API keys and Partner keys do not authorize these routes. Provider directory publication is separate from execution qualification, trader Connect and private customer connections. No credential, private endpoint or account binding is published. Profile changes hide the listing until a release for the new profile version is reviewed. Every write requires Idempotency-Key; an identical retry returns its original result, a changed body refuses with idempotency_conflict. Required scope: `provider:manage`. Requires provider:manage. Copies the approved immutable manifest into a venue-local candidate registration with publishedReleaseId. The evidence environment must match the venue. Credentials and validation are configured separately through the existing Connections routes. A listing never grants liquidity or execution.



## OpenAPI

````yaml /api/openapi.json post /api/partner/venues/{venueId}/provider-catalog/releases/{releaseId}/install
openapi: 3.1.0
info:
  title: trdrs Engine API
  version: 1.1.0
  description: >-
    ## API Reference


    Every route the trdrs engine serves, with what to send and what comes back.
    It covers market

    data and news, trading and account state for a trader's own software,
    Connect pre-registration,

    the venue routes a prop firm or brokerage runs its accounts through, and a
    trader's own challenges.


    Start with the Quickstart for your first call. The API standards hold the
    rules every route

    shares: keys, errors, rate limits, idempotency, paging and streaming.
servers:
  - url: https://app.trdrs.co
    description: Production
  - url: /
    description: This engine
security: []
tags:
  - name: Venue platform preview
    description: >-
      Run your venue: its providers, instruments, conditions, groups, routes,
      stages, venue rules, keys, accounts, usage, balance receipts and webhooks.
      These routes are in preview. They are served on the sandbox to every
      venue, and production access is arranged when a venue qualifies. Every
      route here under `/api/partner/` takes a Venue key. The back office
      reaches the same routes under `/api/operator/` with a verified owner’s
      session, because a browser never holds a Venue key, and both run the same
      checks. Changes to these routes are additive only from here on.
  - name: Market data
    description: >-
      Search and look up symbols, read price history and quotes, check the
      server clock, and stream live bars. Crypto prices come from each
      provider’s public feed. Futures prices are licensed to each user and
      stream only from that trader’s own futures source: a login on their firm’s
      production Rithmic system, under their own market data subscription. A
      Rithmic Test login carries no market data. Without a source, a futures
      request answers 503 `feed_requires_connection` and the symbol search lists
      no futures.
  - name: News
    description: >-
      Market news and the economic calendar, from licensed and open sources,
      tagged with futures roots as they arrive. The content is the same for
      everyone, and these routes admit the same callers as market data: a
      licensed origin, a session or a Trading API key. Page headlines by publish
      time, filter them by instrument root, and stream them live over
      server-sent events. Thumbnails come through the image route.
  - name: Trading
    description: >-
      Place, change and cancel orders, set a position’s exits, and close or
      flatten positions. Every call that places an order takes a `clientOrderId`
      as its idempotency key.
  - name: Account
    description: >-
      Read an account a trader can trade: its balance, positions, working
      orders, fills, profit and loss history, and the live account stream. You
      don’t create accounts here. A trader connects their own account at a
      provider, or opens their own Demo on the paper book, in the trdrs app. A
      venue issues accounts on the paper book with Issue an account into a
      group, and a firm pre-registers accounts at a provider through Connect
      with Pre-register a trader’s account.
  - name: Connect
    description: >-
      Connect is the account picker a trader opens, in the trdrs app or embedded
      on a firm’s site. It lists the built-in providers and every listed venue.
      The pre-registration routes let a firm fill it in ahead of time. You tell
      trdrs that a trader has an account at a built-in provider: their sign-in
      email, and optionally the account number and login name. When that trader
      signs in, Connect shows the account ready to link, and they sign in to the
      provider themselves, once. Nothing here sends a password or grants access
      before the trader’s own login succeeds. You can list who you
      pre-registered and who has linked, and cancel a pre-registration that
      hasn’t been used. A pre-registration expires after 30 days, and sending it
      again refreshes it. These routes take the Partner key. The whole flow is
      in the **[Quick Start](/docs/guides/quick-start)**.
  - name: Challenges
    description: >-
      These routes list evaluation programs and a trader’s own enrollments.
      **Preview: the one group in this reference outside the additive-only
      guarantee.** Their shapes will change when challenges are rebuilt; see
      Stability. **They take a signed-in session, not a key**, and are served
      only where the engine runs with `CHALLENGES_ENABLED`. Without it, the
      routes don’t exist and every one answers `404`. The administration half
      isn’t documented here, because it is trdrs’s own tooling, not part of the
      API.
paths:
  /api/partner/venues/{venueId}/provider-catalog/releases/{releaseId}/install:
    post:
      tags:
        - Venue platform preview
      summary: Pin a published release to your venue
      description: >-
        Preview: served on the sandbox to every venue, and production
        availability is arranged when a venue qualifies. Trading API keys and
        Partner keys do not authorize these routes. Provider directory
        publication is separate from execution qualification, trader Connect and
        private customer connections. No credential, private endpoint or account
        binding is published. Profile changes hide the listing until a release
        for the new profile version is reviewed. Every write requires
        Idempotency-Key; an identical retry returns its original result, a
        changed body refuses with idempotency_conflict. Required scope:
        `provider:manage`. Requires provider:manage. Copies the approved
        immutable manifest into a venue-local candidate registration with
        publishedReleaseId. The evidence environment must match the venue.
        Credentials and validation are configured separately through the
        existing Connections routes. A listing never grants liquidity or
        execution.
      parameters:
        - name: venueId
          in: path
          required: true
          schema:
            type: string
            format: uuid
        - name: releaseId
          in: path
          required: true
          schema:
            type: string
            format: uuid
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            minLength: 1
            maxLength: 128
          description: >-
            A key you choose, 1 to 128 characters, that identifies this write.
            Send the same key when you retry it, so the write is never applied
            twice.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ProviderReleaseInstallRequest'
      responses:
        '200':
          description: >-
            Success. The response is sent with `Cache-Control: no-store`, so
            don't cache it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProviderReleaseInstallResponse'
        '400':
          description: >-
            The request is malformed: invalid JSON or input, a bad cursor, or a
            missing `Idempotency-Key` or `If-Match` header. When one value is
            refused, `field` names it where the check can say which.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: >-
            The Venue key or the session is missing, malformed, revoked or
            expired.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: >-
            The credential is valid but can't do this: the key lacks the scope
            or its creator is no longer an owner, the email isn't verified, a
            reader tried to write, or the request came from an origin that isn't
            trusted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: >-
            The venue, account or resource doesn't exist in this environment, or
            isn't yours to see.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '409':
          description: >-
            The request conflicts with what is stored: the `Idempotency-Key` was
            used with a different body, or the version you sent is stale. The
            `error` code names the conflict.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '413':
          description: The body is larger than this route accepts.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '415':
          description: 'Send the body as JSON, with `Content-Type: application/json`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: >-
            trdrs can't complete the request right now, because a part of the
            venue platform or its credential store is unavailable. Don't assume
            a write happened: retry it with the same `Idempotency-Key`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - venueOperatorKey: []
      x-codeSamples:
        - lang: javascript
          label: TypeScript
          source: >-
            const res = await
            fetch('https://app.trdrs.co/api/partner/venues/{venueId}/provider-catalog/releases/{releaseId}/install',
            {
              method: 'POST',
              headers: {
                'content-type': 'application/json',
                Authorization: `Bearer ${process.env.TRDRS_VENUE_KEY}`,
                "Idempotency-Key": "example-request-1",
              },
              body: JSON.stringify({}),
            })

            const data = await res.json()
        - lang: shell
          label: cURL
          source: >-
            curl -X POST
            'https://app.trdrs.co/api/partner/venues/{venueId}/provider-catalog/releases/{releaseId}/install'
            \
              -H "Authorization: Bearer $TRDRS_VENUE_KEY" \
              -H 'Idempotency-Key: example-request-1' \
              -H 'content-type: application/json' \
              -d '{}'
components:
  schemas:
    ProviderReleaseInstallRequest:
      type: object
      additionalProperties: false
      properties: {}
      required: []
      example: {}
    ProviderReleaseInstallResponse:
      type: object
      additionalProperties: false
      properties:
        provider:
          $ref: '#/components/schemas/VenueProviderVersion'
        tradingReady:
          const: false
      required:
        - provider
        - tradingReady
      example:
        provider:
          id: 00000000-0000-0000-0000-000000000001
          venueId: 00000000-0000-0000-0000-000000000001
          name: Example Pricing
          manifest:
            providerVersion: example-1
            protocolVersion: '1.0'
            schemaDigest: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
            capabilities:
              accounts: false
              execution: false
              marketData: true
              generationFencing: false
              completeOrderBook: false
              executionHistory: false
              executionCorrections: false
              orderTypes: []
              timeInForce: []
              reduceOnly: false
              nativeReplace: false
              nativeOco: false
              accountProvisioning: false
              positionModels: []
              replayRetentionSeconds: 0
          manifestHash: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
          publishedReleaseId: 00000000-0000-0000-0000-000000000001
          state: candidate
          creationKey: example-request
          creationHash: bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
          createdAt: '2026-09-14T12:00:00.000Z'
        tradingReady: false
    ErrorResponse:
      type: object
      description: >-
        The body of every error response. It always carries `error`, an English
        sentence you can show. A refused trading request also carries `code`,
        one of the refusal codes, and `params`, the details of that refusal.
        Translate by `code` and `params`, and show a generic message for a code
        you don't recognize. Other errors may carry a `code` of their own.
      properties:
        error:
          type: string
          description: What went wrong, as an English sentence.
        code:
          type: string
          description: >-
            A stable machine code. On a refused trading request, it is one of
            the refusal codes.
        params:
          type: object
          description: >-
            The details of the refusal named by `code`, on a refused trading
            request.
      required:
        - error
      example:
        error: invalid_instrument
    VenueProviderVersion:
      type: object
      additionalProperties: false
      properties:
        id:
          type: string
          format: uuid
        venueId:
          type: string
          format: uuid
        name:
          type: string
        publishedReleaseId:
          type:
            - string
            - 'null'
          format: uuid
        manifest:
          $ref: '#/components/schemas/VenueProviderManifest'
        manifestHash:
          type: string
        state:
          type: string
          enum:
            - candidate
            - sandbox_usable
            - qualified
        creationKey:
          type: string
        creationHash:
          type: string
        createdAt:
          type: string
          format: date-time
      required:
        - id
        - venueId
        - name
        - publishedReleaseId
        - manifest
        - manifestHash
        - state
        - creationKey
        - creationHash
        - createdAt
    VenueProviderManifest:
      type: object
      additionalProperties: false
      properties:
        providerVersion:
          type: string
        protocolVersion:
          const: '1.0'
        schemaDigest:
          type: string
          pattern: ^[a-f0-9]{64}$
        capabilities:
          type: object
          additionalProperties: false
          properties:
            accounts:
              type: boolean
            execution:
              type: boolean
            marketData:
              type: boolean
            generationFencing:
              type: boolean
            completeOrderBook:
              type: boolean
            executionHistory:
              type: boolean
            executionCorrections:
              type: boolean
            orderTypes:
              type: array
              items:
                type: string
                enum:
                  - market
                  - limit
                  - stop
                  - stop_limit
            timeInForce:
              type: array
              items:
                type: string
                enum:
                  - day
                  - gtc
                  - ioc
                  - fok
                  - post_only
            reduceOnly:
              type: boolean
            nativeReplace:
              type: boolean
            nativeOco:
              type: boolean
            accountProvisioning:
              type: boolean
            positionModels:
              type: array
              items:
                type: string
                enum:
                  - net
                  - hedged
            replayRetentionSeconds:
              type: integer
              minimum: 0
              maximum: 31536000
          required:
            - accounts
            - execution
            - marketData
            - generationFencing
            - completeOrderBook
            - executionHistory
            - executionCorrections
            - orderTypes
            - timeInForce
            - reduceOnly
            - nativeReplace
            - nativeOco
            - accountProvisioning
            - positionModels
            - replayRetentionSeconds
      required:
        - providerVersion
        - protocolVersion
        - schemaDigest
        - capabilities
      description: >-
        A public provider's declaration of what it supports, checked against the
        provider contract. A provider must offer accounts, market data or both.
        One that offers execution must also offer accounts, generation fencing,
        a complete order book and execution history, keep at least seven days of
        replay, and list at least one order type, time in force and position
        model; one that doesn't can't declare any execution feature, and account
        provisioning and position models need accounts. Lists hold no
        duplicates, and registering a manifest doesn't certify its claims.
  securitySchemes:
    venueOperatorKey:
      type: http
      scheme: bearer
      description: >-
        The Venue key (`trdrs_vk_sandbox_…` or `trdrs_vk_production_…`), in
        preview. It belongs to one venue in one environment and carries the
        scopes it was created with. The venue's verified owner creates it while
        signed in, and it works only on the `/api/partner/venues/{venueId}`
        routes. A `trdrs_sk_…` key can't be used in its place. It never lets you
        act as a trader, sign in or manage keys. Keep it on your server.

````