| Keys stay on your server | Venue keys, Trading API keys and Partner keys never reach a browser or an app. |
| Each key calls its own routes | Partner keys call only /api/partner/ routes, and Venue keys only /api/partner/venues/ routes. |
Every order has a clientOrderId | Each order you send carries your own stable id. |
A retry reuses its clientOrderId | Sending an order again after a timeout uses the same id, so the trader’s order never happens twice. |
A 429 is waited out | Your client waits the Retry-After time before calling again. |
A 423 is a risk lock | Your client stops sending that order, rather than retrying it as if it were a glitch. |
| Streams recover from a snapshot | After a reconnect, your market and account streams take the fresh full snapshot the stream sends first. |
| Registrations carry no credential | A Connect registration never includes a trader’s password. |
| Unknown money shows as unknown | A money field that’s null is shown as unknown, never as zero. You confirm this one yourself. |