> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trdrs.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Requirements

> Check your integration against the eight rules the sandbox self-check measures, plus the one it can't.

Build your integration so it behaves correctly when things go wrong, not only when they go right.
These are the rules every client of the trdrs API follows. The
[sandbox self-check](/providers/test-evidence) measures eight of them from your real traffic, and
you confirm the ninth yourself, because it's about how your screen shows money.

Use this page as the checklist before you run the self-check. This is about software that calls the
trdrs API. A market that trdrs calls instead follows the [provider self-check](/providers/provider-self-check).

## The rules

| Rule | What it means |
| - | - |
| Keys stay on your server | Venue keys, Trading API keys and Partner keys never reach a browser or an app. |
| Each key calls its own routes | Partner keys call only `/api/partner/` routes, and Venue keys only `/api/partner/venues/` routes. |
| Every order has a `clientOrderId` | Each order you send carries your own stable id. |
| A retry reuses its `clientOrderId` | Sending an order again after a timeout uses the same id, so the trader's order never happens twice. |
| A `429` is waited out | Your client waits the `Retry-After` time before calling again. |
| A `423` is a risk lock | Your client stops sending that order, rather than retrying it as if it were a glitch. |
| Streams recover from a snapshot | After a reconnect, your market and account streams take the fresh full snapshot the stream sends first. |
| Registrations carry no credential | A Connect registration never includes a trader's password. |
| Unknown money shows as unknown | A money field that's `null` is shown as unknown, never as zero. You confirm this one yourself. |

## Audit your code with an agent

Paste this prompt into your coding agent to find the usual gaps before you run the self-check:

```text theme={null}
Audit this integration against the trdrs conformance requirements.
Find every browser exposure of TRDRS_VENUE_KEY, TRDRS_TRADING_API_KEY or TRDRS_PARTNER_KEY.
Find every order call and verify clientOrderId is stable across retries.
Find every 429 handler and verify it reads Retry-After.
Find every stream reconnect path and verify it accepts a full snapshot.
Report failing files and propose patches.
```

The agent reports the files that break a rule and suggests fixes. Then prove the fixes with a run.

## Next steps

<CardGroup cols={2}>
  <Card title="Run a self-check" icon="flask" href="/providers/test-evidence">
    Exercise your integration against the sandbox and get measured results.
  </Card>

  <Card title="Use your results" icon="file-check" href="/providers/submission">
    Keep the result with your release, and fix what failed.
  </Card>
</CardGroup>
