Hosted Connect is a preview. The sandbox host is
https://trdrsco-connect-sandbox.fly.dev.
Production access and the final host are arranged before launch.Before you start
- Create a Venue key with the
connect:managescope in API access in the sandbox. It stays on your server. - Register your website’s exact origin under Developers → Connect websites in the sandbox
back office. An origin is the scheme and host, such as
https://your-app.example, with no path and no wildcard. It must usehttps, excepthttp://localhostwhile you develop. A sandbox website is approved at once; a production website waits for review. - Put your venue’s id in
TRDRS_VENUE_IDand the key inTRDRS_VENUE_KEYon your server.
1
Create a session on your server
When a signed-in trader asks to connect, your server creates a session for that trader’s email
and your page’s origin. This call must run on your server, because it carries the Venue key.The response is
server.js
201 with a session carrying its id, the token for the browser,
expiresAt, the origin and the environment. Keep the id on your server to check the
result later.expiresInSeconds is required, a whole number from 60 to 600, so a session lasts ten minutes
at most. The token works for one venue, one environment, one origin and one email. Send a new
idempotency-key each time you mean to create a new session, and reuse it only to retry the
same one.Required scope: connect:manage.2
Open Connect in the browser
Your page asks your server for a token, then calls
createConnect and open(). The SDK adds
the frame and removes it when Connect closes.index.html
/api/connect-session is your own server route from the first step. The trader signs in to
trdrs inside the frame and picks or connects an account.The SDK sends four events:close() removes the frame. To open Connect again after a session finishes or expires, create
a new session. Where a frame doesn’t fit, such as a small mobile web view, call
connect.redirect() instead of open(): the trader goes to the hosted page and comes back to
yours when they’re done.3
Confirm the result on your server
A browser event is for your interface, never proof of anything. Your server reads the session
it created:The response gives the session’s status and a redacted outcome. It never returns provider
credentials, the browser’s tokens or another trader’s account. To end a session early, send
DELETE to the same path. Closing is safe to repeat and never undoes a finished connection.Follow the security rules
- Keep the Venue key on your server. Never put it in JavaScript, HTML, a mobile app or a Connect address.
- Register exact origins.
https://app.example.comandhttps://admin.example.comare different origins, and each needs its own entry. - Create each session for the signed-in trader’s real email. A different trdrs user can’t use it.
- Treat
connectedas a hint for your interface, and confirm anything important on your server.
When a session is refused
Next steps
Connect overview
See how traders reach your venue’s accounts through Connect.
Venue keys
Create a Venue key with only the scopes your server needs.
Create a Connect session
Read every field of the session request and response.