Hosted API, OnPrem or both
Choose a deployment model and understand Sandbox, Hosted Live approval, installation licensing and separate credentials.
Can one account use Hosted API and OnPrem?
Yes. Choose Hosted API, OnPrem or Both during onboarding. One partner account can have hosted API access and installations, with separate approvals and credentials. Choosing a deployment model records your intent; it does not authorize production access.
| Choice | Start here | Production requirement |
|---|---|---|
| Hosted API | Register, then build in Sandbox | Approved Hosted Live access and an active production API credential |
| OnPrem | Request access, then explore the approved evaluation | Installation license, release, identity and production readiness approval |
| Both | Register once and request an installation under the same approved organization | Hosted and installation approvals are independent |
A Hosted API/Both partner application approval explicitly approves Hosted Live. An OnPrem-only partner application creates evaluation access. Approving an OnPrem request or preparing its evaluation package does not approve Hosted Live, including when that installation request says Both. Administrators can review Hosted Live separately in the organization's workspace. Existing organizations keep their established permissions when an installation request is linked.
What does Sandbox versus Live mean?
Sandbox is the testing environment. Live uses production authorization and can affect real accounts and funds. The dashboard selector checks access on the server before navigating; changing the selection does not issue a key or approve your organization. API authentication also rechecks permissions on each call.
| Environment | Direct hosted base URL | Credential | Important boundaries |
|---|---|---|---|
| Sandbox | https://mystocks.africa/api/sandbox/v1/partner | sk_sandbox_ | Synthetic execution; sandbox prices delayed 15 minutes; enterprise/team/security endpoints unavailable |
| Live | https://mystocks.africa/api/v1/partner | pk_live_ or an authorized derived credential | Hosted approval, scopes, organization status, commercial and financial controls still apply |
Master /trade and /payout deliberately reject Sandbox requests. Check each operation's availability in the API catalog; do not assume full environment parity. Market-data tiers distinguish the paid real-time commercial policy from the current feed's reported freshness.
Which credential should I use?
| Credential | Purpose | Lifecycle |
|---|---|---|
| Sandbox API key | Synthetic Sandbox integration | Managed in the Sandbox console; never a production approval |
| Production full API key | Authorized Hosted Live integration from your backend | Issued through the approved console; rotation/revocation retains the stable organization |
| Data key | Restricted read-only market-data families | Derived from a parent API credential; no trading, funding or customer PII |
| OAuth token | Short-lived authorized API calls | Inherits key type/scopes; expires after 15 minutes and remains subject to current authorization |
| Firebase ID token | Signed-in portal actions | Represents the user, not a partner integration API key |
| Installation license credential | Domain-bound gateway authorization | Temporary or permanent/revocable license; installed privately and bound to enrolled installation identity |
Do not put an installation credential into hosted API examples or expose it to browsers. Key Management covers API rotation; activation and renewal covers installation credentials and authenticated one-time retrieval. Notification emails contain retrieval links and instructions, not secret keys.
Can we evaluate before DNS is ready?
Yes. Hosted evaluation requires no installation domain. Self-hosted evaluation permits synthetic Sandbox workflows before ownership verification, but still needs appropriate hostname routing, HTTPS and sign-in configuration. Production activation requires a fresh verified ownership challenge, enrolled identity, an approved compatible image and an active applied commercial contract. DNS proof alone never enables production.
Who operates each component?
| Responsibility | Hosted API | OnPrem |
|---|---|---|
| API hosting and platform workers | MyStocks | MyStocks cloud remains authoritative; partner operates the gateway |
| Host, container runtime, storage and backups | MyStocks | Partner, using the approved deployment runbook |
| Installation domain, routing DNS and TLS | Not required for direct hosted API access | Partner; ownership TXT/CNAME is separate from routing and TLS |
| Application secrets and integration behavior | Partner | Partner; also protect the installation private identity |
| Licensing, production approval and cloud permissions | MyStocks administration | MyStocks administration with partner readiness evidence |
| Wallet, order, KYC and settlement authority | MyStocks platform controls | The same cloud controls; no offline trading or local balance authority |
| Monitoring and incident response | Shared integration responsibility | Shared; partner additionally monitors its host and gateway |
Next: use your workspace, build the API integration, or install OnPrem.
Was this page useful?
Your signal helps us tighten partner onboarding docs.
Last updated on