Skip to content
MyStocks Developers
API v1

API v1

Current stable contract

Versioning policyRelease changelog
Sandbox console
Start building

Hosted API, OnPrem or both

Choose a deployment model and understand Sandbox, Hosted Live approval, installation licensing and separate credentials.

Can one account use Hosted API and OnPrem?

Yes. Choose Hosted API, OnPrem or Both during onboarding. One partner account can have hosted API access and installations, with separate approvals and credentials. Choosing a deployment model records your intent; it does not authorize production access.

ChoiceStart hereProduction requirement
Hosted APIRegister, then build in SandboxApproved Hosted Live access and an active production API credential
OnPremRequest access, then explore the approved evaluationInstallation license, release, identity and production readiness approval
BothRegister once and request an installation under the same approved organizationHosted and installation approvals are independent

A Hosted API/Both partner application approval explicitly approves Hosted Live. An OnPrem-only partner application creates evaluation access. Approving an OnPrem request or preparing its evaluation package does not approve Hosted Live, including when that installation request says Both. Administrators can review Hosted Live separately in the organization's workspace. Existing organizations keep their established permissions when an installation request is linked.

What does Sandbox versus Live mean?

Sandbox is the testing environment. Live uses production authorization and can affect real accounts and funds. The dashboard selector checks access on the server before navigating; changing the selection does not issue a key or approve your organization. API authentication also rechecks permissions on each call.

EnvironmentDirect hosted base URLCredentialImportant boundaries
Sandboxhttps://mystocks.africa/api/sandbox/v1/partnersk_sandbox_Synthetic execution; sandbox prices delayed 15 minutes; enterprise/team/security endpoints unavailable
Livehttps://mystocks.africa/api/v1/partnerpk_live_ or an authorized derived credentialHosted approval, scopes, organization status, commercial and financial controls still apply

Master /trade and /payout deliberately reject Sandbox requests. Check each operation's availability in the API catalog; do not assume full environment parity. Market-data tiers distinguish the paid real-time commercial policy from the current feed's reported freshness.

Which credential should I use?

CredentialPurposeLifecycle
Sandbox API keySynthetic Sandbox integrationManaged in the Sandbox console; never a production approval
Production full API keyAuthorized Hosted Live integration from your backendIssued through the approved console; rotation/revocation retains the stable organization
Data keyRestricted read-only market-data familiesDerived from a parent API credential; no trading, funding or customer PII
OAuth tokenShort-lived authorized API callsInherits key type/scopes; expires after 15 minutes and remains subject to current authorization
Firebase ID tokenSigned-in portal actionsRepresents the user, not a partner integration API key
Installation license credentialDomain-bound gateway authorizationTemporary or permanent/revocable license; installed privately and bound to enrolled installation identity

Do not put an installation credential into hosted API examples or expose it to browsers. Key Management covers API rotation; activation and renewal covers installation credentials and authenticated one-time retrieval. Notification emails contain retrieval links and instructions, not secret keys.

Can we evaluate before DNS is ready?

Yes. Hosted evaluation requires no installation domain. Self-hosted evaluation permits synthetic Sandbox workflows before ownership verification, but still needs appropriate hostname routing, HTTPS and sign-in configuration. Production activation requires a fresh verified ownership challenge, enrolled identity, an approved compatible image and an active applied commercial contract. DNS proof alone never enables production.

Who operates each component?

ResponsibilityHosted APIOnPrem
API hosting and platform workersMyStocksMyStocks cloud remains authoritative; partner operates the gateway
Host, container runtime, storage and backupsMyStocksPartner, using the approved deployment runbook
Installation domain, routing DNS and TLSNot required for direct hosted API accessPartner; ownership TXT/CNAME is separate from routing and TLS
Application secrets and integration behaviorPartnerPartner; also protect the installation private identity
Licensing, production approval and cloud permissionsMyStocks administrationMyStocks administration with partner readiness evidence
Wallet, order, KYC and settlement authorityMyStocks platform controlsThe same cloud controls; no offline trading or local balance authority
Monitoring and incident responseShared integration responsibilityShared; partner additionally monitors its host and gateway

Next: use your workspace, build the API integration, or install OnPrem.

Was this page useful?

Your signal helps us tighten partner onboarding docs.

Send note

Last updated on

On this page