Skip to content
MyStocks Developers
API v1

API v1

Current stable contract

Versioning policyRelease changelog
Sandbox console
On-prem deployment

On-prem API and identity connectivity

Route authenticated requests through your installation while retaining cloud permissions, sandbox restrictions and identity controls.

Journey overview · Next: operations and troubleshooting

How requests reach MyStocks

Your application calls your approved HTTPS installation domain. The on-prem server forwards permitted requests to MyStocks with a server-only installation credential and the caller's own API key or user token. Cloud partner identity, scopes, rate limits and permissions remain authoritative; the installation key is not a replacement for API authentication.

PurposeAddress
Cloud production APIhttps://mystocks.africa/api/v1/partner
On-prem production proxyhttps://YOUR-DOMAIN/api/v1/partner
Cloud sandbox APIhttps://mystocks.africa/api/sandbox/v1/partner
On-prem sandbox proxyhttps://YOUR-DOMAIN/api/sandbox/v1/partner

Use the endpoint's authentication requirements from Authentication and OpenAPI. Start with a permitted read-only request from the Quick Start, changing only the origin to your approved installation. Keep credentials server-side; do not embed installation secrets in SDKs or browser requests.

Sandbox boundaries

Use sandbox credentials only with sandbox paths and confirm the required sub-account identifiers. An on-prem license does not enable unavailable sandbox enterprise/team/security operations or master trade/payout operations. Follow the sandbox guide and each endpoint's documented availability.

Sign-in, SSO and MFA

Users sign in with their real MyStocks accounts and must belong to the licensed organization. The installer obtains public Firebase client configuration through license verification; never install a Firebase administrative credential in this image.

For SAML/OIDC, configure the active provider in the authoritative Firebase/Identity Platform project and partner SSO settings. Rerun the installer after changing the provider configuration. The exact provider identity is checked; a license alone does not enroll users. Membership creation through invitations or just-in-time provisioning remains subject to configured organization policies.

Enrolled Firebase TOTP authenticator challenges are supported. Enroll or recover factors through your identity administrator before enforcing MFA. SMS challenge UI and authenticator enrollment are not included in this image. Verify your actual identity provider; acceptance with one test provider does not certify every vendor configuration.

Proxy and edge behavior

Preserve the approved Host header and use verified HTTPS upstream connections. Configure streaming without response buffering. The application proxy implements HTTP and server-sent events; an edge proxy accepting WebSocket upgrades does not establish a WebSocket API contract.

Do not inject trusted certificate-attestation headers from clients. Any required mutual-TLS integration must use the approved trusted proxy configuration and server-side attestation secret; certificate headers alone are not authorization. Cloud SCIM uses the gateway URL returned by the cloud console.

Acceptance checks

  • Readiness succeeds on the public domain and login resolves the expected organization.
  • A permitted read succeeds; anonymous, wrong-domain and cross-partner requests fail.
  • Authorized sandbox actions work within their documented restrictions, with no production money movement.
  • Streaming reconnects and revalidates authorization; credentials are absent from URLs and application logs.
  • Revocation, expiry and cloud-disconnection behavior are exercised in a dedicated test installation.

Was this page useful?

Your signal helps us tighten partner onboarding docs.

Send note

Last updated on

On this page