Skip to content
MyStocks Developers
API v1

API v1

Current stable contract

Versioning policyRelease changelog
Sandbox console
On-prem deployment

Install the on-prem platform

Prepare DNS, TLS, registry access and your Linux host, then install a digest-pinned MyStocks partner release.

Journey overview · Next: activation and keys

Before installation

Use the deployment planner to preview commands for an on-site, AWS, Azure, Google Cloud or other Linux VM. Enter your final choices in the access request. These targets use the same supported installer; your infrastructure team first creates the VM, networking, DNS and identity configuration. Kubernetes and private-edge selections require architecture review and a separate agreed runbook; the planner does not claim to provision them automatically.

What resources and limits apply?

ItemCurrent behavior
Request bodyUp to 10 MiB through the on-prem proxy.
Ordinary upstream request30-second timeout.
Server-sent eventsConnection lifetime up to 300 seconds; reconnect and revalidate.
Private application port3000 by default; installer accepts 1024 through 65535.
CPU, RAM, disk and concurrent usersNo benchmark-certified minimum or throughput guarantee is published. Submit available vCPUs, RAM and disk in GiB, and expected users for capacity review.
Offline useNot supported; cloud verification is required for protected access.

These proxy limits do not override cloud endpoint limits or your partner rate-limit tier. Resource fields in the form are planning inputs, not reservations or enforced container quotas.

Host prerequisites

  • Obtain an approved partner organization, active full API credential and authorized team accounts.
  • Prepare a Linux AMD64 or ARM64 host with Docker Engine, Docker Compose and Python 3. Capacity is agreed during onboarding; no universal sizing guarantee is implied.
  • Control an exact public domain and publish its supplied DNS TXT ownership challenge. Point A and any AAAA records to working addresses; remove stale IPv6 records.
  • Allow inbound 80/443 as required by your HTTPS proxy and certificate challenge. Keep the application port private (default loopback port 3000).
  • Allow DNS and outbound HTTPS to MyStocks, Firebase authentication and your approved image registry. Maintain accurate system time.
  • Obtain a domain-bound license through a secure channel, registry reader access and an immutable approved image digest. Registry access and the installation license are separate credentials.
  • Have the identity administrator register your installation domain in the authoritative Firebase project's authorized domains.
  • Use Safari 16.4+, Chrome 111+ or Firefox 128+ for the workspace.

Which installer version should we use?

These commands were checked against installer revision ce0c36171 on 3 October 2026. Obtain the approved image digest from onboarding; the installer and image have separate versions. The download URL serves the current installer. Verify its checksum before running this revision:

curl -fsSLo install-onprem.sh https://mystocks.africa/install-onprem.sh
printf '%s  %s\n' '16540118749f778b2e4947556bcaa061d28badc6d44b176a937912deb83e22de' 'install-onprem.sh' | sha256sum --check -
bash -n install-onprem.sh

Stop on checksum mismatch and obtain reviewed release instructions. Do not bypass the check or assume an updated script is compatible with an older image. Keep the verified script with the release record.

Default installation: Docker and Caddy

Authenticate Docker to the registry specified in your release instructions before installation. Download and review the installer; do not pipe an unreviewed script into a privileged shell.

curl -fsSLo install-onprem.sh https://mystocks.africa/install-onprem.sh
# Review the file. Replace the domain and image with approved values.
sudo bash install-onprem.sh --domain trading.example.com \
  --image REGISTRY/IMAGE@sha256:DIGEST \
  --mode docker --proxy caddy

Enter the license at the hidden terminal prompt. For automation, use --key-file PATH with a file readable only by its owner; never put a license in command arguments, shell history or browser code. The installer verifies the license before pulling the image and writes a protected environment file under /opt/mystocks by default.

The installer uses flags rather than an interactive deployment-choice menu. Docker and Caddy are the defaults.

Select a proxy

FlagRequired preparation
--proxy caddyWorking public DNS and certificate-challenge reachability; Caddy obtains TLS certificates.
--proxy nginxInstall the generated configuration, provide certificates at its configured paths and validate with nginx -t. Certificate issuance is your responsibility.
--proxy traefikProvide the existing proxy network, websecure entrypoint and letsencrypt resolver. Select a network with --traefik-network.
--proxy noneSupply and manage an external TLS reverse proxy yourself.

Preserve the verified domain's Host header, keep upstream port 3000 private, and disable response buffering for server-sent events. Do not disable TLS certificate verification. The generated installer configuration differs from the repository's example Compose networking; use one complete configuration rather than mixing fragments.

Exact proxy commands

After verifying the script, set your approved values. The digest must contain 64 hexadecimal characters:

DOMAIN='trading.example.com'
IMAGE='REGISTRY/IMAGE@sha256:DIGEST'
# Choose ONE command matching your prepared infrastructure:
sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode docker --proxy caddy
sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode docker --proxy nginx
sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode docker --proxy traefik --traefik-network proxy
sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode docker --proxy none

Do not run all four alternatives. Nginx needs your installed TLS certificates; Traefik needs the existing proxy network, entrypoint and resolver described above. Use --output-dir consistently when your approved installation directory differs from /opt/mystocks.

Native service option

Use --mode bare-metal --proxy nginx or --proxy none on Debian 12 or Ubuntu 24.04 with Node.js 22 and systemd. Docker is still required to extract the matching glibc image bundle. The application runs as a dedicated unprivileged service user; this is not a Docker-free installation path.

sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode bare-metal --proxy nginx
# Or use --proxy none with your independently managed TLS ingress.

Verify before accepting traffic

curl --fail --show-error https://trading.example.com/api/live
curl --fail --show-error https://trading.example.com/api/health

Liveness alone is insufficient. Confirm readiness, certificate hostname and chain, authorized sign-in and a read-only API call. Then test authorized sandbox workflows, rejection of anonymous/cross-partner requests, and restart recovery in a dedicated test installation. --render-only produces configuration with an invalid fixture credential; it does not deploy or verify a working installation.

Continue with API connectivity and operations.

Was this page useful?

Your signal helps us tighten partner onboarding docs.

Send note

Last updated on

On this page