Skip to content

OnPrem Access

Your infrastructure.
Connected to MyStocks.

Run the partner platform on your own domain and host. Keep your team’s workspace close, with authenticated API requests routed through the MyStocks gateway.

Requires an active cloud connection. OnPrem is not an offline trading system.

One partner workspace, on your domain

Partner console

Navigate accounts, trading tools, reports, team access and operational controls according to your cloud role and permissions.

API gateway

Route partner and sandbox API calls through the installation. Caller credentials, rate limits, idempotency and cloud policies remain enforced.

Enterprise sign-in

Use configured OIDC or SAML sign-in and supported authenticator challenges. Provider setup and user enrollment are separate onboarding steps.

Deployment choices

Use Docker with Caddy, Nginx or Traefik, or a supported native Linux service with an HTTPS proxy.

Before you install

  • An approved partner organization with an active full API credential and authorized team accounts.
  • A Linux AMD64 or ARM64 host, Docker Engine, Compose and Python 3. Native mode supports Debian 12 or Ubuntu 24.04 with Node.js 22 and systemd; Docker is still used to extract the image.
  • An exact public domain you control, permission to publish its DNS TXT ownership challenge, and HTTPS ingress on ports 80/443. Keep the application’s internal port private.
  • Outbound HTTPS to MyStocks, Firebase authentication and the private image registry, plus DNS resolution and accurate system time. SSE connections require a proxy configured without response buffering.
  • A domain-bound installation license and separate, repository-scoped registry reader access. Store secrets on the server and never in browser code.

Capacity, availability targets, networking and vendor-specific SSO are reviewed during onboarding.

Installation, step by step

  1. Request access. Submit your organization, domain and requirements below. We email you when the application is received and reviewed.
  2. Verify your domain. Publish the TXT record supplied by your administrator. The administrator verifies ownership and grants temporary access until an exact date/time or permanent, revocable access.
  3. Collect your release details. Receive your key securely, authenticate Docker to the private registry, and obtain the approved image digest. Your activation email includes these installation instructions, without the secret.
  4. Run the installer. Download and review the script, then run it with your domain and digest-pinned image. Enter the license at the secure prompt.
    curl -fsSLo install-onprem.sh https://mystocks.africa/install-onprem.sh
    # Review the downloaded script before running it.
    sudo bash install-onprem.sh --domain trading.example.com \
      --image REGISTRY/IMAGE@sha256:DIGEST

    Replace the example domain and image with your approved values. Defaults are Docker with Caddy. Select another configuration explicitly with --proxy and --mode; see the full guide below.

  5. Check readiness and sign in. Confirm https://YOUR-DOMAIN/api/health returns ready. Sign in with an authorized partner account, then verify a read-only account request before running sandbox workflows.
  6. Connect your application. Use https://YOUR-DOMAIN/api/v1/partner/… or /api/sandbox/v1/… as appropriate. Send your normal partner API credentials. The on-prem server adds its installation credential and forwards to MyStocks.

When access expires

Protected API calls stop at expiry. The installation displays an access wall with a new-request link. Submit a renewal request; approval can grant temporary or permanent access. Your administrator must install the replacement key, then recheck readiness. A cloud outage also closes access until verification recovers.

Read the complete installation and operations guides →

Installation and administration answers

Can on-prem operate without MyStocks Cloud?

No. Protected access and readiness require cloud license verification. On-prem is not an offline trading system.

Who manages the server, DNS and TLS?

Your infrastructure team operates the host, DNS, TLS, backups and upgrades. MyStocks Cloud remains authoritative for API authorization, trading and balances.

What happens when temporary access expires?

Protected calls are denied and an access wall provides a new-request link. Submit a renewal for administrator approval, install the replacement key securely and recheck readiness.

Does permanent access mean access cannot be revoked?

No. Permanent access has no scheduled expiry, but remains revocable and bound to the approved organization and domain.

Plan your deployment

Explore supported configurations. Enter your final choices in the application below; administrators review capacity and approve a release before activation.

Your deployment checklist

  • AMD64 Linux host; Docker Engine, Compose plugin and Python 3.
  • Provision trading.example.com; verify its DNS TXT ownership challenge and authorized Firebase sign-in domain.
  • Keep application port 3000 private. Permit DNS and outbound HTTPS to MyStocks, Firebase and the image registry.
  • Use separate registry reader access and an active domain-bound installation key. Never include secrets in this form or email.
  • Allow inbound 80/443 and certificate challenges; Caddy manages TLS.

Download and checksum-verify the installer using the linked guide. Replace the image placeholder with the administrator-approved digest, then enter the key at the hidden prompt.

sudo bash install-onprem.sh --domain trading.example.com --image REGISTRY/IMAGE@sha256:DIGEST --mode docker --proxy caddy --port 3000
curl --fail --show-error https://trading.example.com/api/health
Versioned installer, checksum and detailed guide
Current implementation limits, not throughput guarantees
Request body10 MiB maximum
Upstream request timeout30 seconds
SSE connection lifetime5 minutes, then reconnect and revalidate
Application port3000 by default; configurable from 1024–65535
CPU / RAM / disk / concurrencyNo benchmark-certified minimum or capacity guarantee. Submit available resources for review.
Offline operationNot supported; protected requests fail closed without cloud verification.

Access plans

Temporary evaluation

An administrator-approved evaluation with an exact expiry. Explore the platform and validate your installation and sandbox integration.

Duration and scope agreed during review.

Discuss access →

Enterprise

Deployment for your organization, with onboarding and requirements reviewed by our team. Temporary or permanent activation is an administrative decision.

Contact sales for pricing, scope and service terms.

Discuss access →

A license enables the installation. API entitlements, roles, supported markets and sandbox restrictions remain those of your approved partner account.

Request onboarding & access

Tell us where you plan to install and what your team needs. Use this form for new installations and renewal requests.

Use a verified MyStocks account to submit and track your organization’s request.

Return to this page after signing in.

Deployment details

These selections accompany your request and tailor your approved installation instructions. Do not enter passwords or credentials.

Your deployment checklist

  • AMD64 Linux host; Docker Engine, Compose plugin and Python 3.
  • Provision trading.example.com; verify its DNS TXT ownership challenge and authorized Firebase sign-in domain.
  • Keep application port 3000 private. Permit DNS and outbound HTTPS to MyStocks, Firebase and the image registry.
  • Use separate registry reader access and an active domain-bound installation key. Never include secrets in this form or email.
  • Allow inbound 80/443 and certificate challenges; Caddy manages TLS.

Download and checksum-verify the installer using the linked guide. Replace the image placeholder with the administrator-approved digest, then enter the key at the hidden prompt.

sudo bash install-onprem.sh --domain trading.example.com --image REGISTRY/IMAGE@sha256:DIGEST --mode docker --proxy caddy --port 3000
curl --fail --show-error https://trading.example.com/api/health
Versioned installer, checksum and detailed guide