Replace an account's password
Gives a connected account a new trading password — after the member changed it at the broker, or when the account is in invalid_credentials because the one it had was wrong. Send server as well to correct the server name.
The account is taken offline first (refused with 409 while an order is in flight), the new password is encrypted and stored, and only then is the old one erased — a failure leaves the old credential in place. The account lands in created and comes online on the next order or when you bring it online; bring it online straight away to check the new password while the member is still there. The password is never returned or logged.
Authorization
apiKey Authorization: Bearer fx_live_<id>_<secret>.
A key is shown once, at creation. We cannot show it again or recover it for you.
Keys carry a label (live or test) in the key itself, so each configuration is easy to tell
apart. Both reach real brokers: test with a broker demo account.
Scopes are per key. A key without accounts:write can read accounts and nothing else.
In: header
Path Parameters
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/accounts/497f6eca-6276-4993-bfeb-53cbbbba6f08/password" \ -H "Content-Type: application/json" \ -d '{ "password": "the-members-new-trading-password" }'{ "data": { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "label": null, "login": "string", "server": "string", "mode": "always_on", "state": "created", "stateDetail": null, "stateChangedAt": "2019-08-24T14:15:22Z", "currency": null, "leverage": null, "marginMode": null, "tradeAllowed": null, "brokerName": null, "tradingDisabled": true, "createdAt": "2019-08-24T14:15:22Z" }}Poll lifecycle state GET
The endpoint to poll after bringing an account online. Cheap enough to call every second or two; `state` reaches `ready` when the account is logged in and ready to trade.
Bring an account online POST
Starts connecting the account and returns **202** immediately — the broker login is still in progress. Poll `pollUrl` until `state` is `ready`. Calling this for an account that is already online is harmless and returns `alreadyRunning: true`, so a client that is unsure can simply call it. Returns 409 when the account needs a human first (a wrong password, 2FA, a certificate, trading disabled at the broker). Retrying will not fix those, and repeated failed logins are how a broker locks an account.