Skip to main content
4casters does not issue API keys today. You authenticate against every 4casters API with the same username and password you use to sign in at 4casters.io. There is nothing to request, generate, or copy from your account settings.Dedicated API keys are on the roadmap. When they ship they will be announced in the changelog and this page will be updated. Until then, your login is the credential.

How it works

  1. Log in with your account’s username (or email) and password via POST /user/login on the REST API.
  2. Receive a token in the response. It is a 256-character hex string.
  3. Send that token on every REST request and every WebSocket handshake. All three APIs accept the same token.
There is no separate signup for API access. If you can log in on the website, you can use the API.

1. Log in

POST https://api.4casters.io/user/login
The username field accepts either your username or the email on the account. The token is at data.user.auth in the response body. The same value is also set as a signed auth cookie; server-side integrations should capture data.user.auth and ignore the cookie.
The full response shape is documented on the REST authentication page.
Log in once and reuse the token. Login is rate-limited per IP and per account, and every successful login mints a new token. Logging in again does not invalidate tokens you already hold.

2. Send the token

Pass the token in the Authorization header. The Bearer prefix is optional.
A missing, unknown, or expired token returns 401 with body { "error": { "message": "InvalidCredentials", "code": 401 } }.

Token lifetime

For a long-running integration, do one of the following:
  • Re-login on any 401. Simplest and robust. Treat 401 as “get a fresh token”, not as a fatal error.
  • Watch for X-Auth-Token. Whenever that header is present on a response, persist its value and use it from then on.
A script that logs in once, stores the token, and never looks at response headers will work for exactly 30 days and then fail with 401 on every request.

Two-factor authentication

Two-factor authentication on 4casters protects withdrawals, not login. Enabling it on your account does not change how you authenticate against the API. POST /user/login never asks for a code.

Login errors

Keeping credentials safe

  • Store the username and password in environment variables or a secrets manager, never in source control.
  • Treat the token like a password. Anyone holding it can place orders and read your account.
  • Consider a dedicated account for automated trading so a leaked bot credential does not expose your main balance. Accounts are opened the same way as any user account.