How it works
- Log in with your account’s username (or email) and password via
POST /user/loginon the REST API. - Receive a token in the response. It is a 256-character hex string.
- Send that token on every REST request and every WebSocket handshake. All three APIs accept the same token.
1. Log in
POST https://api.4casters.io/user/login
username field accepts either your username or the email on the account.
The token is at data.user.auth in the response body. The same value is also set as a signed auth cookie; server-side integrations should capture data.user.auth and ignore the cookie.
2. Send the token
- REST API
- Orders WebSocket
- Streaming WebSocket
Pass the token in the A missing, unknown, or expired token returns
Authorization header. The Bearer prefix is optional.401 with body { "error": { "message": "InvalidCredentials", "code": 401 } }.Token lifetime
For a long-running integration, do one of the following:
- Re-login on any
401. Simplest and robust. Treat401as “get a fresh token”, not as a fatal error. - Watch for
X-Auth-Token. Whenever that header is present on a response, persist its value and use it from then on.
401 on every request.
Two-factor authentication
Two-factor authentication on 4casters protects withdrawals, not login. Enabling it on your account does not change how you authenticate against the API.POST /user/login never asks for a code.
Login errors
Keeping credentials safe
- Store the username and password in environment variables or a secrets manager, never in source control.
- Treat the token like a password. Anyone holding it can place orders and read your account.
- Consider a dedicated account for automated trading so a leaked bot credential does not expose your main balance. Accounts are opened the same way as any user account.