Reference · broker APIs

Broker API comparison: limits, sign-in and test accounts

The practical facts that shape a trading system on twelve broker and exchange APIs we have built on, taken from each one’s own documentation. Checked on 7 October 2026, client libraries on 8 October 2026. Brokers change these, so follow the docs link before you build.

Broker or exchangeHow you connectSign-inTest accountPublished limitsClient librariesWorth knowing
Interactive Brokers (TWS API)official docs ↗Socket API to a running TWS or IB GatewayTWS or IB Gateway must be running and logged inPaper trading accountUp to 50 messages per second from the clientOfficial: Python, Java, C++, C#, VBTWS and IB Gateway restart daily; a Client Portal Web API and FIX also exist
Charles Schwab (Trader API)official docs ↗REST, with streaming quotesOAuth 2: the account holder authorises the app; refresh tokens renew access, and a full re-authorisation is needed periodicallyNot stated in public docsNot published publiclyNot stated in public docsReplaced the retired TD Ameritrade API
Alpacaofficial docs ↗REST and WebSocket streamingAPI key ID and secret (OAuth for apps used by others)Paper trading environmentTrading API: 200 requests per minute per accountOfficial: Python, .NET (C#), Node.js, Go, JavaStocks, ETFs, options and crypto
Tradierofficial docs ↗REST and streamingAccess tokenSandboxProduction: 120 per minute for account and market data calls, 60 per minute for trading. Sandbox: 60 per minute. Per access tokenNone listed in the docs; REST from any languageRemaining quota is returned in response headers
TradeStation (API v3)official docs ↗REST and HTTP streamingOAuth 2SIM environment with simulated accounts and fillsQuotas per resource, mostly per 5 minutes (for example 250 for accounts, orders and positions; 30 per minute for quote snapshots)None listed in the docs; REST from any languageConcurrent-stream limits on streaming endpoints
Tastytradeofficial docs ↗REST, account streamer and DXLink market data streamsOAuth 2; access tokens last 15 minutes; personal apps need no third-party reviewSandbox with simulated moneyREST: no published quota (too many requests get a 429 error). Market data: 5 concurrent sessionsNone listed on the developer site; REST from any languageSandbox and production credentials are separate
OANDA (v20)official docs ↗REST and streamingSee docsfxTrade Practice account100 requests per second on an established connection; 2 new connections per secondOfficial v20 bindings: Python, Java, JavaScriptReuse connections to stay within the limit
Zerodha (Kite Connect)official docs ↗REST and WebSocketDaily login: request token exchanged for an access token that expires at 6 AM the next dayNot stated in the docsOrders: 10 per second, 400 per minute, 5,000 per day; quotes 1 per second; historical 3 per second; 25 modifications per orderOfficial: Python, Java, Go, .NET (C#), TypeScriptSEBI retail algo rules apply (static IP, algo tagging)
Angel One (SmartAPI)official docs ↗REST, WebSocket prices and order statusSession login (see docs)Not stated in the docsPlace, modify, cancel: 20 per second, 500 per minute, 1,000 per hour; prices 10 per second; historical 3 per second; login 1 per secondCode samples in the docs: Python, Node.js, Java, R, GoSEBI retail algo rules apply (static IP, algo tagging)
Dhan (DhanHQ v2)official docs ↗RESTAccess token valid for 24 hoursNot stated in the docsOrders: 10 per second, 250 per minute, 1,000 per hour, 7,000 per day; data 5 per second, 100,000 per day; quotes 1 per second; 25 modifications per orderOfficial: PythonSEBI retail algo rules apply (static IP, algo tagging)
Binance (Spot)official docs ↗REST, WebSocket API and market streamsAPI key with signed requestsSpot TestnetWeighted request limits per IP and unfilled-order limits per account; current values from the exchangeInfo endpointOfficial connectors: Python, Java, Node.js, TypeScript, Go, Rust, .NET (C#), PHP, RubyRepeatedly ignoring 429 responses leads to automated IP bans
Coinbase (Advanced Trade)official docs ↗REST and WebSocketCDP API key; a signed JWT on each private requestNot stated in the docsPrivate endpoints: 30 requests per second per user; public: 10 per second per IPOfficial: Python; sample SDKs in TypeScript, Go, JavaKey permissions (view, trade, transfer) set per key

On a phone, scroll the table sideways.

How to read the limits

Brokers count differently. Some limit requests per second, others per minute or per five minutes; some count per account or per access token, others per IP address; Binance weights each request by how much work it costs. The useful question is not which number is biggest but whether your system’s busiest moment fits inside it. A system that streams prices instead of polling for them, and sends orders only when its rules fire, rarely gets close.

Where a limit is reached, every broker here answers with an error rather than a delay, and a well-built system backs off and retries without sending the same order twice. Our guide to the edge cases of live trading systems covers how. For terms like rate limit and pacing, see the glossary.

Indian brokers and SEBI’s rules

Zerodha, Angel One and Dhan also apply SEBI’s framework for retail algorithmic trading: API access through a unique key and a whitelisted static IP, and tagging or registration of algo orders depending on how fast they are sent. Our guide to SEBI’s retail algo rules explains what that means for a bot, and our Indian broker API comparison adds Upstox.

Where this comes from

Each row comes from the broker’s own documentation or official announcement, linked as “official docs”. Where the public documentation does not state something, the cell says so instead of guessing. We re-check the table every quarter. This is technical reference, not a recommendation of any broker, and not investment advice.

Common questions

Which broker API has the highest rate limits?
Limits are measured differently by each broker, so they are hard to compare directly: per second, per minute, per five minutes, by IP or by account. For most strategies that trade a handful of orders a minute, every broker in this table is fast enough. Limits start to matter for systems that poll for data instead of streaming it, or that place many orders in a burst.
Do Indian broker APIs need a static IP?
Under SEBI’s framework for retail algorithmic trading, brokers allow API access only through a unique API key and a static IP they have whitelisted. Our plain-English guide to the rules explains what that means for a bot.
Which brokers offer a paper trading account for API testing?
In this table: Interactive Brokers, Alpaca, Tradier (sandbox), TradeStation (SIM), Tastytrade (sandbox), OANDA (practice account) and Binance (Spot Testnet). Where a broker’s public documentation does not mention one, the table says so.
start here

Building on one of these APIs?

Send us your strategy, your broker and how you want it to run. We reply with our questions, then a fixed quote.

Send us your brief

A few lines is enough to start: your rules in plain words, or a link to your script. We'll ask for the rest.