Broker API comparison: limits, sign-in and test accounts
The practical facts that shape a trading system on twelve broker and exchange APIs we have built on, taken from each one’s own documentation. Checked on 7 October 2026, client libraries on 8 October 2026. Brokers change these, so follow the docs link before you build.
| Broker or exchange | How you connect | Sign-in | Test account | Published limits | Client libraries | Worth knowing |
|---|---|---|---|---|---|---|
| Interactive Brokers (TWS API)official docs ↗ | Socket API to a running TWS or IB Gateway | TWS or IB Gateway must be running and logged in | Paper trading account | Up to 50 messages per second from the client | Official: Python, Java, C++, C#, VB | TWS and IB Gateway restart daily; a Client Portal Web API and FIX also exist |
| Charles Schwab (Trader API)official docs ↗ | REST, with streaming quotes | OAuth 2: the account holder authorises the app; refresh tokens renew access, and a full re-authorisation is needed periodically | Not stated in public docs | Not published publicly | Not stated in public docs | Replaced the retired TD Ameritrade API |
| Alpacaofficial docs ↗ | REST and WebSocket streaming | API key ID and secret (OAuth for apps used by others) | Paper trading environment | Trading API: 200 requests per minute per account | Official: Python, .NET (C#), Node.js, Go, Java | Stocks, ETFs, options and crypto |
| Tradierofficial docs ↗ | REST and streaming | Access token | Sandbox | Production: 120 per minute for account and market data calls, 60 per minute for trading. Sandbox: 60 per minute. Per access token | None listed in the docs; REST from any language | Remaining quota is returned in response headers |
| TradeStation (API v3)official docs ↗ | REST and HTTP streaming | OAuth 2 | SIM environment with simulated accounts and fills | Quotas per resource, mostly per 5 minutes (for example 250 for accounts, orders and positions; 30 per minute for quote snapshots) | None listed in the docs; REST from any language | Concurrent-stream limits on streaming endpoints |
| Tastytradeofficial docs ↗ | REST, account streamer and DXLink market data streams | OAuth 2; access tokens last 15 minutes; personal apps need no third-party review | Sandbox with simulated money | REST: no published quota (too many requests get a 429 error). Market data: 5 concurrent sessions | None listed on the developer site; REST from any language | Sandbox and production credentials are separate |
| OANDA (v20)official docs ↗ | REST and streaming | See docs | fxTrade Practice account | 100 requests per second on an established connection; 2 new connections per second | Official v20 bindings: Python, Java, JavaScript | Reuse connections to stay within the limit |
| Zerodha (Kite Connect)official docs ↗ | REST and WebSocket | Daily login: request token exchanged for an access token that expires at 6 AM the next day | Not stated in the docs | Orders: 10 per second, 400 per minute, 5,000 per day; quotes 1 per second; historical 3 per second; 25 modifications per order | Official: Python, Java, Go, .NET (C#), TypeScript | SEBI retail algo rules apply (static IP, algo tagging) |
| Angel One (SmartAPI)official docs ↗ | REST, WebSocket prices and order status | Session login (see docs) | Not stated in the docs | Place, modify, cancel: 20 per second, 500 per minute, 1,000 per hour; prices 10 per second; historical 3 per second; login 1 per second | Code samples in the docs: Python, Node.js, Java, R, Go | SEBI retail algo rules apply (static IP, algo tagging) |
| Dhan (DhanHQ v2)official docs ↗ | REST | Access token valid for 24 hours | Not stated in the docs | Orders: 10 per second, 250 per minute, 1,000 per hour, 7,000 per day; data 5 per second, 100,000 per day; quotes 1 per second; 25 modifications per order | Official: Python | SEBI retail algo rules apply (static IP, algo tagging) |
| Binance (Spot)official docs ↗ | REST, WebSocket API and market streams | API key with signed requests | Spot Testnet | Weighted request limits per IP and unfilled-order limits per account; current values from the exchangeInfo endpoint | Official connectors: Python, Java, Node.js, TypeScript, Go, Rust, .NET (C#), PHP, Ruby | Repeatedly ignoring 429 responses leads to automated IP bans |
| Coinbase (Advanced Trade)official docs ↗ | REST and WebSocket | CDP API key; a signed JWT on each private request | Not stated in the docs | Private endpoints: 30 requests per second per user; public: 10 per second per IP | Official: Python; sample SDKs in TypeScript, Go, Java | Key permissions (view, trade, transfer) set per key |
On a phone, scroll the table sideways.
How to read the limits
Brokers count differently. Some limit requests per second, others per minute or per five minutes; some count per account or per access token, others per IP address; Binance weights each request by how much work it costs. The useful question is not which number is biggest but whether your system’s busiest moment fits inside it. A system that streams prices instead of polling for them, and sends orders only when its rules fire, rarely gets close.
Where a limit is reached, every broker here answers with an error rather than a delay, and a well-built system backs off and retries without sending the same order twice. Our guide to the edge cases of live trading systems covers how. For terms like rate limit and pacing, see the glossary.
Indian brokers and SEBI’s rules
Zerodha, Angel One and Dhan also apply SEBI’s framework for retail algorithmic trading: API access through a unique key and a whitelisted static IP, and tagging or registration of algo orders depending on how fast they are sent. Our guide to SEBI’s retail algo rules explains what that means for a bot, and our Indian broker API comparison adds Upstox.
Where this comes from
Each row comes from the broker’s own documentation or official announcement, linked as “official docs”. Where the public documentation does not state something, the cell says so instead of guessing. We re-check the table every quarter. This is technical reference, not a recommendation of any broker, and not investment advice.
Common questions
- Which broker API has the highest rate limits?
- Limits are measured differently by each broker, so they are hard to compare directly: per second, per minute, per five minutes, by IP or by account. For most strategies that trade a handful of orders a minute, every broker in this table is fast enough. Limits start to matter for systems that poll for data instead of streaming it, or that place many orders in a burst.
- Do Indian broker APIs need a static IP?
- Under SEBI’s framework for retail algorithmic trading, brokers allow API access only through a unique API key and a static IP they have whitelisted. Our plain-English guide to the rules explains what that means for a bot.
- Which brokers offer a paper trading account for API testing?
- In this table: Interactive Brokers, Alpaca, Tradier (sandbox), TradeStation (SIM), Tastytrade (sandbox), OANDA (practice account) and Binance (Spot Testnet). Where a broker’s public documentation does not mention one, the table says so.