# 1. OAuth Client Credentials → Bearer JWT
$body = @{
grant_type = 'client_credentials'
scope = 'webapi'
client_id = $env:CPLUGIN_CLIENT_ID
client_secret = $env:CPLUGIN_CLIENT_SECRET
}
$token = (Invoke-RestMethod -Method Post -Uri 'https://auth.cplugin.net/connect/token' -Body $body).access_token
# 2. List your trade platforms
Invoke-RestMethod -Headers @{ Authorization = "Bearer $token" } `
-Uri 'https://cloud.mywebapi.com/api/TradePlatforms'
# 3. Ping one of them
Invoke-RestMethod -Headers @{ Authorization = "Bearer $token" } `
-Uri "https://cloud.mywebapi.com/api/TradePlatforms/$ID/Ping"
# 1. OAuth Client Credentials → Bearer JWT
TOKEN=$(curl -s -X POST https://auth.cplugin.net/connect/token \
-d 'grant_type=client_credentials&scope=webapi' \
-d "client_id=$CPLUGIN_CLIENT_ID" \
-d "client_secret=$CPLUGIN_CLIENT_SECRET" \
| jq -r .access_token)
# 2. List your trade platforms
curl -H "Authorization: Bearer $TOKEN" \
https://cloud.mywebapi.com/api/TradePlatforms
# 3. Ping one of them
curl -H "Authorization: Bearer $TOKEN" \
https://cloud.mywebapi.com/api/TradePlatforms/$ID/Ping
# 1. OAuth Client Credentials → Bearer JWT
TOKEN=$(curl -s -X POST https://auth.cplugin.net/connect/token \
-d 'grant_type=client_credentials&scope=webapi' \
-d "client_id=$CPLUGIN_CLIENT_ID" \
-d "client_secret=$CPLUGIN_CLIENT_SECRET" \
| jq -r .access_token)
# 2. List your trade platforms
curl -H "Authorization: Bearer $TOKEN" \
https://cloud.mywebapi.com/api/TradePlatforms
# 3. Ping one of them
curl -H "Authorization: Bearer $TOKEN" \
https://cloud.mywebapi.com/api/TradePlatforms/$ID/Ping
Two API versions, one reference each
Full MT4 / MT5 ManagerAPI surface — Organizations, TradePlatforms, MT4ManagerAPI, MT5ManagerAPI. Both versions run side by side on the same hosts, with the same token; the same references apply to Production and Sandbox.
API v1
stableThe complete surface most integrations run on today. Paths /api/MT4/…, /api/MT5/…, hubs /hubs/mt4/v1, /hubs/mt5/v1.
API v2
betaVersion in the path, faster JSON, SDKs for TypeScript, .NET, PowerShell and Python. Paths /api/v2/…, hubs /hubs/mt4/v2, /hubs/mt5/v2.
Guides — authentication, timeouts, idempotency, realtime: cplugin.com/docs/webapi ↗ · What is new in v2
HTML API reference — every operation with parameters, schemas and curl examples · OpenAPI JSON: v1, v2 · llms.txt
Swagger UI remains available, deprecated and slated for removal. · Test methods (no auth) ↗
Meet the v2 API
A faster, cleaner endpoint surface, live in production and in the Sandbox. v2 puts the version in the path — call
/api/v2/…
directly, no query string — and serves responses through a zero-reflection JSON pipeline. v1 stays
stable and fully supported; migrate at your own pace.
Call /api/v2/… directly — no api-version query parameter to remember.
Source-generated serialization, zero runtime reflection — lower latency and allocations per response.
Hub /hubs/mt4/v2 streams ticks, margins and trade events.
import { CPluginWebApiClient } from '@mywebapi.com/sdk';
const client = new CPluginWebApiClient({
env: 'prod', // or 'staging' for the Sandbox
clientId: process.env.CPLUGIN_WEBAPI_CLIENT_ID,
clientSecret: process.env.CPLUGIN_WEBAPI_CLIENT_SECRET,
});
const time = await client.mt4.getServerTime(tradePlatformId);
using CPlugin.SaaSWebApi.Client;
using var client = new CPluginWebApiClient(CPluginEnvironment.Prod, clientId, clientSecret);
var mt4 = client.MT4(tradePlatformId);
var time = await mt4.ServerTimeAsync();
$session = Connect-MyWebApi -Environment Production `
-ClientId $env:CPLUGIN_WEBAPI_CLIENT_ID -ClientSecret $secret
Get-MT4ServerTime -Connection $session -TradePlatform $tradePlatformId
from cplugin_webapi_sdk import CPluginWebApiClient
with CPluginWebApiClient(env="prod", client_id=client_id, client_secret=client_secret) as client:
time = client.mt4.get_server_time(trade_platform_id)
Two environments, one API
Same surface, same OAuth flow, just different hosts. Sandbox is fully separated — no billing, no SLA, safe to break.
- REST cloud.mywebapi.com
- Auth auth.cplugin.net
- Hub /hubs/mt4/v1 · /hubs/mt4/v2 (mt5 alike)
- Manage toolbox.cplugin.com
Multi-region cloud (m3 / m4 / m9), DNS traffic manager routes to the nearest instance. Your pricing in Toolbox ↗
- REST pre.mywebapi.com
- Auth pre.auth.cplugin.net
- Hub /hubs/mt4/v1 · /hubs/mt4/v2 (mt5 alike)
- Manage pre.toolbox.cplugin.com
Fully separated environment with its own Toolbox for client and MT4 / MT5 connection management. No charges, no SLA, may be reset without notice. Use for integration testing before pointing at Production.
Realtime over SignalR
Hubs /hubs/mt4/v1, /hubs/mt5/v1 for API v1 and /hubs/mt4/v2, /hubs/mt5/v2 for API v2. Subscribe to ticks, margins, trade events. WebSockets / Long Polling / SSE — same code path. Auto-reconnect, bearer auth, typed contracts.
Working examples
Full source for download. Plug in your credentials, run, ship.
Questions about the MT4 / MT5 API
What is CPlugin WebAPI?
A hosted REST JSON API over the MT4 and MT5 Manager API. Your application manages accounts, trades, groups and symbols on MetaTrader 4 and 5 servers from any language that speaks HTTP, and receives quotes, margin and trade events in realtime over SignalR.
Do I need to install anything on my MT4 or MT5 server?
No. WebAPI connects to your trade server with a regular manager account, the same way the MetaTrader Manager terminal does. You register the server address and the manager credentials once in Toolbox; no server plugin is required.
How do I authenticate?
With OAuth 2.0 client credentials: exchange your client id and secret at auth.cplugin.net for a bearer token and send it in the Authorization header. The SDKs discover, cache and refresh the token for you. Realtime connections pass the same token in the signalr_token query parameter.
Is there a free sandbox?
Yes. The Sandbox at pre.mywebapi.com has the same API surface and OAuth flow as Production, with its own Toolbox at pre.toolbox.cplugin.com. It is free and has no SLA, and it may be reset without notice, so use it for integration testing.
How do I receive realtime quotes and trade events?
Connect to the SignalR hubs /hubs/mt4/v2 and /hubs/mt5/v2 (or /hubs/mt4/v1 and /hubs/mt5/v1 for API v1) and subscribe to ticks, margins and trade events. SignalR uses WebSockets and falls back to Server-Sent Events or long polling, with the same client code.
What happens if the trading platform does not answer in time?
Every trade-platform request has a deadline, which you can set per request with the X-Request-Timeout header (1 to 300 seconds). A read that timed out changed nothing and is safe to repeat. A trade that timed out may still be completed by the platform: you get OutcomeUnknown, and repeating it with the same Idempotency-Key returns its real result without executing it twice.
Which SDKs are available?
Open-source SDKs for TypeScript (npm @mywebapi.com/sdk), .NET (NuGet MyWebApi.Sdk), PowerShell (module MyWebApi) and Python (pip mywebapi-sdk). Any other language works over plain HTTP, using the OpenAPI references.
Should I use API v1 or v2?
v1 is stable and is what most integrations run on today. v2 is in beta: the version is in the path, responses are faster, and the SDKs are built on it. For MT4, v2 is the larger surface: 147 operations against 42 in v1. For MT5, v2 has 12 operations against 55 in v1 — reads, positions, orders and deals by group, and partial updates (PATCH) of user, group and symbol records; dealing, balance operations and account creation are v1-only, so full MT5 integrations stay on v1. Both run side by side on the same hosts with the same token, so you can migrate one call at a time.
How is WebAPI priced?
The Sandbox is free. Production is billed by usage; your current rates are shown on the pricing page in Toolbox.