CPlugin

MT4 v2 :: Authentication

API v2 (beta) · MT4 · 2 operations · base URL https://cloud.mywebapi.com · OpenAPI v2 (JSON) · Redoc

Every call needs Authorization: Bearer $TOKEN — an OAuth 2.0 client-credentials token from https://auth.cplugin.net/connect/token (scope webapi). $TRADE_PLATFORM_ID is the id of a trade platform registered in Toolbox.

Operations

Verify account password

POST /api/v2/MT4/{tradePlatform}/UserPasswordCheck/{login}

Verify an account password against the MT4 server.

POST body: the candidate password as a JSON string (e.g. "secret123"). Returns envelope with bool payload — true if MT4 server accepts the password, false when wrapper returns InvalidLoginOrPassword (envelope marked as MT4Error with the underlying ResultCode in managerAPICode).

Read-only operation: no state changes. Idempotency-Key on this endpoint is supported but rarely useful — pin if your retry policy expects the same answer across attempts.

Timeout: 15 s by default, adjustable per request with the X-Request-Timeout header. When the trade server does not answer in time: The operation may still be completed by the server (X-Request-Outcome: unknown): check its result before repeating it.

Parameters

NameInTypeRequiredDescription
tradePlatform path string (uuid) yes Trade platform id (GUID)
login path integer (int32) yes Account login (positive integer)
X-Request-Timeout header number (double) no How long to wait for the trade server, in seconds (1–300). Default for this operation: 15 s (change). The query parameter requestTimeout does the same for clients that cannot set headers. The applied value is returned in the X-Request-Timeout-Applied response header.

Request body

string (application/json) — Candidate password (JSON-encoded string body)

Responses

Example

curl -X POST "https://cloud.mywebapi.com/api/v2/MT4/$TRADE_PLATFORM_ID/UserPasswordCheck/$LOGIN" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '""'

Set account password

POST /api/v2/MT4/{tradePlatform}/UserPasswordSet/{login}

Set the account password — Type 1 mutator (direct overwrite).

POST body: the new password as a JSON string. Optional query params: changeInvestor=true sets the read-only investor password instead of the primary one; cleanPubkey=true resets the public key alongside the password (caller's RSA-protected secondary auth).

This is a Type 1 mutator — full-replace semantics. The wrapper accepts the new password directly without a read-modify-write loop. There is no Type 2 ("set only this field, leave the rest alone") variant of password change because the password is itself a single field — the read step would be tautological.

Idempotency-Key is strongly recommended. A retried password change without the header risks setting it twice (the second call returns success even though the password is the same), which is harmless but generates audit noise. With the header, the second call short-circuits to the cached response.

Timeout: 15 s by default, adjustable per request with the X-Request-Timeout header. When the trade server does not answer in time: The operation may still be completed by the server (X-Request-Outcome: unknown): check its result before repeating it.

Parameters

NameInTypeRequiredDescription
tradePlatform path string (uuid) yes Trade platform id (GUID)
login path integer (int32) yes Account login (positive integer)
changeInvestor query boolean no If true, sets the investor (read-only) password instead
cleanPubkey query boolean no If true, also resets the account's public key
X-Request-Timeout header number (double) no How long to wait for the trade server, in seconds (1–300). Default for this operation: 15 s (change). The query parameter requestTimeout does the same for clients that cannot set headers. The applied value is returned in the X-Request-Timeout-Applied response header.

Request body

string (application/json) — New password (JSON-encoded string body)

Responses

Example

curl -X POST "https://cloud.mywebapi.com/api/v2/MT4/$TRADE_PLATFORM_ID/UserPasswordSet/$LOGIN" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '""'

Schemas

Types the operations above take and return, with their first-level properties; * marks a required one. The full graph is in the OpenAPI specification.

BooleanApiResponse

Unified v2 response envelope: data is the payload (null on error); error is the error object (null on success, always serialised); meta contains response metadata (activityId and optional paging). HTTP status is always 200.

PropertyTypeDescription
data boolean
error ApiError v2 error body. Code is the stable transport error code; ManagerCode is the raw MT4 ResultCode (serialized as a string for a known enum member, or as a number for an unrecognised value returned by MT4); Message is a human-readable description.
meta ApiMeta Response metadata. ActivityId is the W3C trace-id for correlation in Seq/SigNoz. Paging is present only on paginated list responses; otherwise it is omitted — the global JSON context policy serialises null fields, so we override that here with System.Text.Json.Serialization.JsonIgnoreCondition.WhenWritingNull.

ApiError

v2 error body. Code is the stable transport error code; ManagerCode is the raw MT4 ResultCode (serialized as a string for a known enum member, or as a number for an unrecognised value returned by MT4); Message is a human-readable description.

PropertyTypeDescription
code WebApiErrorCode Stable transport-level error code.
managerCode ResultCode Raw MT4/MT5 manager result code, when the error came from the trading platform; otherwise null.
message string, nullable Human-readable error description.

ApiMeta

Response metadata. ActivityId is the W3C trace-id for correlation in Seq/SigNoz. Paging is present only on paginated list responses; otherwise it is omitted — the global JSON context policy serialises null fields, so we override that here with System.Text.Json.Serialization.JsonIgnoreCondition.WhenWritingNull.

PropertyTypeDescription
activityId string, nullable W3C trace id for correlating this response in logs and tracing (Seq/SigNoz).
paging PagingMeta Pagination info; present only on list responses, omitted otherwise.