# Executor credentials

> Read and rotate the Account Number / Server / Password a trader signs into the terminal with.

Source: https://www.propexecutor.com/docs/credentials
Whole reference in one file: https://www.propexecutor.com/doc.md

Executor credentials are the three fields a trading terminal asks for: **Account Number**, **Server** and **Password**. You hand them to whichever trader currently holds the account.

| Field | What it is | Changes? |
| --- | --- | --- |
| Account Number | The account's 8-digit number. | Never. |
| Server | Your firm's server name — your organization's slug. | Never, once you have provisioned an account. |
| Password | Generated per account. | Whenever you rotate it. |

## Read credentials

`GET /v1/accounts/{account}/credentials` · **Available** · scope `credentials:read`

<!-- 200 OK -->
```json
{
  "account_number": 10000042,
  "server": "apex-prop",
  "password": "K7MNPQ4RSTUVWXYZ",
  "rotated_at": null
}
```

> **This is a working login**
> Anyone holding these three fields can trade that account. The scope is separate from `accounts:read` for exactly this reason — do not put it on a key that only draws charts, and never send a password to a browser.

## Rotate the password

`POST /v1/accounts/{account}/credentials/rotate` · **Available** · scope `credentials:read`

Generates a new password, returns it, and **ends every live session** on the account. Use it when an account changes hands or a password has been shared somewhere it should not have been.

- Already-issued access tokens stay valid for up to 15 minutes; the sessions behind them are killed at once, so nothing survives past that window.
- The old password stops working immediately. Tell the trader before you rotate, or they will simply find themselves logged out.
