How are trader sessions secured?

Quick answer

Trader sessions are scoped to exactly one trading account, which is taken from the signed session token and never from the request. Access tokens last up to 15 minutes and are renewed with a refresh token that rotates on use. Rotating the password, reassigning or archiving the account revokes every session for it.

Detailed answer

The terminal session model is designed for an environment where credentials are handed out by firms and may change hands.

One account per session

Every terminal request reads the account from the verified token. No terminal endpoint accepts an account ID from the client, so a trader cannot reach another account by changing a request.

Token lifetimes

  • Access token: short-lived, up to 15 minutes, verified by signature for speed.
  • Refresh token: stored as a secure cookie on the API's domain, revocable, and replaced on each use.

Revocation

These actions revoke all refresh tokens for an account:

  • Rotating the password.
  • Reassigning or unassigning the account.
  • Archiving it.

An open terminal then loses access when its access token expires, within 15 minutes.

The account switcher

Switching to another account under the same trader email issues a new session for that account only, after confirming both accounts belong to the same trader record in the same firm.

Prefilled login links are removed from the address bar on load and kept out of analytics, but the link itself remains a credential.

PropExecutor team · Updated

All 11 questions in Security, data and reliability · Every category