MT5 Investor Password vs Trading Password: Which Does Your App Need?
The investor password can only watch an MT5 account; the trading password can trade it. Which one your app needs, why the wrong one fails late, and how to ask.
In short
- Every MT5 account has two passwords. The investor password is read-only; the trading (master) password can also place and close trades.
- An app that places trades needs the trading password. With the investor password the login succeeds and every order is rejected.
- Because the login succeeds, the mistake shows up late — at the first trade — unless your connect screen names the right password.
- Asking for the trading password is a responsibility. It should pass through your backend once and be kept only, encrypted, by the service that uses it.
On this page
An app that places trades needs the trading password. The investor password lets software look at an account, not trade it. The trouble is that nothing fails when you connect with the wrong one — it fails at the first order.
Two passwords, two permissions
| Aspect | Investor password | Trading (master) password |
|---|---|---|
| Log in | Yes | Yes |
| See balance, positions, history | Yes | Yes |
| Place, modify and close trades | No | Yes |
| Change the account's passwords | No | Yes |
| Usual use | Letting someone watch an account | Trading it, yourself or through software |
MetaTrader calls the full-access password the master password. Brokers and apps often say trading password. They are the same thing.
Which one your app needs
- It places or closes trades — a signal app, a copier, a trading bot, a prop-firm tool that can close positions: the trading password.
- It only reads — a dashboard, a performance tracker: the investor password is enough, if the tool you use connects with it.
fxapis is built to trade, so it asks for the trading password.
Why the wrong password fails late
With the investor password, the broker accepts the login. The account comes online, looks healthy, and shows its positions. Then the first order is refused, because the login has no trading rights.
With fxapis, such an account reaches ready and its orders come back rejected by the broker. The fix is to replace the password on the existing account with POST /v1/accounts/{id}/password — its id and history stay — and bring it online again.
How to ask for the right one
Most failures here are a labelling problem. On your connect screen:
- Name it. "MT5 trading password (not the investor password)" in the field label.
- Say why. "We need it to place trades on your behalf. The investor password can only view."
- Say what happens to it. Users are right to hesitate before handing over a password that can trade their money.
- Check at once. Bring the account online while the user is still on the screen, and show the result.
Handling a trading password responsibly
A trading password can move someone's money, so treat it that way:
- The form posts to your backend, which sends it to fxapis in the same request. Your API key never goes near a browser.
- Do not store it, log it, queue it or send it to analytics. Keep the fxapis account
idinstead. - Disconnect accounts when users leave. fxapis erases the stored password at once and keeps the trading history.
On fxapis's side, each password is encrypted on arrival with a key unique to that account, never returned by any endpoint, used only to log the account in — with every use audited — and erased on disconnect. See security.
Next steps
- Connect MT5 accounts — handling credentials in your app, step by step.
- API key vs broker login — every credential an integration uses, and where each one lives.