# MT5 Investor Password vs Trading Password: Which Does Your App Need?

> The investor password can only watch an MT5 account; the trading password can trade it. Which one your app needs, why the wrong one fails late, and how to ask.

Published 2026-10-10 by fxapis. Canonical: https://fxapis.com/blog/mt5-investor-password-vs-trading-password

## In short

- Every MT5 account has two passwords. The investor password is read-only; the trading (master) password can also place and close trades.
- An app that places trades needs the trading password. With the investor password the login succeeds and every order is rejected.
- Because the login succeeds, the mistake shows up late — at the first trade — unless your connect screen names the right password.
- Asking for the trading password is a responsibility. It should pass through your backend once and be kept only, encrypted, by the service that uses it.

**An app that places trades needs the trading password.** The investor password lets software look at an account, not trade it. The trouble is that nothing fails when you connect with the wrong one — it fails at the first order.

## Two passwords, two permissions

| | Investor password | Trading (master) password |
|---|---|---|
| Log in | Yes | Yes |
| See balance, positions, history | Yes | Yes |
| Place, modify and close trades | No | Yes |
| Change the account's passwords | No | Yes |
| Usual use | Letting someone watch an account | Trading it, yourself or through software |

MetaTrader calls the full-access password the **master** password. Brokers and apps often say **trading** password. They are the same thing.

## Which one your app needs

- **It places or closes trades** — a signal app, a copier, a trading bot, a prop-firm tool that can close positions: the **trading** password.
- **It only reads** — a dashboard, a performance tracker: the investor password is enough, if the tool you use connects with it.

fxapis is built to trade, so it asks for the trading password.

## Why the wrong password fails late

With the investor password, the broker accepts the login. The account comes online, looks healthy, and shows its positions. Then the first order is refused, because the login has no trading rights.

With fxapis, such an account reaches `ready` and its orders come back rejected by the broker. The fix is to replace the password on the existing account with `POST /v1/accounts/{id}/password` — its id and history stay — and bring it online again.

## How to ask for the right one

Most failures here are a labelling problem. On your connect screen:

- **Name it.** "MT5 trading password (not the investor password)" in the field label.
- **Say why.** "We need it to place trades on your behalf. The investor password can only view."
- **Say what happens to it.** Users are right to hesitate before handing over a password that can trade their money.
- **Check at once.** Bring the account online while the user is still on the screen, and show the result.

## Handling a trading password responsibly

A trading password can move someone's money, so treat it that way:

- The form posts to **your backend**, which sends it to fxapis in the same request. Your API key never goes near a browser.
- **Do not store it**, log it, queue it or send it to analytics. Keep the fxapis account `id` instead.
- **Disconnect** accounts when users leave. fxapis erases the stored password at once and keeps the trading history.

On fxapis's side, each password is encrypted on arrival with a key unique to that account, never returned by any endpoint, used only to log the account in — with every use audited — and erased on disconnect. See [security](https://docs.fxapis.com/security).

## Next steps

- [Connect MT5 accounts](https://docs.fxapis.com/guides/connect-accounts) — handling credentials in your app, step by step.
- [API key vs broker login](https://fxapis.com/blog/mt5-api-key-vs-broker-login) — every credential an integration uses, and where each one lives.

## Questions

### What is the MT5 investor password?

A read-only password for a MetaTrader 5 account. It lets someone log in and see positions, history and balance, but not trade. Traders give it out to let others watch an account.

### Is the master password the same as the trading password?

Yes. MetaTrader calls the full-access password the master password; brokers and apps often call it the trading password.

### Can an API trade an MT5 account with the investor password?

No. The investor password does not allow trading. With fxapis the account reaches ready, because the login works, but its orders are rejected by the broker.

### How does fxapis store the trading password?

It is encrypted on arrival with a key unique to that account, never returned by any endpoint, never shown in the console or written to a log, used only to log the account in, and erased when the account is disconnected.
