DEVELOPER PLATFORM · API V1

MindAIGold Partner API

One controlled integration for real-time markets, MT5, trading automation, users, referrals and commissions.

REST / JSONWEBSOCKETHMAC-SHA256V1 · 2026-09-10

First request

Send the key in a header. Keys in URLs are rejected. Write operations also require request signing, a one-time nonce and an idempotency key.

cURL
curl -sS \
  'https://mindaigold.com/api/v1/market/quote.php?symbol=XAU_USD' \
  -H 'X-API-Key: mag_live_xxxxxxxxxxxx_your_secret'
Authentication

Use X-API-Key for server-to-server requests. Authorization: Bearer is also accepted for API keys.

Available endpoints

MethodEndpointRequired scopeDescription

Market intelligence and real-time data

GET/api/v1/market/instruments.phpmarket.read

Supported forex, metals, crypto perpetuals and US equities.

GET/api/v1/market/quote.php?symbol=XAU_USDmarket.read

Latest price, bid, ask, upstream timestamp and source.

GET/api/v1/market/candles.php?symbol=XAU_USD&timeframe=15m&limit=200market.read

Ascending OHLCV candles for supported timeframes.

GET/api/v1/market/stream-ticket.php?symbols=BTC-USDT-SWAPmarket.stream

One-time ticket for an approved real-time WebSocket session.

GET/api/v1/signals/latest.php?symbol=XAUUSD&lang=ensignals.read

Published strategy signals with levels, confidence and expiry.

GET/api/v1/news/latest.php?days=7&limit=30news.read

Gold news with AI sentiment and concise summaries.

MT5 accounts, orders and positions

GET/api/v1/trading/accounts.phpmt5.read

Linked MT5 accounts, connection state, balances and margin telemetry.

GET/api/v1/trading/orders.phptrading.read

Orders owned by the linked MindAIGold user.

POST/api/v1/trading/orders.phptrading.write

Validate a paper order or queue an approved live MT5 order.

POST/api/v1/trading/order-cancel.phptrading.write

Cancel a linked order that has not yet been sent to MT5.

GET/api/v1/trading/positions.phpmt5.read

Current open positions reported by the linked MT5 account.

POST/api/v1/trading/position-control.phptrading.write

Queue a close or stop-loss / take-profit modification.

GET/api/v1/trading/deals.phpmt5.read

Filled MT5 deal history, including profit, commission and swap.

Automated trading

GET/api/v1/automation/status.phpautomation.read

Strategies, activations, linked accounts and automated positions.

POST/api/v1/automation/activate.phpautomation.write

Activate a strategy in paper mode or separately approved live mode.

POST/api/v1/automation/control.phpautomation.write

Pause, resume or stop an owned automation activation.

Users, referrals and commissions

GET/api/v1/partners/profile.phpusers.read

Linked partner user profile; contact details are masked by default.

GET/api/v1/referrals/users.php?depth=1referrals.read

Approved levels of the linked agent referral tree.

GET/api/v1/referrals/commissions.phpcommissions.read

Commission records and total rebates for the linked agent.

GET/api/v1/account/usage.phpaccount.read

Your own monthly quota and 30-day usage history.

Real-time WebSocket market data

Request a short-lived, one-time ticket with market.stream, then connect to the returned WebSocket URL within 60 seconds. Sessions are read-only and limited by the partner plan.

JAVASCRIPT
const ticket = await fetch(
  'https://mindaigold.com/api/v1/market/stream-ticket.php?symbols=BTC-USDT-SWAP',
  { headers: { 'X-API-Key': process.env.MINDAIGOLD_API_KEY } }
).then(response => response.json());

const socket = new WebSocket(ticket.data.websocket_url);
socket.onmessage = event => console.log(JSON.parse(event.data));
Market-data rights are enforced

Approved crypto streaming is available. Forex and metals streaming remains locked until upstream redistribution rights are recorded for the partner service.

Signed write operations

Trading and automation writes are server-to-server only. Sign the exact raw JSON body and never reuse a nonce. Keep one Idempotency-Key for every logical operation and its retries.

CANONICAL REQUEST
timestamp + "\n" + nonce + "\n" +
method.toUpperCase() + "\n" + requestPath + "\n" +
sha256(rawJsonBody)

X-MAG-Signature = HMAC-SHA256(apiKey, canonicalRequest)
X-MAG-TimestampCurrent Unix time in seconds, within the configured signature window.
X-MAG-NonceA unique 16-80 character value for every request attempt.
Idempotency-KeyA stable 16-100 character value reused only when retrying the same logical operation.
Live does not bypass platform controls

A live key still requires an active linked user, approved partner, fixed client IP, live-trading approval and every existing MT5, quote freshness, risk and global pause check. Test keys and paper-approved partners never dispatch live orders.

Limits and evidence

Every response includes a request ID. Rate and monthly quota headers let your integration slow down before it is rejected.

X-RateLimit-LimitPer-minute limit
X-Monthly-Quota-RemainingMonthly quota
X-Request-IDRequest log

Stable error contract

Errors always return a machine-readable code, a message and the same request ID carried in the response header.

CodeHTTPMeaning
missing_api_key / invalid_api_key401

Missing, invalid, revoked or expired credential.

insufficient_scope403

The key does not include the endpoint scope.

origin_denied / ip_denied403

The browser origin or client IP is not allowlisted.

rate_limit_exceeded429

Per-minute rate limit reached.

monthly_quota_exceeded429

Partner monthly quota reached.

signature_required / invalid_signature401

Required signed-write headers are missing or do not match the request.

replayed_request / idempotency_conflict409

A nonce was reused or an idempotency key was reused with different content.

live_trading_paused409

The platform-wide live MT5 dispatch control is paused.

JSON
{
  "error": {
    "code": "insufficient_scope",
    "message": "This key does not have the required scope: signals.read"
  },
  "meta": { "request_id": "0f1e2d3c4b5a69788796a5b4" }
}

Production onboarding

Access is enabled after partner identity, use case and traffic controls are reviewed.

  1. 01Create a partner workspace and link the responsible account.
  2. 02Approve scopes, stream class, trading mode, referral depth, fixed IP or browser origins, and quotas.
  3. 03Issue the secret once, complete paper and signature tests, then approve only the production capabilities required.
Start a partnership review
Copy example