First request
Send the key in a header. Keys in URLs are rejected. Write operations also require request signing, a one-time nonce and an idempotency key.
curl -sS \
'https://mindaigold.com/api/v1/market/quote.php?symbol=XAU_USD' \
-H 'X-API-Key: mag_live_xxxxxxxxxxxx_your_secret'
Use X-API-Key for server-to-server requests. Authorization: Bearer is also accepted for API keys.
Available endpoints
Market intelligence and real-time data
/api/v1/market/instruments.phpmarket.readSupported forex, metals, crypto perpetuals and US equities.
/api/v1/market/quote.php?symbol=XAU_USDmarket.readLatest price, bid, ask, upstream timestamp and source.
/api/v1/market/candles.php?symbol=XAU_USD&timeframe=15m&limit=200market.readAscending OHLCV candles for supported timeframes.
/api/v1/market/stream-ticket.php?symbols=BTC-USDT-SWAPmarket.streamOne-time ticket for an approved real-time WebSocket session.
/api/v1/signals/latest.php?symbol=XAUUSD&lang=ensignals.readPublished strategy signals with levels, confidence and expiry.
/api/v1/news/latest.php?days=7&limit=30news.readGold news with AI sentiment and concise summaries.
MT5 accounts, orders and positions
/api/v1/trading/accounts.phpmt5.readLinked MT5 accounts, connection state, balances and margin telemetry.
/api/v1/trading/orders.phptrading.readOrders owned by the linked MindAIGold user.
/api/v1/trading/orders.phptrading.writeValidate a paper order or queue an approved live MT5 order.
/api/v1/trading/order-cancel.phptrading.writeCancel a linked order that has not yet been sent to MT5.
/api/v1/trading/positions.phpmt5.readCurrent open positions reported by the linked MT5 account.
/api/v1/trading/position-control.phptrading.writeQueue a close or stop-loss / take-profit modification.
/api/v1/trading/deals.phpmt5.readFilled MT5 deal history, including profit, commission and swap.
Automated trading
/api/v1/automation/status.phpautomation.readStrategies, activations, linked accounts and automated positions.
/api/v1/automation/activate.phpautomation.writeActivate a strategy in paper mode or separately approved live mode.
/api/v1/automation/control.phpautomation.writePause, resume or stop an owned automation activation.
Users, referrals and commissions
/api/v1/partners/profile.phpusers.readLinked partner user profile; contact details are masked by default.
/api/v1/referrals/users.php?depth=1referrals.readApproved levels of the linked agent referral tree.
/api/v1/referrals/commissions.phpcommissions.readCommission records and total rebates for the linked agent.
/api/v1/account/usage.phpaccount.readYour own monthly quota and 30-day usage history.
Real-time WebSocket market data
Request a short-lived, one-time ticket with market.stream, then connect to the returned WebSocket URL within 60 seconds. Sessions are read-only and limited by the partner plan.
const ticket = await fetch(
'https://mindaigold.com/api/v1/market/stream-ticket.php?symbols=BTC-USDT-SWAP',
{ headers: { 'X-API-Key': process.env.MINDAIGOLD_API_KEY } }
).then(response => response.json());
const socket = new WebSocket(ticket.data.websocket_url);
socket.onmessage = event => console.log(JSON.parse(event.data));Approved crypto streaming is available. Forex and metals streaming remains locked until upstream redistribution rights are recorded for the partner service.
Signed write operations
Trading and automation writes are server-to-server only. Sign the exact raw JSON body and never reuse a nonce. Keep one Idempotency-Key for every logical operation and its retries.
timestamp + "\n" + nonce + "\n" +
method.toUpperCase() + "\n" + requestPath + "\n" +
sha256(rawJsonBody)
X-MAG-Signature = HMAC-SHA256(apiKey, canonicalRequest)X-MAG-TimestampCurrent Unix time in seconds, within the configured signature window.X-MAG-NonceA unique 16-80 character value for every request attempt.Idempotency-KeyA stable 16-100 character value reused only when retrying the same logical operation.A live key still requires an active linked user, approved partner, fixed client IP, live-trading approval and every existing MT5, quote freshness, risk and global pause check. Test keys and paper-approved partners never dispatch live orders.
Limits and evidence
Every response includes a request ID. Rate and monthly quota headers let your integration slow down before it is rejected.
X-RateLimit-LimitPer-minute limitX-Monthly-Quota-RemainingMonthly quotaX-Request-IDRequest logStable error contract
Errors always return a machine-readable code, a message and the same request ID carried in the response header.
missing_api_key / invalid_api_key401Missing, invalid, revoked or expired credential.
insufficient_scope403The key does not include the endpoint scope.
origin_denied / ip_denied403The browser origin or client IP is not allowlisted.
rate_limit_exceeded429Per-minute rate limit reached.
monthly_quota_exceeded429Partner monthly quota reached.
signature_required / invalid_signature401Required signed-write headers are missing or do not match the request.
replayed_request / idempotency_conflict409A nonce was reused or an idempotency key was reused with different content.
live_trading_paused409The platform-wide live MT5 dispatch control is paused.
{
"error": {
"code": "insufficient_scope",
"message": "This key does not have the required scope: signals.read"
},
"meta": { "request_id": "0f1e2d3c4b5a69788796a5b4" }
}Production onboarding
Access is enabled after partner identity, use case and traffic controls are reviewed.
- 01Create a partner workspace and link the responsible account.
- 02Approve scopes, stream class, trading mode, referral depth, fixed IP or browser origins, and quotas.
- 03Issue the secret once, complete paper and signature tests, then approve only the production capabilities required.