Skip to main content

Connection details

Required headers

Store the CRM API key only in backend secret storage. Do not include it in repositories, screenshots, browser requests, mobile applications, logs, or analytics tools.
Use HTTPS for every environment. If IP allowlisting is enabled, coordinate the CRM’s outbound addresses before testing. Do not silently switch credentials when a route returns 403; confirm that the endpoint belongs to the customer’s CRM contract.

Secret-bearing responses

Account creation and sensitive information routes may return MT5 passwords. Encrypt only the fields your authorized workflow requires and prevent complete response bodies from reaching application logs.

Previous: Integration model

Return to system ownership and fund separation.

Next: End-to-end workflow

Implement the recommended integration sequence.
Last modified on September 7, 2026