MetaApi Cloud Token
Description
General
- Documentation: https://metaapi.cloud/docs/client/restApi/auth/
- Summary: MetaApi is a cloud API that connects applications to MetaTrader 4 and MetaTrader 5
trading accounts. A MetaApi token authenticates every REST and WebSocket call through
the
auth-tokenheader, and carries the access rules granted to the user.
An admin token grants access to every MetaApi application the account can reach: reading and updating trading accounts, placing and closing trades, streaming market data, trade-copying through CopyFactory, MetaStats analytics and the billing API. Tokens can be narrowed down to a subset of applications, roles or trading accounts, but a leaked unrestricted token lets an attacker trade on the victim's brokerage accounts and exfiltrate their positions and history.
Revoke the secret
Sign in to https://app.metaapi.cloud, open the API access section (https://app.metaapi.cloud/api-access/generate-token) and delete the compromised token. Tokens narrowed down from an admin token stay valid only as long as their own validity period, so the admin token they derive from must be revoked too.
Details for MetaApi Cloud Token
-
Family: token
-
Category: other
-
Company: MetaApi
-
High recall: False
-
Validity check available: True
-
Analyzer available: False
-
Revoker available: False
-
On-premise instances exist: False
-
Only valid secrets raise an alert: False
-
Occurrences found for one million commits: 0.075
-
Prefixed: False