Get a Tradovate API key for Autoview
Autoview's Tradovate form asks for four things: your Tradovate username, a password, a CID, and a Secret. The last two come from an API key you create inside Tradovate. This page shows where to make that key, how to set it up, and where each value goes.
Tradovate only lets some accounts create a key. You need a funded live account and a paid add-on first. The Tradovate API access requirements guide covers who qualifies. This page assumes you already do.
Start on Simulation
Connect Tradovate Simulation before you connect live. Simulation trades practice money, so a typo in an alert costs you nothing. It's free on Autoview.
Use the Tradovate Simulation setup page. The live page is Tradovate setup. Both pages ask for the same four values, and the same key works on both. The key always comes from your live account, even when you only plan to trade Simulation. The Tradovate Sim guide covers the Simulation side in more detail.
Create the key in Tradovate
These steps follow Tradovate's API Access article. Tradovate can change its screens, so trust its page if the two ever differ.
- Sign in to the Tradovate Web Trader with your live account.
- Click Application Settings at the top right of the page.
- Open the API Access tab. If you haven't subscribed to the add-on yet, do that here first.
- Finish Tradovate's self-attestation and sign its digital agreement.
- Click Generate API Key.
- Set the permissions. The next section says which ones.
- If Tradovate offers a dedicated password for the key, set one. More on that below.
- Click Generate.
- Copy the CID and the Secret right away. Tradovate shows the key one time only.
Paste both values into a plain text editor before you copy them into Autoview. That makes a stray space at the start or end easy to spot.
API password or login password?
When you generate a key, Tradovate can ask you to make a dedicated password for it. Tradovate staff describe it as a way to hide your real password. If the key ever leaks, you delete the key and your login stays safe.
If you set one, use it. Once a key has a dedicated password, Tradovate expects that password with the key, not your login password. If you skipped it, use the password you sign in with.
Which permissions to set
Each key has permission sections. Anything marked Denied is closed to apps that use the key. Autoview sends and closes orders, and it reads your balance and positions. Tradovate staff name these sections for an app that trades:
| Section | Set it to | Why Autoview needs it |
|---|---|---|
| Orders | Full Access | Place and cancel orders, brackets included |
| Positions | Full Access | Read open positions and close them |
| Account Information | Read | Find your account and read its cash balance |
| Contract Library | Read | Turn a symbol into the exact contract to trade |
Leave every other section at Denied. Autoview never transfers or withdraws money, so it needs nothing that could move funds. If the dialog shows a section you don't recognize, deny it. You can change permissions later from the same tab with Change Permissions.
IP restrictions
Tradovate's API Access article and its API documentation don't describe an IP allowlist for keys, as of October 6, 2026. So there is nothing to set here. Follow Tradovate's own page if that changes.
If Tradovate adds one later, the addresses Autoview sends orders from are in Are my API keys safe?. Ask support which zone your account runs on before you lock a key to one address.
Which value goes in which field
Step 1 of the Autoview form has four boxes. Fill them like this:
| Autoview field | What to paste |
|---|---|
| Tradovate Username | The username you sign in to Tradovate with |
| Tradovate Password or API Password | The dedicated password you set for the key, or your login password if you didn't set one |
| CID | The CID from the API Access tab (a number) |
| Secret | The Secret Tradovate showed when you generated the key |
Then pick a Zone from the list. It sets where Autoview runs your commands. It isn't a Tradovate value.
The form also warns about Live and Simulation. Make sure you're on the setup page for the environment you mean to trade. Your username and password have to sign in to that same environment.
Want to know how Autoview stores these values? Are my API keys safe? explains it.
Common errors
- Incorrect username or password. Check which password you used. If the key has a dedicated password, your login password won't work, and the reverse is also true. Re-paste through a text editor to drop stray spaces.
- Request rate limited. Tradovate slows down repeated failed sign-ins. Wait out the time it gives. In some cases Tradovate asks you to wait an hour before an app can try again. Fix the password before you retry, or the wait starts over.
- Access is denied when placing an order. Check the key's permissions. Orders and Positions need Full Access. Account Information and Contract Library need at least Read.
- Access denied on your first live order. Tradovate emails you to approve the new device. Approve it, and orders flow after that. Simulation doesn't do this.
- Sign-in fails on one environment but not the other. Check that you're on the right setup page, Simulation or live, and that your username signs in there.
- You lost the Secret. Tradovate won't show it again. Delete the key on the API Access tab, generate a new one, and paste the new CID and Secret.
- The Subscribe button is greyed out. Your account doesn't meet Tradovate's terms yet. See the requirements guide.
Once you're connected, the Connect Tradovate guide walks you through a first test order. The Tradovate command reference lists every order type.