
Tradovate API Authentication: 6 Steps to Link Multiple Prop Accounts
TradeDupe
16 min read
Link multiple Tradovate prop accounts through OAuth without sharing your password. Check permissions, token renewal, and firm rules before copying trades.
Yes: Tradovate's OAuth connection lets you link multiple prop firm accounts to a copy-trading platform without ever handing over your Tradovate password. Copying runs on an access token instead, and mirrored fills typically land in under 100ms. To get started, open the connect flow in your copier dashboard and authenticate directly through Tradovate.
*
> TL;DR: > > - Before linking accounts, confirm each Tradovate account is active, verify follower IDs, and test one follower with a small trade before enabling others. > - Mirrored fills typically arrive in under 100ms, but automatic token refresh and a live connection determine continuity; investigate stale or disconnected status before trading. > - Prop firm rules vary by firm and account type, so get written approval for copying; daily loss limits, profit targets, and consistency rules still apply. > - Review requested permissions and reject access beyond reading fills and placing enabled follower orders; you can revoke each account's token through Tradovate settings.
*
Table of Contents
- What Tradovate OAuth does and why it matters for copy trading
- Step-by-step: connect your Tradovate accounts to a copier (user flow)
- Session and token management, uptime, and latency expectations
- Security checklist and red flags when connecting via OAuth
- What to confirm with each prop firm before you connect
- Common connection problems and quick fixes
- Detailed explanation of the OAuth token scope and permissions specifically required for trade copying
- How to revoke Tradovate API access tokens and manage connected apps
- Error handling in the OAuth authentication flow (e.g., denied permissions, expired tokens)
- Differences between OAuth authentication and legacy API key methods if applicable
- How the OAuth authentication integrates technically with real-time WebSocket data streaming
- Recommended frequency and method for token renewal to maintain uninterrupted copying
- A practitioner's take on OAuth for multi-account copying
- How TradeDupe implements OAuth safely
- FAQ
- Sources
What Tradovate OAuth does and why it matters for copy trading
OAuth separates two jobs that used to get mixed together: proving who you are, and letting a third-party tool act on your behalf. When you connect a copier through Tradovate's OAuth flow, you log in on Tradovate's own page, not inside the copier's app, and Tradovate issues the copier a token rather than handing over your credentials. That token typically grants limited permissions: reading your fills and account status, and placing mirrored orders on accounts you've explicitly enabled.
This matters because password sharing (or sharing API keys you generated yourself) puts you at the mercy of however carefully a third party stores that secret. A stolen or logged token can be revoked in seconds; a stolen password often cannot be changed fast enough to stop damage. For traders running several funded or evaluation accounts at once, the architecture also keeps the math simple: one authentication event per account, one token per connection, and a clean audit trail if something goes wrong.
Latency matters here too. Since copying is token-based and runs server-side rather than through a locally stored password, there's no added delay from credential handling, which keeps execution parity between leader and follower accounts tight.
Step-by-step: connect your Tradovate accounts to a copier (user flow)
Before you connect anything, confirm your Tradovate account is funded or active under your prop firm's evaluation, since a dormant account won't authenticate cleanly.
- Open the copier's dashboard and select "Connect Tradovate account."
- You're redirected to a Tradovate-hosted login page, not a page inside the copier's app.
- Enter your Tradovate credentials directly on that Tradovate page.
- Review the permissions requested (read fills, place orders on enabled accounts) and approve.
- You're returned to the copier dashboard, where the account now shows as connected.
- Repeat the process for each additional account: one leader, and as many followers as your plan allows.
Once connected, add each follower account individually and double-check the account IDs against what's listed in Tradovate itself, since prop firms often issue similarly numbered accounts across different evaluations.
A successful connection shows:
- The account listed as "active" with a visible token expiry or renewal status.
- A clear leader/follower designation for each linked account.
- A completed test trade that mirrors correctly, with matching entry price and size within a reasonable execution window.
Run that test with one follower before enabling the rest. It's the fastest way to catch a misconfigured account ID or a permissions issue before real size is on the line.
Session and token management, uptime, and latency expectations
Tokens issued through the OAuth token exchange come with an expiration window and a refresh token, which a well-built copier uses to renew access automatically in the background. You shouldn't need to manually re-authenticate every session: the point of the refresh mechanism is that it happens without your intervention, keeping the connection alive across the trading day.
This matters more than it sounds. A missed refresh means a dropped connection, and a dropped connection during an active trade means a follower account that doesn't mirror the leader's exit. Tradovate's own authentication guidance treats token renewal and session management as core to reliable authentication, not an afterthought.
On execution speed, "typically under 100ms" means the gap between your leader's fill and the follower's mirrored fill is small enough that slippage from the copying mechanism itself is rarely the issue; price movement in the underlying market is.
Check your dashboard periodically for token health indicators: connection status, last refresh time, and any flagged disconnections. If a connection shows as stale for more than a few minutes during market hours, that's worth investigating before you assume your followers are mirroring correctly.
Security checklist and red flags when connecting via OAuth
Before you trust any service with your Tradovate accounts, run through a short list of checks.
- Confirm the login redirect lands on a Tradovate domain, not a lookalike page or a form inside the third-party app itself.
- Refuse any request to type your Tradovate password into a non-Tradovate page, no matter how the service frames it.
- Verify the service describes itself as using token-based access rather than storing your credentials directly.
- Look for automatic token refresh and a clear statement that passwords aren't logged or retained.
Tradovate's partner documentation is explicit that genuine OAuth flows redirect you to Tradovate for authentication. If a service instead asks for your raw credentials or an API key you'd need to generate yourself, treat it as a red flag rather than a minor inconvenience.
Pro Tip: Before enabling your full account list, connect one follower, place a single small test trade, and confirm the fill, size, and price all mirror correctly before scaling up.
What to confirm with each prop firm before you connect
Every prop firm sets its own rules on automated trade mirroring, and those rules vary enough that you should confirm them directly rather than assume. Ask specifically whether your account agreement allows copying trades from another account, since some evaluations treat this differently than funded accounts.
Daily loss limits, profit targets, and consistency rules typically still apply in full when you're copying, and they're usually enforced by the broker itself rather than by the copying tool. That's a meaningful distinction: a limit enforced at the Tradovate account level holds regardless of what the copier does on its side.
If a firm's policy on copying isn't clearly stated in your agreement, get written confirmation from their support team before you connect multiple accounts. For broader context on trader obligations and where to direct questions about registrants, the CFTC's futures market guidance is a useful starting point, though firm-specific rules always take precedence over general guidance.
Common connection problems and quick fixes
Most connection issues trace back to a handful of causes, and most are quick to resolve.
- Login redirect fails or hangs: check your browser's pop-up and redirect settings, since some browsers block the Tradovate login window by default.
- Frequent disconnections: re-authenticate manually once, then confirm the service's automatic token refresh is functioning; a pattern of repeated disconnects suggests a refresh issue worth reporting to support.
- Missing fills on a follower account: verify that account has sufficient margin and is explicitly enabled for copying, since an under-margined or disabled account won't mirror trades even when connected.
- Unexpected orders appear on a follower: disable copying on that account immediately using the per-account toggle, then contact support before re-enabling.
Keeping a simple log of token expiry dates and connection status checks makes these issues far easier to diagnose when they happen mid-session rather than after the fact.
Detailed explanation of the OAuth token scope and permissions specifically required for trade copying
Trade copying doesn't require broad account access. The permissions a copier needs typically break down into two categories: read access to your fills and account status, so it knows when your leader account executes a trade, and limited write access to place and manage orders on the specific follower accounts you've enabled.
This is narrower than full account control. A properly scoped token doesn't grant access to things like withdrawing funds or changing account settings, since those actions fall outside what mirroring requires. The scope is also account-specific: enabling copying on one follower doesn't automatically extend permissions to every account tied to your Tradovate login.
When you approve the permissions screen during the OAuth flow, you're seeing exactly what the copier is requesting, which is why it's worth reading that screen rather than clicking through it. If a service asks for permissions that go beyond reading fills and placing mirrored orders, treat that as a reason to ask questions before approving.
Because the token is scoped per connection, revoking access to one account doesn't affect your other connected accounts. That granularity is part of why OAuth-based copying is structured the way it is: each account relationship stands on its own, which limits the blast radius if any single token is ever compromised or needs to be pulled.
How to revoke Tradovate API access tokens and manage connected apps
Revoking access is a safeguard you'll want to know before you ever need it, not after. If you stop using a copier, switch services, or simply want to tighten up which apps have access to your accounts, you can revoke a connected app's token directly through Tradovate's own account settings rather than relying on the third-party service to do it for you.
Once revoked, the token stops working immediately: the copier loses both read and write access to that account, and any further mirroring attempts on it will fail until you reconnect and go through the OAuth flow again. This is a cleaner process than changing a password, since revocation is specific to that one connection and doesn't disrupt any other account or service you've authorized.
It's worth periodically reviewing which apps have standing access to your Tradovate accounts, particularly if you've tested multiple copy-trading tools over time. An old connection you forgot to revoke is still a live token with permissions attached to it, even if you haven't used that service in months.
If you're managing several funded or evaluation accounts across different prop firms, keep a simple record of which copier is connected to which account. That makes it far faster to spot an unfamiliar connection or to clean house when you consolidate your trading onto fewer tools.
Error handling in the OAuth authentication flow (e.g., denied permissions, expired tokens)
OAuth flows are built to fail safely, which means most errors show up as a blocked connection rather than a silent problem. If you deny the permissions request during setup, the connection simply doesn't complete: no token is issued, and the copier has no access to that account until you try again and approve the request.
Expired tokens behave differently depending on whether the refresh token is still valid. A well-built copier catches an expiring access token and renews it automatically in the background, so you typically never see this as a visible error. If the refresh token itself has expired or been revoked, though, you'll usually see the account marked as disconnected in your dashboard, and you'll need to re-authenticate through the Tradovate login screen again.
Other common errors include a denied scope (the account connects, but without full permissions, which usually blocks order placement while still allowing read access) and a redirect mismatch, which typically shows up as a failed login rather than a partial connection.
The practical takeaway is to treat any "disconnected" or "pending" status in your dashboard as something to resolve before market open, not during an active trade. Checking connection status as part of your pre-market routine catches most of these issues before they affect a mirrored fill.

Differences between OAuth authentication and legacy API key methods if applicable
Tradovate's partner quickstart documentation outlines an alternative developer-level flow using an access token request method, which is closer to a traditional API key setup. That path is built for developers registering their own applications with Tradovate, and it typically requires partner approval to obtain a client ID and secret.
As a retail trader connecting a copier, you generally don't interact with that developer flow at all. You use the copier's own registered app and authenticate through Tradovate's hosted login, which is the OAuth delegation model described throughout this article. The practical difference comes down to who holds the keys: in a legacy API key setup, a long-lived credential sits with whoever registered the app, while in OAuth, your authentication happens directly with Tradovate each time, and the copier only ever holds a scoped, revocable token.
This is part of why community discussions around registering an OAuth app are aimed at developers building tools, not at traders using them. If you're connecting accounts to mirror trades, you shouldn't need to generate your own client credentials. If a service asks you to do that, it's worth confirming why, since it departs from the standard retail connection flow.
How the OAuth authentication integrates technically with real-time WebSocket data streaming
Once your account is authenticated and a token is issued, that token is what authorizes the ongoing connection to Tradovate's real-time data stream. The access token isn't just used once at login: it's presented when the copier opens a live WebSocket connection to receive your account's fills and order updates as they happen, rather than polling for updates on a delay.
This is what makes near-instant mirroring possible. When your leader account's order fills, that fill event travels over the authenticated WebSocket connection to the copier almost immediately, which is what allows mirrored execution on your follower accounts to happen with the latency typically under 100ms mentioned earlier. Without a persistent, authenticated stream, a copier would have to repeatedly check for updates, adding delay at every step.

If the token backing that WebSocket connection expires or is revoked, the stream drops, which is another reason automatic token refresh matters: a lapsed token doesn't just block new logins, it can interrupt an active data stream mid-session. A properly built copier monitors that connection and re-establishes it quickly if a refresh occurs or a brief disconnection happens, so you don't lose fills during the gap.
Recommended frequency and method for token renewal to maintain uninterrupted copying
You shouldn't need to manually renew tokens on any regular schedule. The refresh mechanism built into Tradovate's OAuth flow is designed to run automatically in the background, typically renewing the access token before it expires without requiring you to log in again. This is the method Tradovate's own authentication guidance points to as standard practice for session management.
Your role is mostly supervisory rather than active. Check your dashboard's connection status periodically, especially before and during market hours, to confirm each account shows as actively connected rather than pending or disconnected. If you notice a pattern of frequent re-authentication prompts, that's a signal the refresh process isn't working as expected, and it's worth flagging to support rather than treating as routine.
A simple habit worth adopting: glance at your connected accounts list at the start of each trading session, the same way you'd check margin or account balance. It takes a few seconds and catches a lapsed connection before it costs you a missed mirrored fill. Beyond that daily glance, there's no manual renewal process you need to run. The system is built to keep the token cycle invisible, which is the entire point of using OAuth over a static credential that depends on you to maintain it.
A practitioner's take on OAuth for multi-account copying
In building a copying workflow around Tradovate's own OAuth flow, the pattern that stands out is how little the trader actually has to manage day to day. Mirroring that runs typically under 100ms only matters if the connection underneath it is stable, and stability comes from boring, reliable token renewal rather than anything flashy.
The habits worth keeping are simple: check your connected accounts each morning, test with a single follower before scaling to the rest, and use per-account toggles rather than an all-or-nothing switch. None of that replaces confirming your specific firm's rules on automated copying before you turn it on.
> — Andres
How TradeDupe implements OAuth safely
Our connection flow uses Tradovate's OAuth system so you can link accounts without handing over your password to anyone. You authenticate directly through Tradovate, the system receives a scoped token, and that token is used to mirror your leader account's fills to your enabled followers in real time.

Beyond the connection itself, we layer in the controls multi-account traders actually need:
- Per-account copy toggles so you can enable or pause mirroring on any single account without touching the rest.
- Rogue-trade detection that flags follower trades the copier didn't place.
- Daily loss limits and profit targets enforced directly on Tradovate, so the broker holds the line rather than relying on client-side settings.
If you're running accounts across firms like Apex Trader Funding, Tradeify, Lucid Trading, MyFundedFutures, Alpha Futures, or TakeProfit Trader, you can start a 7-day free trial and connect one follower account to see how the mirroring holds up before enabling the rest.
FAQ
Does Tradovate OAuth require sharing my password with a copier?
No. The OAuth flow redirects you to a Tradovate-hosted login page, so you enter your credentials directly with Tradovate rather than with the third-party service. The copier only receives a scoped access token afterward, as described in Tradovate's community documentation on third-party app access.
How fast are mirrored trades after connecting via OAuth?
Execution latency for mirrored fills is typically under 100ms, based on community reporting on OAuth integrations. That speed depends on a stable, authenticated connection rather than on the OAuth handshake itself, which only happens once per session.
What happens if my OAuth token expires mid-session?
A well-built copier renews your access token automatically in the background before it expires, following the session management practices described in Tradovate's partner authentication guidance. If the refresh token itself has expired, you'll typically see the account marked as disconnected and need to log in again.
Can I revoke a connected app's access to my Tradovate account?
Yes, you can revoke a connected app's token directly through your Tradovate account settings at any time. Revocation is specific to that one connection, so it immediately stops the app's access without affecting your password or any other connected service.
Do I need to confirm copy trading is allowed with my prop firm?
Yes, policies on automated mirroring vary by firm and by account type, so confirm directly with your prop firm before connecting multiple accounts. Daily loss limits, profit targets, and consistency rules typically still apply in full and are usually enforced at the broker level regardless of how trades are placed.
Sources
Recommended
- Tradovate Trade Copier | Real-Time Account Sync
- Tradovate API Security: Auth Rules Developers Need
- Tradovate multi-account trading: Master your ecosystem
- 34ms Mirroring: Link Tradovate Accounts for Prop Desks
For educational purposes only. Not financial advice. Futures trading involves substantial risk of loss and is not suitable for every investor.