- Home
- Knowledge Center
- api-trading-india-2026-static-ip-sebi-rules

API trading in India 2026: static IP rules, SEBI compliance and what traders need to know

API trading lets trading software connect directly with a broker's system and send orders automatically. In India, the way these APIs can be used is now subject to specific SEBI and exchange requirements, including rules around static IPs, authentication, and order limits.
Quick Answer
API trading can save traders from entering every order manually, but the connection has to meet the broker's compliance requirements. A static IP is used to link API access to the client, while authentication, order limits and other controls apply to automated trading. These requirements came into effect for stock brokers from April 1, 2026.
What is API trading in India?
API stands for Application Programming Interface. In trading, it allows your software to communicate with your broker's trading system.
For example, a trader may create software that generates an order based on a predefined rule. The API can send that order to the broker instead of requiring the trader to enter it manually.
When API trading is used to automate buying or selling, it comes under the regulatory framework for algorithmic trading. The rules apply to retail API access provided through brokers.
Why is a static IP required for API trading?
A static IP is an internet address that rarely changes. According to the implementation standards for the exchange, the client requesting API access is required to provide a static IP mapped to the API key.
The purpose is identification and traceability. The broker can link API activity to a particular client instead of allowing an open API connection from changing addresses.
Multiple API keys can also be mapped to the same approved IP addresses, depending on how the broker has configured the facility.
What are the main SEBI API rules in 2026?
The current framework covers more than just the static IP requirement.
| Requirement | What It Means |
|---|---|
| Static IP | API access must use a mapped static IP |
| API Key | Access is linked to a client-specific API key |
| 2FA | Client access must use permitted two-factor authentication |
| Order Limit | Threshold Order Per Second applies |
| Algo Registration | Higher-speed algos need exchange registration |
| Audit Trail | API orders and trades must be traceable |
| Risk Controls | Brokers must maintain required RMS checks |
| API Sessions | Sessions must be logged out before the next trading day |
What is the 10 orders per second rule?
The framework initially set the Threshold Order Per Second (TOPS) at 10 orders per second per exchange or segment. Exchanges can change this threshold after giving notice to the market. Brokers can also set a lower client-level limit.
In cases where API-based algo orders fall below the threshold, the trader will not be required to register an algorithm for the individual client. However, the orders still remain subject to broker risk controls and exchange tagging requirements.
If a client wants to place orders above the threshold, the algorithm must be registered with each exchange where it will be used. The broker forwards the required information to the exchange, which provides the relevant registration ID.
What happens if you use an algo provider?
A trader does not always build the trading software personally. An external algo provider can also provide the technology.
Under the framework, algo providers must be impaneled with the relevant exchanges. Their algorithms also need the required exchange registration and identification. Brokers are expected to carry out due diligence on these providers and report violations of securities laws to the relevant exchange.
This means traders should not assume that any third-party software can simply be connected to a broker API.
What should traders check before using an API?
Before starting API trading, check the broker's current API requirements. The practical points include:
Whether a static IP is required and how it is mapped
Whether 2FA is required
The applicable order-per-second limit
Whether your algo needs exchange registration
Whether the software provider is impaneled where required
How API sessions and access are monitored
What does SEBI compliance mean for retail traders?
SEBI's framework places significant responsibility on the broker. Brokers must have systems to monitor API activity, maintain audit trails, and apply risk controls. API and algo orders must also be traceable to the relevant user.
For traders, this means API access is no longer simply a technical connection between software and a broker. The connection has regulatory and operational requirements that must be followed.
NSE's current framework also provides a category called Client Direct API for retail algo facilities and requires members to follow the exchange's registration and documentation process.
Conclusion
API trading in India now involves more than a software connection. Static IP mapping, order limits, authentication, risk controls and algo registration can all apply depending on how the API is used.
For retail traders, the important point is simple: an API is not just a software connection anymore. The way it is configured and used must fit the broker's and exchange's current compliance framework.
Frequently asked questions
Q. Is a static IP mandatory for API trading in India?
Ans. Yes. In accordance with the standards of the current implementation of the exchange, any client who uses a broker API connection needs to provide static IP addresses mapped to their API keys.
Q. What is the API trading order limit in India?
Ans. Initially, the threshold order per second limit was 10 orders per second per exchange or segment. Exchanges can change this, and brokers can impose their own client-level limits.
Q. Does every API strategy need algo registration?
Ans. No, not always. If orders do not exceed the corresponding threshold, algorithm registration is not required, but orders exceeding the threshold should be registered at the relevant exchange.
Q. Can I change my static IP whenever I want?
Ans. The implementation standards allow clients to update their mapped static IP, but normally not more than once in a calendar week. Extraordinary cases can be handled through the broker.
Q. Can I use any third-party algo provider?
Ans. No. The framework requires algo providers to be empanelled with the relevant exchanges where their algorithms are intended to trade.
Sources
SEBI: Safer participation of retail investors in Algorithmic trading, February 4, 2025.
SEBI: Extension of timeline for implementation of SEBI Circular dated…, Sept 30, 2025
NSE: Implementation Standards for safer participation of retail investors in Algorithmic trading, May 5, 2025.
NSE: current Decision Support Tools / Algorithms trading framework.
Disclaimer: Investments in the securities market are subject to market risks. Please read all related documents carefully before investing. This article is intended for informational and knowledge purposes only and should not be considered tax, financial, or investment advice. Tax laws and deductions may vary based on individual circumstances and regulatory changes. Readers are advised to consult a qualified tax advisor or financial professional before making any investment or tax planning decisions.
Indira Securities Private Limited (SEBI Reg. No.): NSE TM ID: 12866 | BSE TM ID: 663 | CDSL DPID: 17000 | SEBI Reg. No.: INZ000188930 | MCX TM ID: 56470 | NCDEX TM ID: 01277 | CDSL Reg. No.: IN-DP-90-2015 | CIN:U67120MP1996PTC085111 | RA SEBI Reg. No.: INH000023269 | IA SEBI Reg. No.: INA000021410 | SEBI Merchant Banking Reg. No.: INM000013536
Related Posts
Discover more insights and expert advice on investing and financial planning.



Open Your Free Demat Account
Getting started doesn’t take much. No paperwork, no hidden charges. Just a few steps and you’re ready to invest or trade.
Account Today
No paperwork | No hidden fees | Just a few taps to get started.
