API trading in India 2026: static IP rules, SEBI compliance and what traders need to know
IPO & New Listings

API trading in India 2026: static IP rules, SEBI compliance and what traders need to know

JITENDRA BAROD profile photo
JITENDRA BAROD
5 min
BlogsIPO & New Listings
API trading in India 2026
API trading in India allows software to connect directly with broker systems and automate orders. From April 1, 2026, API-based trading is subject to requirements such as static IP mapping, authentication and order limits. This guide explains the key compliance rules traders need to know.

API trading lets trading software connect directly with a broker's system and send orders automatically. In India, the way these APIs can be used is now subject to specific SEBI and exchange requirements, including rules around static IPs, authentication, and order limits.

Quick Answer

API trading can save traders from entering every order manually, but the connection has to meet the broker's compliance requirements. A static IP is used to link API access to the client, while authentication, order limits and other controls apply to automated trading. These requirements came into effect for stock brokers from April 1, 2026.

What is API trading in India?

API stands for Application Programming Interface. In trading, it allows your software to communicate with your broker's trading system.

For example, a trader may create software that generates an order based on a predefined rule. The API can send that order to the broker instead of requiring the trader to enter it manually.

When API trading is used to automate buying or selling, it comes under the regulatory framework for algorithmic trading. The rules apply to retail API access provided through brokers.

Why is a static IP required for API trading?

A static IP is an internet address that rarely changes. According to the implementation standards for the exchange, the client requesting API access is required to provide a static IP mapped to the API key.

The purpose is identification and traceability. The broker can link API activity to a particular client instead of allowing an open API connection from changing addresses.

Multiple API keys can also be mapped to the same approved IP addresses, depending on how the broker has configured the facility.

What are the main SEBI API rules in 2026?

The current framework covers more than just the static IP requirement.

RequirementWhat It Means
Static IPAPI access must use a mapped static IP
API KeyAccess is linked to a client-specific API key
2FAClient access must use permitted two-factor authentication
Order LimitThreshold Order Per Second applies
Algo RegistrationHigher-speed algos need exchange registration
Audit TrailAPI orders and trades must be traceable
Risk ControlsBrokers must maintain required RMS checks
API SessionsSessions must be logged out before the next trading day

What is the 10 orders per second rule?

The framework initially set the Threshold Order Per Second (TOPS) at 10 orders per second per exchange or segment. Exchanges can change this threshold after giving notice to the market. Brokers can also set a lower client-level limit.

In cases where API-based algo orders fall below the threshold, the trader will not be required to register an algorithm for the individual client. However, the orders still remain subject to broker risk controls and exchange tagging requirements.

If a client wants to place orders above the threshold, the algorithm must be registered with each exchange where it will be used. The broker forwards the required information to the exchange, which provides the relevant registration ID.

What happens if you use an algo provider?

A trader does not always build the trading software personally. An external algo provider can also provide the technology.

Under the framework, algo providers must be impaneled with the relevant exchanges. Their algorithms also need the required exchange registration and identification. Brokers are expected to carry out due diligence on these providers and report violations of securities laws to the relevant exchange.

This means traders should not assume that any third-party software can simply be connected to a broker API.

What should traders check before using an API?

Before starting API trading, check the broker's current API requirements. The practical points include:

  • Whether a static IP is required and how it is mapped

  • Whether 2FA is required

  • The applicable order-per-second limit

  • Whether your algo needs exchange registration

  • Whether the software provider is impaneled where required

  • How API sessions and access are monitored

What does SEBI compliance mean for retail traders?

SEBI's framework places significant responsibility on the broker. Brokers must have systems to monitor API activity, maintain audit trails, and apply risk controls. API and algo orders must also be traceable to the relevant user.

For traders, this means API access is no longer simply a technical connection between software and a broker. The connection has regulatory and operational requirements that must be followed.

NSE's current framework also provides a category called Client Direct API for retail algo facilities and requires members to follow the exchange's registration and documentation process.

Conclusion

API trading in India now involves more than a software connection. Static IP mapping, order limits, authentication, risk controls and algo registration can all apply depending on how the API is used.

For retail traders, the important point is simple: an API is not just a software connection anymore. The way it is configured and used must fit the broker's and exchange's current compliance framework.

Frequently asked questions

Q. Is a static IP mandatory for API trading in India?

Ans. Yes. In accordance with the standards of the current implementation of the exchange, any client who uses a broker API connection needs to provide static IP addresses mapped to their API keys.

Q. What is the API trading order limit in India?

Ans. Initially, the threshold order per second limit was 10 orders per second per exchange or segment. Exchanges can change this, and brokers can impose their own client-level limits.

Q. Does every API strategy need algo registration?

Ans. No, not always. If orders do not exceed the corresponding threshold, algorithm registration is not required, but orders exceeding the threshold should be registered at the relevant exchange.

Q. Can I change my static IP whenever I want?

Ans. The implementation standards allow clients to update their mapped static IP, but normally not more than once in a calendar week. Extraordinary cases can be handled through the broker.

Q. Can I use any third-party algo provider?

Ans. No. The framework requires algo providers to be empanelled with the relevant exchanges where their algorithms are intended to trade.

Disclaimer: Investments in the securities market are subject to market risks. Please read all related documents carefully before investing. This article is intended for informational and knowledge purposes only and should not be considered tax, financial, or investment advice. Tax laws and deductions may vary based on individual circumstances and regulatory changes. Readers are advised to consult a qualified tax advisor or financial professional before making any investment or tax planning decisions.

Indira Securities Private Limited (SEBI Reg. No.): NSE TM ID: 12866 | BSE TM ID: 663 | CDSL DPID: 17000 | SEBI Reg. No.: INZ000188930 | MCX TM ID: 56470 | NCDEX TM ID: 01277 | CDSL Reg. No.: IN-DP-90-2015 | CIN:U67120MP1996PTC085111 | RA SEBI Reg. No.: INH000023269 | IA SEBI Reg. No.: INA000021410 | SEBI Merchant Banking Reg. No.: INM000013536

Related Posts

Discover more insights and expert advice on investing and financial planning.

Stockk mobile trading app preview

Open Your Free Demat Account

Getting started doesn’t take much. No paperwork, no hidden charges. Just a few steps and you’re ready to invest or trade.