> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://partner.ninjatrader.com/connect/api/rest-api-endpoints/users/get-account-trading-permissions/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://partner.ninjatrader.com/_mcp/server. # Get Account Trading Permissions POST https://demo.tradovateapi.com/v1/user/getaccounttradingpermissions Content-Type: application/json ### Query the granted trading permissions associated with this account. **Available to:** Traders (own account); organization administrators (any account in their organization) **Environments:** Demo, Live **[Rate Limit](/overview/core-concepts/rate-limits):** 100 requests per hour, 1-second back-off, counts all requests Retrieve every trading permission on the account identified by `accountId`. Each `TradingPermission` ties a user to the account and carries the permission's status, so this endpoint shows which users can trade the account and where each one stands in the approval flow. Don't poll this endpoint to watch for a permission's approval. The rate limit counts every request, so a polling loop pushes you toward a penalty ticket. After you call `createTradingPermission`, keep the permission ID it returns and fetch that record directly by its ID, or subscribe to updates over a WebSocket with `user/syncRequest`. See [Penalty Tickets](/overview/core-concepts/penalty-tickets). **Common Failure Scenarios** * A Trader queries an account they don't own. The call is denied. * The `accountId` can't be reached: it doesn't exist, or it's in another organization (organization administrators can only query accounts in their own organization). The call fails with a not-found error. **Related Endpoints** * Use [`createTradingPermission`](/api/rest-api-endpoints/users/create-trading-permission) to grant a permission to a user in one step. * Use [`requestTradingPermission`](/api/rest-api-endpoints/users/request-trading-permission) to request a permission the account holder then accepts with [`acceptTradingPermission`](/api/rest-api-endpoints/users/accept-trading-permission). * Use [`revokeTradingPermission`](/api/rest-api-endpoints/users/revoke-trading-permission) or [`revokeTradingPermissions`](/api/rest-api-endpoints/users/revoke-trading-permissions) to remove permissions. Reference: https://partner.ninjatrader.com/connect/api/rest-api-endpoints/users/get-account-trading-permissions ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Request ### Body (application/json) This endpoint expects a GetAccountTradingPermissions. - `accountId` (long, required) ## Response ### 200 TradingPermissionsResponse - `tradingPermissions` (list of TradingPermission, required) ## Types ### TradingPermission - `userId` (long, required) - `accountId` (long, required) - `accountHolderContact` (string, required) - `accountHolderEmail` (string, required) - `ctaContact` (string, required) - `ctaEmail` (string, required) - `status` (enum, required) — Accepted, Approved, Declined, Requested, Revoked - Allowed values: `Accepted`, `Approved`, `Declined`, `Requested`, `Revoked` - `id` (long, optional) - `updated` (datetime, optional) - `approvedById` (long, optional) ## Examples **Request** ```json { "accountId": 1 } ``` **Response** ```json { "tradingPermissions": [ { "userId": 1, "accountId": 1, "accountHolderContact": "string", "accountHolderEmail": "string", "ctaContact": "string", "ctaEmail": "string", "status": "Accepted", "id": 1, "updated": "2024-01-15T09:30:00Z", "approvedById": 1 } ] } ``` **SDK Code** ```python import requests url = "https://demo.tradovateapi.com/v1/user/getaccounttradingpermissions" payload = { "accountId": 1 } headers = { "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://demo.tradovateapi.com/v1/user/getaccounttradingpermissions'; const options = { method: 'POST', headers: {Authorization: 'Bearer ', 'Content-Type': 'application/json'}, body: '{"accountId":1}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://demo.tradovateapi.com/v1/user/getaccounttradingpermissions" payload := strings.NewReader("{\n \"accountId\": 1\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://demo.tradovateapi.com/v1/user/getaccounttradingpermissions") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{\n \"accountId\": 1\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://demo.tradovateapi.com/v1/user/getaccounttradingpermissions") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{\n \"accountId\": 1\n}") .asString(); ``` ```php request('POST', 'https://demo.tradovateapi.com/v1/user/getaccounttradingpermissions', [ 'body' => '{ "accountId": 1 }', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://demo.tradovateapi.com/v1/user/getaccounttradingpermissions"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", "Bearer "); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"accountId\": 1\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "Bearer ", "Content-Type": "application/json" ] let parameters = ["accountId": 1] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://demo.tradovateapi.com/v1/user/getaccounttradingpermissions")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```