> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://partner.ninjatrader.com/eval/api/rest-api-endpoints/risks/organization-admin-lock-account/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://partner.ninjatrader.com/_mcp/server. # Organization Admin Lock Account POST https://live.tradovateapi.com/v1/accountRiskStatus/organizationadminlockaccount Content-Type: application/json ### Lock a subaccount to closing orders only.**Available to:** Organization administrators**Environments:** Live**[Rate Limit](/eval/overview/core-concepts/rate-limits):** No endpoint-specific limitApply a partner lock to a subaccount in your own organization, putting it in liquidate-only mode (`LiquidateOnlyModeImmediately`): the account can close open positions but can't open new ones. The lock is recorded with the `PartnerPayoutLock` reason code. You can pass an optional `reason`, stored with the lock and prefixed with `Partner lock:`.A partner lock never overrides a stronger lock. The check reads the subaccount's `adminAction`: if it's already `LockTradingImmediately` or `LiquidateImmediately`, the request is rejected. Locking a subaccount that's already in liquidate-only mode has no further effect, and returns the same shape as a successful lock — `HTTP 200` carrying the account's risk status, with no `errorText`.NinjaTrader enables this feature per organization, so work with the NinjaTrader Support team to turn it on.A rejected request returns `HTTP 200` with `errorText` set and no `accountRiskStatus`, not an error status. Check `errorText` to determine whether the lock succeeded.For the subaccount lifecycle, the effect on trading, and how this differs from Change Lock, see [Partner Account Lock and Unlock](/eval/overview/prop-firm-management/partner-account-lock-and-unlock).**Common Failure Scenarios**- The account isn't a subaccount in your organization, or the feature isn't enabled for your organization. The request is denied. - The account's `adminAction` is already `LockTradingImmediately` or `LiquidateImmediately`, which a partner lock can't replace.**Error Messages**A failed request returns one of these messages:| Message | Response | Trigger | | ---------------------------------------------------- | -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `"Account has an existing lock - contact Tradovate"` | 200 (in `errorText`) | The account's `adminAction` is already `LockTradingImmediately` or `LiquidateImmediately`, which a partner lock can't replace. | | `"Access is denied"` | 401 | The caller isn't an organization administrator, the account isn't a subaccount in the caller's organization, or the feature isn't enabled. An account in another organization can return `HTTP 404`. |**Related Resources**- To reverse a partner lock or clear a risk lock, see [`organizationAdminUnlockAccount`](/eval/api/rest-api-endpoints/risks/organization-admin-unlock-account). - To apply a partner lock or unlock using the Admin Dashboard, see [Partner Account Lock and Unlock](/eval/overview/prop-firm-management/partner-account-lock-and-unlock). Reference: https://partner.ninjatrader.com/eval/api/rest-api-endpoints/risks/organization-admin-lock-account ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Request ### Body (application/json) This endpoint expects an OrganizationAdminLockAccount. - `accountId` (long, required) - `reason` (string, optional) ## Response ### 200 AccountRiskStatusResponse - `errorText` (string, optional) — Non-empty if the request failed - `accountRiskStatus` (AccountRiskStatus, optional) ## Types ### AccountRiskStatus - `id` (long, optional) - `adminAction` (enum, optional) — AgreedOnLiqOnlyModeByAutoLiq, AgreedOnLiquidationByAutoLiq, DisableAutoLiq, LiquidateImmediately, LiquidateOnlyModeImmediately, LockTradingImmediately, Normal, PlaceAutoLiqOnHold - Allowed values: `AgreedOnLiqOnlyModeByAutoLiq`, `AgreedOnLiquidationByAutoLiq`, `DisableAutoLiq`, `LiquidateImmediately`, `LiquidateOnlyModeImmediately`, `LockTradingImmediately`, `Normal`, `PlaceAutoLiqOnHold` - `adminTimestamp` (datetime, optional) - `liquidateOnly` (datetime, optional) - `userTriggeredLiqOnly` (boolean, optional) - `maxNetLiq` (double, optional) — $ Max Net Liq - `minNetLiq` (double, optional) — $ Min Net Liq ## Examples **Request** ```json { "accountId": 1 } ``` **Response** ```json { "errorText": "string", "accountRiskStatus": { "id": 1, "adminAction": "AgreedOnLiqOnlyModeByAutoLiq", "adminTimestamp": "2024-01-15T09:30:00Z", "liquidateOnly": "2024-01-15T09:30:00Z", "userTriggeredLiqOnly": true, "maxNetLiq": 1.1, "minNetLiq": 1.1 } } ``` **SDK Code** ```python import requests url = "https://live.tradovateapi.com/v1/accountRiskStatus/organizationadminlockaccount" payload = { "accountId": 1 } headers = { "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://live.tradovateapi.com/v1/accountRiskStatus/organizationadminlockaccount'; const options = { method: 'POST', headers: {Authorization: 'Bearer ', 'Content-Type': 'application/json'}, body: '{"accountId":1}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://live.tradovateapi.com/v1/accountRiskStatus/organizationadminlockaccount" payload := strings.NewReader("{\n \"accountId\": 1\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://live.tradovateapi.com/v1/accountRiskStatus/organizationadminlockaccount") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{\n \"accountId\": 1\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://live.tradovateapi.com/v1/accountRiskStatus/organizationadminlockaccount") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{\n \"accountId\": 1\n}") .asString(); ``` ```php request('POST', 'https://live.tradovateapi.com/v1/accountRiskStatus/organizationadminlockaccount', [ 'body' => '{ "accountId": 1 }', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://live.tradovateapi.com/v1/accountRiskStatus/organizationadminlockaccount"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", "Bearer "); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"accountId\": 1\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "Bearer ", "Content-Type": "application/json" ] let parameters = ["accountId": 1] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://live.tradovateapi.com/v1/accountRiskStatus/organizationadminlockaccount")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```