Developer APIOverview

Developer portal

Build with the CandleScript.io REST and WebSocket APIs.

Get started

Partner market-data calls use /v1/public/* with a Bearer API key. Create keys on the Manage API keys page (or workstation Plans & API). Production base URL: https://candlescript.io/api.

bash
curl -s "https://candlescript.io/api/v1/public/symbols?query=AAPL" \
  -H "Authorization: Bearer $CHARTING_API_KEY"
javascript
const response = await fetch(
  "https://candlescript.io/api/v1/public/quotes?symbols=NASDAQ%3AAAPL,COINBASE%3ABTCUSD",
  { headers: { Authorization: `Bearer ${process.env.CANDLESCRIPT_API_KEY}` } }
);
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());

Authentication & scopes

Public API keys are scoped to market-data endpoints. Session cookies are required for Candle Script, webhooks, and user resources.

ScopeGrants
symbols:readSearch and resolve symbols (`GET /v1/public/symbols`).
quotes:readLatest quote snapshots (`GET /v1/public/quotes`).
history:readHistorical OHLCV bars (`GET /v1/public/history`).
screeners:readRun screeners (`GET /v1/public/screeners`).
news:readRead the signed partner news feed (`GET /v1/public/news`).
news:eventsRead lifecycle events and distribution usage reports.
http
GET /v1/public/history?symbol=NASDAQ:AAPL&resolution=1D HTTP/1.1
Host: api.candlescript.io
Authorization: Bearer cpk_xxxxxxxxxxxxxxxx
Accept: application/json

Rate limits

Limits are enforced per API key. On 429 responses, honor Retry-After and inspect X-RateLimit-Remaining and X-RateLimit-Reset.

PlanREST APIWebSocket API
Essential1,000 requests / dayNot included
Plus10,000 requests / day2 connections; 100 symbols each
Premium50,000 requests / day10 connections; 500 symbols each
Ultimate250,000 requests / day50 connections; 1,000 symbols each

Resources

Developer API FAQ

How do I authenticate with the CandleScript.io partner API?
Create a scoped API key from the authenticated developer key page, then send it as a Bearer token in the Authorization header. Session cookies are used for account-owned resources and are not a substitute for a partner API key.
Which plans include REST and WebSocket API access?
Essential includes scoped REST access with 1,000 requests per day. Plus and higher include the partner quote WebSocket, with connection, symbol, and daily request limits increasing by tier. Basic accounts cannot create partner API keys.
Is the browser chart stream the same as the partner WebSocket API?
No. The product market stream powers CandleScript.io pages and has its own session entitlements. The partner quote WebSocket is API-key authenticated, separately metered, and available starting with Plus.
Is there a published JavaScript or Python SDK?
Not yet. The public integration contract is the OpenAPI document plus the REST and WebSocket guides. Examples use standard fetch, WebSocket, and Python HTTP clients so they work without an unpublished package.

CandleScript.io uses synthetic data in offline development. Production keys return entitlement-gated market data.

Developer portal | CandleScript.io