Use the CandleScript.io REST API with Python and JavaScript
Authenticate with a scoped partner key and request symbols, quote snapshots, and historical bars without an unpublished SDK dependency.
Published 2026-08-18; reviewed 2026-08-18.
1. Store the API key server-side
Create the key from the authenticated developer page and place it in a server-side environment variable. Never embed partner keys in browser JavaScript.
bashCANDLESCRIPT_API_KEY=cpk_replace_me CANDLESCRIPT_API_BASE=https://candlescript.io/api2. Fetch a quote with JavaScript
Use the platform-native fetch API in Node.js and send the key in the Authorization header.
javascriptconst base = process.env.CANDLESCRIPT_API_BASE; const response = await fetch( `${base}/v1/public/quotes?symbols=NASDAQ%3AAAPL,COINBASE%3ABTCUSD`, { headers: { Authorization: `Bearer ${process.env.CANDLESCRIPT_API_KEY}` } } ); if (!response.ok) throw new Error(`HTTP ${response.status}`); console.log(await response.json());3. Fetch daily history with Python
The same Bearer key can call a permitted history scope from a backend Python process.
pythonimport os import requests base = os.environ["CANDLESCRIPT_API_BASE"] headers = {"Authorization": f"Bearer {os.environ['CANDLESCRIPT_API_KEY']}"} params = {"symbol": "NASDAQ:AAPL", "resolution": "1D"} response = requests.get(f"{base}/v1/public/history", headers=headers, params=params, timeout=15) response.raise_for_status() print(response.json())4. Handle limits and failures
Treat 401 and 403 as credential or scope failures. On 429, honor Retry-After and the rate-limit response headers rather than retrying immediately.