Operations
Fresh approval flow
- Allocate a canonical UUID
operation_idfor the exact draft. - Start with
purpose:"credential"or"binding"and the full proposed request. - Use an offered authentication method. The Apple flow must use the returned nonce and the subject already linked to this account.
- Verify exactly one of
passwordorapple_token, plusmfa_codewhen required. - Issue the exact approved request with the same operation ID before approval expiry.
Credential request
integration_id is for replacement within an existing exact namespace policy.
The issuance response contains credential metadata and a one-time secret on new issuance. A committed duplicate cannot recover the secret. After a lost response, inspect metadata and revoke a key whose secret was not retained before explicitly creating another.
TradingView binding policy
In addition to restricted credential fields, a binding hasmode, position_mode, allow_market_terminate, positive decimal-string max_quantity, fresh source UUID and guided position_request when applicable. One exact link and instrument are required. The returned immutable revision accompanies subsequent signals.
single/multiple controls OPEN occupancy, while the signal’s exact-position/strategy/market target controls what termination selects. The explicit market grant is additional authority, including manual and other strategies’ positions in that exact market. It is not enabled by choosing multiple-position mode.
Metadata, retention and revocation
Active metadata is listed first, followed by recent history, up to 100 rows. Inactive credentials become eligible for cleanup 30 days after their own expiry or revocation, provided retained command evidence no longer references them. Unrevoked keyless TradingView setups remain visible for disconnection. A credential’s expiry does not itself remove its setup or free the unrevoked-binding capacity. Export metadata you need beyond its retention window without exporting secrets. The Settings Activity list retains the command receipt semantics described in commands and receipts. Confirmed revocation is200 {"revoked":true}. If the result is REVOCATION_UNCERTAIN, refresh metadata before an explicit retry. New handoff authorization changes do not interrupt trading-owned protection or recovery.