Enable API access / create a Kite Connect app
Your trading account (chapter 3) is separate from API access. API access is a developer product you subscribe to on top of the trading account.
Regulatory note (as of April 2026): SEBI's retail algo trading framework is now fully mandatory for every broker — before you can place a single live order through this API, your broker requires you to register with a static IP address and (for anything beyond manual-trigger use) a broker-issued Strategy/Algo ID. This changes several steps below and in later chapters. Read chapter 134 in full before going further if you intend to run anything live, not just in paper mode.
Steps (Zerodha Kite Connect)
- Go to
developers.kite.tradeand log in with your Zerodha client ID. - Subscribe to Kite Connect. Pricing dropped from the old ₹2000/month to ₹500/month per API key (Zerodha revised this in response to developer community pressure) — a free "Personal" tier also exists with reduced rate limits, sufficient for learning/paper trading before you pay for the full Connect tier. Verify current pricing on the developer console before subscribing, as this has changed before and can change again.
- Create a new app: - App name — anything, e.g.
my-algo-bot- Redirect URL — where Zerodha sends the user after login, e.g.https://127.0.0.1for local development, or a real HTTPS endpoint you control for anything unattended. Must exactly match what you pass in code later. - App type — "Connect" for personal/algo use. - On creation you get: - API key (
api_key) — public identifier for your app - API secret (api_secret) — private, used to generate sessions, never expose this
Broker equivalents
- Upstox: developer console at
developer.upstox.com, OAuth2client_id/client_secret, redirect URI same idea. - Fyers:
myapi.fyers.in, app createsclient_id(app_id) andsecret_key. - Dhan: DhanHQ issues a long-lived access token directly from the web console (no separate app-creation OAuth dance for personal use) — this is simpler but means the token itself must be guarded even more carefully since it doesn't expire daily like Kite's.
Why this two-tier structure exists
The API key/secret identifies your *application*; the access token (chapter 9) identifies an authenticated *session* for a specific user. Separating them lets Zerodha revoke a compromised session without forcing you to recreate the whole app, and lets one app technically serve multiple users' logins (not relevant for a personal bot, but it's why the flow has this shape).
Checkpoint
You should have api_key and api_secret saved somewhere temporary (not committed anywhere yet — chapter 6 covers secure storage).
Before chapter 44's first live order, you also need: a static IP registered with your broker, and (if running unattended/automated, rather than manually clicking "confirm" per order) a Strategy ID from your broker's algo registration process — chapter 134 covers both in full, including what changes if you skip registration and try to trade manually-confirmed orders only.