Generate the login URL, manual login flow
Kite Connect uses an OAuth-like flow: you (a human) log in via a browser once per day; the app then holds a token for the rest of the day.
Generate the login URL
# auth/session.py
from kiteconnect import KiteConnect
from config import API_KEY
kite = KiteConnect(api_key=API_KEY)
print(kite.login_url())
# -> https://kite.zerodha.com/connect/login?api_key=xxx&v=3
Manual flow (for learning / semi-manual bots)
- Run the snippet above, copy the printed URL into a browser.
- Log in with your Zerodha client ID, password, and 2FA (TOTP/PIN).
- Zerodha redirects you to your app's redirect URL (chapter 4) with a
request_tokenquery parameter appended, e.g.: ``https://127.0.0.1/?request_token=abcXYZ123&action=login&status=success`` - Copy the
request_tokenvalue — you'll exchange it for an access token in chapter 9.
This manual copy-paste step is fine while learning. Chapter 10 covers automating it for daily unattended runs (as far as Kite allows — Zerodha does not support fully headless login due to mandatory 2FA, so most production bots either automate the browser step with a saved TOTP seed, or accept a once-a-day manual step).
Why a redirect-based flow at all
The broker never wants your password. The redirect flow means your credentials are typed only into Zerodha's own login page; your app only ever sees a short-lived, single-use request_token — even if your app is compromised, the attacker can't recover your password from it.