Generate the login URL, manual login flow

Kite Connect uses an OAuth-like flow: you (a human) log in via a browser once per day; the app then holds a token for the rest of the day.

Generate the login URL

# auth/session.py
from kiteconnect import KiteConnect
from config import API_KEY

kite = KiteConnect(api_key=API_KEY)
print(kite.login_url())
# -> https://kite.zerodha.com/connect/login?api_key=xxx&v=3

Manual flow (for learning / semi-manual bots)

  1. Run the snippet above, copy the printed URL into a browser.
  2. Log in with your Zerodha client ID, password, and 2FA (TOTP/PIN).
  3. Zerodha redirects you to your app's redirect URL (chapter 4) with a request_token query parameter appended, e.g.: `` https://127.0.0.1/?request_token=abcXYZ123&action=login&status=success ``
  4. Copy the request_token value — you'll exchange it for an access token in chapter 9.

This manual copy-paste step is fine while learning. Chapter 10 covers automating it for daily unattended runs (as far as Kite allows — Zerodha does not support fully headless login due to mandatory 2FA, so most production bots either automate the browser step with a saved TOTP seed, or accept a once-a-day manual step).

Why a redirect-based flow at all

The broker never wants your password. The redirect flow means your credentials are typed only into Zerodha's own login page; your app only ever sees a short-lived, single-use request_token — even if your app is compromised, the attacker can't recover your password from it.

Next: 008 — Handle the redirect and request token