Security
Facts as of 03.10.2026.
Your API key
A key starts with adk_live_ or adk_test_. It is shown once, when it is made; we keep only a SHA-256 fingerprint of it, so nobody on our side can read it back. A lost key is replaced by a rotation, which retires the old one.
The key belongs on your server. The route that takes it, POST /v1/tokens, refuses to be called from a web page (cross-origin), and so does the MCP server, whose get_candles tool takes it too.
Tokens and the stream
Your server trades the key for a token per end user, valid 12 hours. A token names the key that made it: rotating the key retires every token it made.
A browser holds a token, never the key. The /v1 routes a web page may call answer only pages whose origin a customer account has declared, and never with cookies or other credentials. The live stream opens with a single-use ticket, offered as a subprotocol and never in the URL.
Cutting off a key
A key cut off from your account page is refused from its next request for a token or for candles. A stream ticket, and streams still open, follow within the delay the account page states once you confirm; the same delay applies to a rotation.
Blocking an account cuts its key off too. A key cut off cannot be turned back on from the account page: getting back in goes through support. Deleting an account cuts its key off for good.
Your account
Passwords are stored hashed (PBKDF2-SHA256). Two-factor authentication (an authenticator app) can be turned on from your account page, with ten single-use recovery codes; turning it on or off signs out every other session.
Our staff accounts cannot sign in through api.adona-robot.com. We test the API with a data account of our own, whose id starts with ops-: it is never billed, and it is kept out of the capacity and connection figures.
Card payments go through Stripe's own page: the card number never reaches our servers.
Hosting
Who hosts our servers is in the legal notice; what leaves them, and where to, is on the privacy page.
Report a vulnerability
Write to support@adona-robot.com. The same address is in our security.txt.