How does REST access to an MT4 or MT5 server work?
CPlugin WebAPI turns the MetaTrader Manager API, a Windows-only native library, into a JSON REST interface plus a realtime SignalR hub. Your code sends ordinary HTTPS requests with an OAuth 2.0 bearer token; WebAPI reaches your MT4 or MT5 server through a manager account that you register once in Toolbox.
The short version
- You register your trade platform in Toolbox with the address and credentials of a manager account on your server.
- You create an API client in Toolbox and receive a client id and a client secret.
- Your code exchanges the id and secret for a bearer token (OAuth 2.0, Client Credentials flow), then calls
https://cloud.mywebapi.com/api/v2/…with that token. - For streaming you connect to a SignalR hub with the same token and subscribe to ticks, margin updates, online users or open orders.
Why a layer in front of the Manager API
The native Manager API has to be hosted in your own Windows process, and the realtime plumbing around it (reconnects, queueing, retries) is yours to write. WebAPI runs that part for you. It is built on top of MetaQuotes' Manager API, so a manager account on your server is always required. See also MT5 Manager API over REST.
REST
Requests and responses are JSON, rooted at https://cloud.mywebapi.com and versioned in the path. Every v2 response has the same envelope: { data, error, meta }.
curl https://cloud.mywebapi.com/api/v2/MT4/{tradePlatform}/ServerTime \
-H "Authorization: Bearer $ACCESS_TOKEN"
{tradePlatform} is the id Toolbox gives to the MT4 or MT5 server you registered. The full list of operations, with request and response schemas, is in the v2 OpenAPI document.
How much of each platform is covered
| v1 | v2 | |
|---|---|---|
| MT4 operations | 42 | 147 |
| MT5 operations | 55 | 12 |
v2 is the recommended surface for MT4. For MT5, v2 covers reads (server time, managers, users, groups, symbols, positions, orders and deals by group) and partial updates of user, group and symbol records; dealing, balance operations, account creation and password changes are still v1-only. The counts are read from the live API specification on every site build. Details: WebAPI documentation.
Realtime
Realtime data comes over SignalR (Web Sockets, with Long Polling and other transports as fallback), so updates arrive after you subscribe and you do not poll. The official SDKs wrap the hub in typed helpers and reconnect for you.
What happens when the server is slow
Every request addressed to a trade platform has a deadline, from 5 seconds for a trade operation to 60 seconds for server maintenance, and you can set your own with the X-Request-Timeout header. A timed-out trade or change returns OutcomeUnknown, which does not mean it failed. To repeat such an operation safely, send an Idempotency-Key header and repeat the same request with the same key. The rules are in Timeouts and retries.
Try it without cost
The Sandbox at pre.mywebapi.com is a full copy of production with no billing and no SLA. Billing starts only when you connect to production. See what it costs.

