# Access Denied for Place Order API

**URL:** <https://community.tradovate.com/t/access-denied-for-place-order-api/4333>\
**Category:** Community Support\
**Created:** [March 31, 2022, 7:32pm UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333 "2022-03-31T19:32:25Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Idris\_Iqbal\_Tarwala](https://avatars.discourse-cdn.com/v4/letter/i/57b2e6/32.png) [@Idris\_Iqbal\_Tarwala](https://community.tradovate.com/u/Idris_Iqbal_Tarwala)\
**Post date:** [March 31, 2022, 7:32pm UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333/1 "2022-03-31T19:32:26Z")

</div>

Hi,  
I am running into Access Denied for my place order API request.

```
def __init__ (self) -> None:
    self.contracts = int(os.environ.get("CONTRACTS","2"))
    self.access_token = ""
    self.url="https://demo.tradovateapi.com"
    self.route_access_token = "/v1/auth/accesstokenrequest"
    self.route_place_order = "/v1/order/placeorder"
    self.route_contractFind = "/v1/contract/find"
    pass

def open_long_position(self):
    self.get_access_token()
    payload = {
        "accountSpec" : ***,
        "accountId" : ***,
        "action" : "Buy",
        "symbol" : "MESM2",
        "orderQty" : self.contracts,
        "orderType" : "Market",
        "isAutomated": True 
    }
    headers = {
        "Content-Type" : "application/json",
        "Authorization": f"Bearer {self.access_token}",
    }
    try:
        response = http.post(url=f"{self.url}{self.route_place_order}",data=json.dumps(payload),headers=headers)
        if response.status_code == 200:
            print(f"Response {response.status_code} : {response.json()}")
        else:
            print(f"Response {response.status_code} : {response.text}")
    except Exception as e:
        print(e)
        self.access_token = ""
        pass
    pass

```

Response :- Response 200 : {‘failureReason’: ‘UnknownReason’, ‘failureText’: ‘Access is denied’}

---

<div class="post-metadata">

**Author:** ![Alexander](https://sea1.discourse-cdn.com/flex015/user_avatar/community.tradovate.com/alexander/32/988_2.png) [@Alexander](https://community.tradovate.com/u/Alexander)\
**Post date:** [March 31, 2022, 8:17pm UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333/2 "2022-03-31T20:17:11Z")

</div>

Please check on the permissions for your API Key - check to see that Orders has full access. The other thing that you should make sure you do is generate a device ID for your application and use it when you request access in the `deviceId` field. SHA-256 hashes are a great way to identify a device but you need to ensure that your device ID is the same every time for the same device - eg. when I log in on PC `A` I want the device ID to be the same every time, but unique compared to PC `B`.

---

<div class="post-metadata">

**Author:** ![Idris\_Iqbal\_Tarwala](https://avatars.discourse-cdn.com/v4/letter/i/57b2e6/32.png) [@Idris\_Iqbal\_Tarwala](https://community.tradovate.com/u/Idris_Iqbal_Tarwala)\
**Post date:** [March 31, 2022, 8:20pm UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333/3 "2022-03-31T20:20:36Z")

</div>

![Screen Shot 2022-03-31 at 1.19.00 PM](https://us1.discourse-cdn.com/flex015/uploads/tradingforum/original/2X/5/5d7aaf73a8fe452c61e15cf546ff62846dad4997.png)  
I think have all the permissions setup correctly. Regarding the “deviceId”, I dont see any field in the place order payload for the deviceId field.

> **[Tradovate API](https://api.tradovate.com/#operation/placeOrder)**
>
> Documentation for the Tradovate API.

I am able to get the access\_token fine just not able to place the trade

---

<div class="post-metadata">

**Author:** ![Alexander](https://sea1.discourse-cdn.com/flex015/user_avatar/community.tradovate.com/alexander/32/988_2.png) [@Alexander](https://community.tradovate.com/u/Alexander)\
**Post date:** [April 1, 2022, 1:37pm UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333/4 "2022-04-01T13:37:10Z")

</div>

Typically it’s more of an issue when users change from sim to live, but the device ID often contributes to this issue. `deviceId` is a field that you can include as part of the request body to `/auth/accessTokenRequest`. Its purpose is to identify the device using the current access token. This is very strictly enforced in the LIVE environment, but can still come up in the simulation mode. Just pass an ID that is the same for a given device each time, but unique from device to device.

One other thing to check on - make sure you are using your account entity ID for the `accountId` field. You need to call `/account/list` or some other account-retrieving operation to find your account’s entity ID, it doesn’t come with the access token.

---

<div class="post-metadata">

**Author:** ![Kart](https://avatars.discourse-cdn.com/v4/letter/k/87869e/32.png) [@Kart](https://community.tradovate.com/u/Kart)\
**Post date:** [April 29, 2022, 2:34am UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333/5 "2022-04-29T02:34:07Z")

</div>

Thank you for your help.

I have the similar issue. Response :- Response 200 : {‘failureReason’: ‘UnknownReason’, ‘failureText’: ‘Access is denied’}

am using demo api url. All permission setting are done, accountId was taken from /account/list.  
{

“accountSpec”: “DEMO\*\*\*\*\*\*”,

“accountId”: 7\*\*\*\*,

“action”: “Buy”,

“symbol”: “MNQM2022”,

“orderQty”: 1,

“orderType”: “Market”,

“isAutomated”: true

}  
what should be in the place of accountSpec: yourUserName. I tired with my Trodovate login username, it didn’t work. is any other suggestion to consider?

Appreciate your help!

---

<div class="post-metadata">

**Author:** ![Alexander](https://sea1.discourse-cdn.com/flex015/user_avatar/community.tradovate.com/alexander/32/988_2.png) [@Alexander](https://community.tradovate.com/u/Alexander)\
**Post date:** [April 29, 2022, 1:10pm UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333/6 "2022-04-29T13:10:33Z")

</div>

You can use the `name` field from the `accessTokenRequest` response for `accountSpec`.

---

<div class="post-metadata">

**Author:** ![Kart](https://avatars.discourse-cdn.com/v4/letter/k/87869e/32.png) [@Kart](https://community.tradovate.com/u/Kart)\
**Post date:** [April 29, 2022, 2:08pm UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333/7 "2022-04-29T14:08:57Z")

</div>

Sorry it didn’t help, still failure message. name which i am getting from accesstokenrequest is the same username which am using to login.

any other suggestion please?

---

<div class="post-metadata">

**Author:** ![Kart](https://avatars.discourse-cdn.com/v4/letter/k/87869e/32.png) [@Kart](https://community.tradovate.com/u/Kart)\
**Post date:** [April 29, 2022, 2:33pm UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333/8 "2022-04-29T14:33:01Z")

</div>

got it fixed, the issue was with the symbol. changed from MNQM2022 to MNQM2.

Thank you for your help!

---

<div class="post-metadata">

**Author:** ![Alexander](https://sea1.discourse-cdn.com/flex015/user_avatar/community.tradovate.com/alexander/32/988_2.png) [@Alexander](https://community.tradovate.com/u/Alexander)\
**Post date:** [April 29, 2022, 2:36pm UTC](https://community.tradovate.com/t/access-denied-for-place-order-api/4333/9 "2022-04-29T14:36:44Z")

</div>

🤦‍♂️ I should’ve seen that right away, my apologies. That’s how we format the symbols, with a single trailing digit for the year.
