> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ninjatrader.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ninjatrader.com/_mcp/server.

# Accept Trading Permission

POST https://demo.tradovateapi.com/v1/user/accepttradingpermission
Content-Type: application/json

### Accept a trading permission granted by another party.

**Available to:** All authenticated users

**Environments:** Demo, Live

**[Rate Limit](/api/authentication#request-rate-limits-and-time-penalties):** No endpoint-specific limit

Accepts a pending trading permission, transitioning its status from `Requested` to `Accepted`. A trading permission authorizes a CTA (commodity trading advisor) to trade on an account holder's behalf; accepting it is the step where the named CTA confirms the arrangement. Identify the permission with `tradingPermissionId` (the integer entity ID).

Only the CTA named on the permission can accept it — the request fails for any other caller. The permission must still be in `Requested` status; once it has moved to another status, it can no longer be accepted.

To find pending permissions and their IDs, query [tradingPermissionList](/api/rest-api-endpoints/users/trading-permission-list).

On success, the response returns the updated `tradingPermission` with its new status and an empty `errorText`. On a handled failure, the `tradingPermission` is still returned alongside a non-empty `errorText` describing the problem.

**Common Failure Scenarios**

- The permission is no longer in `Requested` status, so it is too late to accept it.
- The caller is not the CTA named on the permission (returns an access-denied error).
- The `tradingPermissionId` doesn't exist or isn't accessible to the caller.
- The access token is missing or invalid (returns `HTTP 401`).

**Error Messages**

| `errorText` | Trigger |
|-------------|---------|
| `"It is too late, the status has been changed"` | The permission is no longer in `Requested` status. |
| Non-empty `errorText` | The request failed; the field describes the reason. |

Reference: https://docs.ninjatrader.com/api/rest-api-endpoints/users/accept-trading-permission

## OpenAPI Specification

```yaml
openapi: 3.1.0
info:
  title: public
  version: 1.0.0
paths:
  /user/accepttradingpermission:
    post:
      operationId: acceptTradingPermission
      summary: Accept Trading Permission
      description: >-
        ### Accept a trading permission granted by another party.


        **Available to:** All authenticated users


        **Environments:** Demo, Live


        **[Rate
        Limit](/api/authentication#request-rate-limits-and-time-penalties):** No
        endpoint-specific limit


        Accepts a pending trading permission, transitioning its status from
        `Requested` to `Accepted`. A trading permission authorizes a CTA
        (commodity trading advisor) to trade on an account holder's behalf;
        accepting it is the step where the named CTA confirms the arrangement.
        Identify the permission with `tradingPermissionId` (the integer entity
        ID).


        Only the CTA named on the permission can accept it — the request fails
        for any other caller. The permission must still be in `Requested`
        status; once it has moved to another status, it can no longer be
        accepted.


        To find pending permissions and their IDs, query
        [tradingPermissionList](/api/rest-api-endpoints/users/trading-permission-list).


        On success, the response returns the updated `tradingPermission` with
        its new status and an empty `errorText`. On a handled failure, the
        `tradingPermission` is still returned alongside a non-empty `errorText`
        describing the problem.


        **Common Failure Scenarios**


        - The permission is no longer in `Requested` status, so it is too late
        to accept it.

        - The caller is not the CTA named on the permission (returns an
        access-denied error).

        - The `tradingPermissionId` doesn't exist or isn't accessible to the
        caller.

        - The access token is missing or invalid (returns `HTTP 401`).


        **Error Messages**


        | `errorText` | Trigger |

        |-------------|---------|

        | `"It is too late, the status has been changed"` | The permission is no
        longer in `Requested` status. |

        | Non-empty `errorText` | The request failed; the field describes the
        reason. |
      tags:
        - Users
      parameters:
        - name: Authorization
          in: header
          description: Bearer authentication
          required: true
          schema:
            type: string
      responses:
        '200':
          description: TradingPermissionResponse
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TradingPermissionResponse'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AcceptTradingPermission'
servers:
  - url: https://demo.tradovateapi.com/v1
    description: Demo
  - url: https://live.tradovateapi.com/v1
    description: Live
components:
  schemas:
    AcceptTradingPermission:
      type: object
      properties:
        tradingPermissionId:
          type: integer
          format: int64
      required:
        - tradingPermissionId
      title: AcceptTradingPermission
    TradingPermissionStatus:
      type: string
      enum:
        - Accepted
        - Approved
        - Declined
        - Requested
        - Revoked
      description: Accepted, Approved, Declined, Requested, Revoked
      title: TradingPermissionStatus
    TradingPermission:
      type: object
      properties:
        id:
          type: integer
          format: int64
        userId:
          type: integer
          format: int64
        accountId:
          type: integer
          format: int64
        accountHolderContact:
          type: string
        accountHolderEmail:
          type: string
        ctaContact:
          type: string
        ctaEmail:
          type: string
        status:
          $ref: '#/components/schemas/TradingPermissionStatus'
          description: Accepted, Approved, Declined, Requested, Revoked
        updated:
          type: string
          format: date-time
        approvedById:
          type: integer
          format: int64
      required:
        - userId
        - accountId
        - accountHolderContact
        - accountHolderEmail
        - ctaContact
        - ctaEmail
        - status
      title: TradingPermission
    TradingPermissionResponse:
      type: object
      properties:
        errorText:
          type: string
          description: Non-empty if the request failed
        tradingPermission:
          $ref: '#/components/schemas/TradingPermission'
      title: TradingPermissionResponse
  securitySchemes:
    bearer_access_token:
      type: http
      scheme: bearer

```

## Examples



**Request**

```json
{
  "tradingPermissionId": 1
}
```

**Response**

```json
{
  "errorText": "string",
  "tradingPermission": {
    "userId": 1,
    "accountId": 1,
    "accountHolderContact": "string",
    "accountHolderEmail": "string",
    "ctaContact": "string",
    "ctaEmail": "string",
    "status": "Accepted",
    "id": 1,
    "updated": "2024-01-15T09:30:00Z",
    "approvedById": 1
  }
}
```

**SDK Code**

```python
import requests

url = "https://demo.tradovateapi.com/v1/user/accepttradingpermission"

payload = { "tradingPermissionId": 1 }
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://demo.tradovateapi.com/v1/user/accepttradingpermission';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"tradingPermissionId":1}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://demo.tradovateapi.com/v1/user/accepttradingpermission"

	payload := strings.NewReader("{\n  \"tradingPermissionId\": 1\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://demo.tradovateapi.com/v1/user/accepttradingpermission")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"tradingPermissionId\": 1\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://demo.tradovateapi.com/v1/user/accepttradingpermission")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"tradingPermissionId\": 1\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://demo.tradovateapi.com/v1/user/accepttradingpermission', [
  'body' => '{
  "tradingPermissionId": 1
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://demo.tradovateapi.com/v1/user/accepttradingpermission");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"tradingPermissionId\": 1\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = ["tradingPermissionId": 1] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://demo.tradovateapi.com/v1/user/accepttradingpermission")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```