Capital.com Public API Session API

Operations for creating, switching, and ending API sessions.

OpenAPI Specification

capital-com-public-api-session-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Capital.com REST Accounts Session API
  description: The Capital.com REST API provides programmatic access to the Capital.com trading engine, including positions, working orders, deal confirmations, account information, account switching, transaction history, account preferences (leverage, hedging mode), market navigation, instruments, and historical price data. Authentication uses an API key plus login credentials to create a session that returns CST and X-SECURITY-TOKEN headers, which expire after ten minutes of inactivity.
  version: v1
  contact:
    name: Capital.com API Support
    url: https://open-api.capital.com
servers:
- url: https://api-capital.backend-capital.com
  description: Capital.com production REST API server
- url: https://demo-api-capital.backend-capital.com
  description: Capital.com demo (sandbox) REST API server
security:
- apiKey: []
  sessionToken: []
  securityToken: []
tags:
- name: Session
  description: Operations for creating, switching, and ending API sessions.
paths:
  /api/v1/session/encryptionKey:
    get:
      operationId: getEncryptionKey
      summary: Get Encryption Key
      description: Returns the public encryption key used to encrypt the session password.
      tags:
      - Session
      responses:
        '200':
          description: Encryption key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericObject'
  /api/v1/session:
    get:
      operationId: getSession
      summary: Get Session Details
      description: Returns details of the currently active API session.
      tags:
      - Session
      responses:
        '200':
          description: Session details
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericObject'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createSession
      summary: Create New Session
      description: Authenticates with API key and login credentials to create a new session.
      tags:
      - Session
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GenericObject'
      responses:
        '200':
          description: Session created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericObject'
        '401':
          $ref: '#/components/responses/Unauthorized'
    put:
      operationId: switchAccount
      summary: Switch Active Account
      description: Switches the active account associated with the current session.
      tags:
      - Session
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GenericObject'
      responses:
        '200':
          description: Account switched
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericObject'
    delete:
      operationId: logOutSession
      summary: Log Out Session
      description: Terminates the current API session.
      tags:
      - Session
      responses:
        '200':
          description: Session terminated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericObject'
components:
  schemas:
    GenericObject:
      type: object
      description: Generic JSON object response.
      additionalProperties: true
    Error:
      type: object
      description: Generic error response.
      properties:
        errorCode:
          type: string
        message:
          type: string
      additionalProperties: true
  responses:
    Unauthorized:
      description: Authentication credentials are missing or invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: X-CAP-API-KEY
      description: Capital.com API key required for all calls.
    sessionToken:
      type: apiKey
      in: header
      name: CST
      description: Client session token returned after creating a session.
    securityToken:
      type: apiKey
      in: header
      name: X-SECURITY-TOKEN
      description: Security token returned after creating a session.
externalDocs:
  description: Capital.com Public API Documentation
  url: https://open-api.capital.com
x-generated-from: https://open-api.capital.com
x-generated-by: claude-crawl-2026-05-08