What VEXA can do with your broker connection

VEXA reads your trade history and nothing else. It cannot place, cancel or modify an order, and it cannot move money.

Same on every platform Updated

What this does

VEXA’s access to your broker is read-only. It imports closed trades and account history so it can score your psychology and show you your numbers. It has no ability to place an order, cancel one, change one, or withdraw funds. This is the position stated in the VEXA Privacy Policy, section 4.1: VEXA requests read-only access to your trading history, never stores your broker login credentials, and never executes trades on your behalf.

If you take one thing from this section, take that.

Before you start

  • This is true for every connection type: an API key, an OAuth token, an Interactive Brokers Flex token, an uploaded CSV or statement, and the MetaTrader bridge.
  • Where a broker lets you choose permissions when you create an API key, VEXA’s own setup instructions tell you to enable reading only and to leave trading and withdrawal switched off. Follow them. A key with trading rights would still never be used to trade, but there is no reason to hand one over.
  • VEXA never asks for your broker password. Connections use API keys, OAuth tokens or file uploads.

What VEXA reads

Connection typeWhat VEXA reads
Direct API syncClosed trades, executions, positions and account identifiers
CSV or statement uploadOnly the file you upload
MetaTrader 4 / 5 bridgeClosed deals and orders from the terminal

Your broker account identifiers are stored. Your broker login is not.

The three things people expect and do not get

  • VEXA cannot trade for you. There is no copy-trading, no signals, no managed accounts, no auto-execution.
  • The MetaTrader bridge does not trade either. The Expert Advisor reads closed deals and orders out of your terminal and sends them to VEXA. It places nothing.
  • Sentinel’s “Block Trades” rule action does not block anything at your broker. It is a message. Sentinel is not connected to your broker and cannot prevent an order. It tells you to stop, and stopping is still your decision. See Is VEXA legit? Brand and impersonation for why this distinction matters.

How credentials are held

API keys, OAuth tokens and Flex tokens are encrypted with AES-256-GCM before they are stored, and they are decrypted only inside VEXA’s servers when a sync runs. They are stripped out of your data export on purpose, so a shared export file can never leak them. More in How VEXA protects your data.

Steps

To cut VEXA’s access completely, remove the broker account in VEXA and revoke the key at your broker.

  1. In the sidebar, select View Profile under your name.
  2. Open Connected Brokers.
  3. Select the trash icon on the account you want to remove.
  4. Sign in to your broker and delete or revoke the API key you gave VEXA.
  1. On Home, tap the avatar at the top right.
  2. Open Connected Services.
  3. Tap the account, then Delete Account.
  4. Sign in to your broker and delete or revoke the API key you gave VEXA.
  1. In the sidebar, tap the profile chip at the bottom, then View Profile.
  2. Open Connected Services.
  3. Tap the account, then Delete Account.
  4. Sign in to your broker and delete or revoke the API key you gave VEXA.
  1. On Home, tap the avatar at the top right.
  2. Open Connected Brokers.
  3. Tap the delete icon on the account you want to remove.
  4. Sign in to your broker and delete or revoke the API key you gave VEXA.
  1. In the sidebar, tap the profile chip at the bottom showing your name.
  2. Open Connected Brokers.
  3. Remove the account you no longer want synced.
  4. Sign in to your broker and delete or revoke the API key you gave VEXA.

What you should see

The broker account disappears from your broker list and stops syncing. Trades already imported stay in VEXA, because they are your records now. If you want those gone as well, see Delete your VEXA account.

If it doesn’t work

  • The account is still listed after you removed it. Reload the screen. If it returns, remove it again from the surface you originally connected on.
  • Your broker still shows the key as active. Removing the account in VEXA does not revoke the key at your broker. Revoke it in your broker’s API settings as well.

Related

Still stuck? Email support@vexatrade.ai.