Interactive Brokers API setup for Firefly: a trading-only key in 20 minutes + IBKR approvals.
Interactive Brokers gives Nova options, portfolio margin and global markets. Its API setup is more involved than Alpaca's — IBKR authenticates sessions rather than issuing a simple key — so we do most of it with you on the call.
Screens change. This guide was checked in October 2026; the broker's own docs are linked below. Never share a key by chat or email — use the onboarding form.
- An IBKR Pro individual account with trading permissions for US stocks and, if wanted, options
- Two-factor authentication (IBKR Mobile) on the login
- A paper-trading account enabled in Client Portal (Settings › Paper Trading Account)
In Client Portal go to Settings › Account Settings › Paper Trading Account and request one. It mirrors your live permissions and is where Nova starts.
Settings › Users & Access Rights › Add User. Give it trading and account-read rights only, no funding or banking rights. This is the login Nova's gateway session uses.
Under Trading Permissions confirm US stocks and, if you want option strategies, the options approval level for defined-risk spreads.
We start the IBKR gateway session with the API user and your 2FA approval, confirm read-only calls succeed, and set capital and the drawdown limit. The session re-authenticates on IBKR's schedule; you approve on your phone.
Permissions: what the key may and may not do
Grant
- Trading (stocks, options as approved)
- Account and portfolio read
Never grant
- Funding, withdrawals and banking rights on the API user — leave unticked
- Permission to change account settings
Share securely
Paste the credentials into the onboarding form we send after the call (encrypted at rest, visible only to the onboarding engineer). We confirm connectivity on the call and you watch the first read-only calls succeed before any order is placed. Rotate the key at the broker at any time — Firefly stops the moment it is revoked.
Troubleshooting
Session expired / needs re-authentication
IBKR ends API sessions daily and weekly. Approve the 2FA prompt on IBKR Mobile; if it keeps failing, the API user's 2FA device needs re-pairing.
No trading permission for options
Options need a separate approval under Trading Permissions; apply in Client Portal, usually approved within a day or two.
Paper account missing
Paper accounts are created on request and take a few hours; live permissions are copied at creation, so request it after permissions are set.
Key created? Book the onboarding call.
Thirty minutes: we connect, set capital and risk limits, and you watch the first read-only calls succeed.