Zerodha API setup for Firefly: a trading-only key in 15 minutes + Zerodha approval.
Kite Connect has a free Personal plan for trading on your own account, which is what Firefly needs; the paid Connect plan (₹500 a month at the time of writing, billed by Zerodha) adds historical data and is not required. You create an app on the developer portal and share the key and secret on the onboarding call.
Screens change. This guide was checked in September 2026; the broker's own docs are linked below. Never share a key by chat or email — use the onboarding form.
- An active Zerodha account with KYC complete
- A Zerodha developer account at developers.kite.trade (same login)
- TOTP enabled on your Kite login
Log in at developers.kite.trade with your Kite credentials and accept the developer agreement.
Create new app and choose the Personal type (free; your own client ID only). App name Firefly, Zerodha client ID = your own, redirect URL as given on the call, postback URL left blank. Personal apps are approved automatically.
The app page shows the API key and, behind a reveal, the API secret. The secret is shown once per reveal; copy it somewhere safe until the call.
Kite Connect issues a token that expires every day; Firefly handles the daily login with your key and secret plus a TOTP. Set up TOTP on Kite under My profile › Password & security if you have not already.
Permissions: what the key may and may not do
Grant
- Orders (place, modify, cancel)
- Portfolio, positions, margins (read)
Never grant
- Fund transfers — not offered on Kite Connect; nothing to disable
Share securely
Paste the credentials into the onboarding form we send after the call (encrypted at rest, visible only to the onboarding engineer). We confirm connectivity on the call and you watch the first read-only calls succeed before any order is placed. Rotate the key at the broker at any time — Firefly stops the moment it is revoked.
Troubleshooting
Redirect mismatch
The redirect URL must match exactly, including https:// and the trailing slash.
Token invalid after midnight
Expected — Kite tokens expire daily. If Firefly reports repeated login failures, the TOTP secret has probably changed; send the new one.
Personal app limits
A Personal app works only for the client ID it was created with — which is exactly the Firefly model: one account, one key.
Key created? Book the onboarding call.
Thirty minutes: we connect, set capital and risk limits, and you watch the first read-only calls succeed.