Setup guide · Zerodha & Dhan
Connect your broker.
It takes a few minutes.
QuantumCat runs on your own Zerodha, Dhan or Angel One account through the broker's official API. Here's exactly how to get your keys, sign in, and clear the one-time IP step so your orders go through. You'll do this once.
Zerodha (Kite Connect)
Create a Kite Connect app for an API key, point it at QuantumCat, then sign in with your normal Kite login.
Zerodha setup →Dhan
No app to build — generate an access token on Dhan's site and paste it in. IP registration is one click.
Dhan setup →Angel One (SmartAPI)
Create a SmartAPI app for a key, enable TOTP, then sign in with your client code and MPIN. No daily token to paste.
Angel One setup →Zerodha · Kite Connect
Set up your Zerodha account.
Zerodha's API is called Kite Connect. You'll create a small "app" on Zerodha's developer site to get an API key, point it at QuantumCat, and then sign in with the same Kite login you already use. You need an active Zerodha account with TOTP 2FA enabled.
-
Turn on Kite Connect
Go to
developers.kite.trade/signupand sign up, then create an app to get your API key. Zerodha bills Kite Connect per app (per API key), not per account — and historical data (candles, screeners, backtests) is a separate add-on on the same page. Check the current plans and prices on that page before subscribing.If everything says "Insufficient permission for that call": that is Kite telling you this API key's app isn't entitled to the call — not a login problem. Because entitlements are per app, the same Zerodha login can work on one machine and fail on another when the two use different API keys. QuantumCat now says this in plain words and links you to the right page.Which plan? QuantumCat is a live terminal (live ticks, charts, order-flow), so most traders want the paid data plan. You can start on the free plan to place orders, then upgrade for live data. Pricing is Zerodha's — check their current rates. -
Create an app & copy the keys
In My Apps → Create new app, give it any name, enter your Zerodha client ID, and set the Redirect URL to exactly
http://127.0.0.1:5678. Save. Zerodha shows you an API key and API secret — keep them handy.The redirect URL matters. It must behttp://127.0.0.1:5678— that's the local address QuantumCat listens on to catch the login. Any path after the port is fine; the host and port must match. -
Add the keys to QuantumCat
Open Settings → Brokers → Zerodha → Add keys and paste the API key and secret. They're stored in your macOS Keychain / Windows Credential Manager — never synced, never sent to us.
-
Sign in
Click Login with Zerodha. Your default browser opens Kite's own login page — type your user ID, password and TOTP there, never inside QuantumCat. Kite sends you back and the app captures the session. Kite tokens last one trading day.
First time with a new app: Kite asks you to approve access once — just say yes in the browser and sign in again.Optional Never sign in by hand again. Turn on full-auto daily sign-in (Settings) — store your Kite user ID, password and TOTP secret in your keychain and QuantumCat mints the daily token itself at launch. The TOTP secret is the long setup code from Kite's 2FA screen, not the 6-digit number.
-
Register your IP for order placement
Since 1 April 2025, SEBI requires order requests to come from an IP you've registered with your broker. Charts and data work from anywhere — only order placing is gated. Zerodha has no API for this, so it's a quick manual step, and QuantumCat walks you through it: it shows your current IP and opens the console.
On
developers.kite.trade→ Profile → IP whitelist, paste the IP (a second, backup IP is allowed), and Save. It goes live within a minute; place a small order to confirm.QuantumCat pops this up automatically the first time an order needs it — showing your IP, opening the console, and re-checking — so you're never guessing. More on the IP rule below.
Dhan
Set up your Dhan account.
Dhan is simpler — there's no app to create. You generate an access token on Dhan's site and paste it into QuantumCat. IP registration is a single click.
-
Generate an access token
Log in at
web.dhan.co→ My Profile → DhanHQ Trading APIs. The first time, click Request Access and refresh — access comes through in seconds. Then generate your access token, and note your Client ID.Tokens last 24 hours. A manually generated Dhan token is valid for one day (a SEBI rule), so you'll generate a fresh one each morning — or turn on full-auto below and forget about it. -
Paste it into QuantumCat
Open Settings → Brokers → Dhan → Sign in, paste the access token, and click Connect. QuantumCat checks it against Dhan and tracks the expiry, warning you before it lapses. The token stays in your keychain.
Optional Full-auto daily sign-in. Store your Dhan client ID, PIN and TOTP secret in your keychain and QuantumCat refreshes the token by itself each day — no more daily paste.
-
Register your IP — one click
The same SEBI IP rule applies, but Dhan has an API for it, so QuantumCat registers it for you: when an order needs it, click “Register this connection for orders.” Your primary slot is never overwritten, and brokers let you change a slot about once a week — so register from the connection you actually trade on.
Set up your Angel One account.
Angel One signs in with your client code, MPIN and a TOTP, plus an API key from SmartAPI. There's no browser redirect and no daily token to paste.
-
Create a SmartAPI app
Go to
smartapi.angelbroking.com, sign in with your Angel One credentials, and open MyApps to create an app. You'll get an API key — keep the page open, you'll paste it in a moment. -
Enable TOTP
On the same SmartAPI portal, enable TOTP for your account and save the secret when it's shown. Angel requires a fresh TOTP on every sign-in, so QuantumCat needs the secret to generate one — it is stored in your keychain and never leaves the machine.
Save the secret, not just the QR. The TOTP secret is shown once. If you only scan it into an authenticator app you'll have to reset TOTP to see it again. -
Sign in from QuantumCat
Open Settings → Brokers → Angel One → add keys, paste the API key, then Sign in with your client code, MPIN and the TOTP secret. QuantumCat generates the TOTP and mints the session itself.
Angel sessions expire at midnight. Angel's API session stays valid until 12 midnight rather than for a rolling 24 hours, so you sign in once per day. QuantumCat tracks the expiry and warns you before it bites an order. -
Register your IP
The same SEBI IP rule applies. Angel has no API to register it, so it's a manual entry in the SmartAPI portal — QuantumCat shows your current public address for copying, and re-reads it through Angel's own connection after sign-in to tell you if it has changed.
Angel One differs from the others in a few places — standing-trigger support and 20-level depth, for instance. QuantumCat models each broker as it actually behaves and disables what a broker can't do, with the reason: see brokers & sessions →
About the IP rule
(every broker).
This is the one part that trips people up, so here's the whole picture. Since 1 April 2025, SEBI requires API orders to come from an internet address (IP) you've registered with your broker.
Only orders are gated
Charts, live ticks, the option chain, your positions and P&L all work from any network. The IP rule applies only when you place an order — so you can watch and analyse from anywhere.
Changes apply ~weekly
Brokers accept an IP change roughly once a week, so register the connection you trade from most days. Dhan shows you when the slot can next change; Zerodha lets you keep a primary and a backup IP.
If your IP keeps moving
Mobile hotspots, CGNAT fiber and café Wi-Fi hand you a new IP often. Two fixes: a static IP from your ISP (a few hundred ₹/month), or QuantumCat's Permanent IP relay (Settings) — register that one fixed IP once and trade from anywhere, forever.
SEBI requires the registered IP to be used exclusively by you (or immediate family). QuantumCat pins its order traffic to IPv4 so the address the broker sees matches the one you registered — a small detail that quietly prevents a lot of “unregistered IP” rejections.
Your keys never leave your machine.
There's no QuantumCat server in the trade path. Your API keys and tokens live in your OS keychain (or an encrypted vault on your own server for the web app), and your password is only ever typed on the broker's own login page. Orders travel from your machine straight to Zerodha, Dhan or Angel One under your own credentials — your money and securities never move to us.
Setup questions, answered straight.
Do I have to pay Zerodha for the API?
Zerodha bills Kite Connect per app (per API key), not per account, and historical data — candles, screeners, backtests — is a separate add-on on the same page. Plans and prices change, so check developers.kite.trade for the current ones. Dhan sells Trading APIs and Data APIs separately; Angel One’s SmartAPI is free but gates calls by the segments your account is enabled for. If a broker refuses a call for lack of entitlement, QuantumCat now names the cause and the page to open instead of showing the broker’s raw error.
Why must my Zerodha redirect URL be http://127.0.0.1:5678?
That's the local address QuantumCat listens on to catch the login hand-off from Kite. Any path after the port is fine, but the host and port must match exactly. Nothing is sent anywhere — the redirect just lands back on your own machine.
My order was rejected with "unregistered IP". What now?
Your current IP isn't registered with the broker, or it changed since you registered. Open the IP step in QuantumCat, re-detect your IP, and register it again — one click on Dhan, or paste it into the Kite console on Zerodha. If it keeps happening, your IP is moving: use a static IP from your ISP or QuantumCat's Permanent IP relay so it never changes again.
Do I need to sign in every day?
Broker tokens expire daily — Kite each morning, Dhan every 24 hours. That's a broker/SEBI rule, not a QuantumCat one. Turn on full-auto daily sign-in and QuantumCat mints a fresh token by itself at launch, so there's nothing to do each morning.
Where are my keys and tokens stored?
In your operating system's secure store — macOS Keychain or Windows Credential Manager — and, for the self-hosted web app, an encrypted vault on your own server. They're never synced and never sent to QuantumCat. Your broker password is only ever entered on the broker's own page.
Is any of this against the rules?
No. You're using your own broker's official, sanctioned API on your own account, within the broker's rate limits. The IP registration and daily token are the exact SEBI-mandated controls, and QuantumCat is built around them. Manual trading and personal automation on your own account are ordinary API use — read your broker's API terms if you plan to run bots.