How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Saxo Bank Apps API

Provides OAuth app secrets related endpoints

Saxo Bank Apps API is one of 80 APIs that Saxo Bank publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Application. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, authentication docs, rate-limit docs, and tutorials.

This API exposes 16 operations across 7 paths, and defines 19 schemas. It is described by OpenAPI 3.0.1, at version 2.4.138+710c760591.

Requests are made against a single base URL, https://gateway.saxobank.com/sim/openapi.

16 operations 7 paths 19 schemas 3 DELETE7 GET3 PATCH3 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.1
API Version
2.4.138+710c760591
Base URL
https://gateway.saxobank.com/openapi
Authentication
HTTP Bearer, OAuth 2.0
Resource Areas
1

Authentication & Security 2

Saxo Bank Apps API declares 2 security schemes for authenticating requests. It accepts HTTP bearer tokens (JWT) (OpenApiJWTSecurityScheme). It supports OAuth 2.0 (OpenApiOAuthSecurityScheme) using the authorizationCode flow.

Paths & Operations 16

Across 7 paths, the API surfaces 16 operations — 3 DELETE, 7 GET, 3 PATCH, 3 POST. Each is listed below with its method, path, parameters, and response codes.

Apps 16

Provides OAuth app secrets related endpoints

GET
/developer/apps/resource/{AppKey}
Returns requested resource by appKey
DeveloperAppGetResourceByAppKey 1 param → 200403400401503429
GET
/developer/apps/{AppKey}
Get app by appKey
DeveloperAppGetAppByAppKey 1 param → 200403400401503429
DELETE
/developer/apps/{AppKey}
Deletes an app
DeveloperAppDeactivateApp 1 param → 204403400401503429
PATCH
/developer/apps/{AppKey}
Updates an app
DeveloperAppUpdateApp 1 param body → 204403400401503429
GET
/developer/apps
Gets the apps owned by the client of the user
DeveloperAppGetApps 3 params → 200403400401503429
POST
/developer/apps
Create a app
DeveloperAppCreateApp body → 201400403401503429
GET
/developer/apps/{AppKey}/redirecturis/{RedirectUriId}
Gets a redirect uri by id
DeveloperRedirectGetRedirectUriFromId 6 params → 200404403400401503429
DELETE
/developer/apps/{AppKey}/redirecturis/{RedirectUriId}
Deletes a redirect uri
DeveloperRedirectDeleteRedirectUri 2 params → 204404403400401503429
PATCH
/developer/apps/{AppKey}/redirecturis/{RedirectUriId}
Updates a redirect uri
DeveloperRedirectUpdateRedirectUri 2 params body → 204200404403400401503429
GET
/developer/apps/{AppKey}/redirecturis
Gets redirect uris for a given app
DeveloperRedirectGetRedirectUris 4 params → 200404403400401503429
POST
/developer/apps/{AppKey}/redirecturis
Creates a redirect uri
DeveloperRedirectCreateRedirectUri 1 param body → 201403400401503429
GET
/developer/apps/{AppKey}/secrets/{SecretId}
Gets a secret by id
DeveloperSecretGetSecretById 2 params → 200204403404400401503429
DELETE
/developer/apps/{AppKey}/secrets/{SecretId}
Deletes a secret
DeveloperSecretDeleteSecret 2 params → 204403404400401503429
PATCH
/developer/apps/{AppKey}/secrets/{SecretId}
Update an app secret
DeveloperSecretUpdateSecret 2 params body → 204200403400401503429
GET
/developer/apps/{AppKey}/secrets
Gets secrets for a given app
DeveloperSecretGetSecrets 4 params → 200404403400401503429
POST
/developer/apps/{AppKey}/secrets
Create an app secret
DeveloperSecretCreateSecret 1 param body → 201403400401503429

Schemas 19

The contract defines 19 schemas that model the data the API accepts and returns. The most detailed are AppDto (12 properties), AppResourceDto (12 properties), AppCreationRequest (5 properties), AppRedirectDtoListResult (4 properties). Each schema is shown below with its type and property counts.

AppSecretDtoListResult
object
4 properties
AppUpdateRequest
object
2 properties
AppStatus
string
AppRedirectDto
object
4 properties
AppCreationRequest
object
5 properties 3 required
AppRedirectUriCreationRequest
object
3 properties 1 required
EndpointDto
object
2 properties
RedirectUriUpdateRequest
object
3 properties
AppRedirectUriResponse
object
2 properties
AppSecretDto
object
4 properties
SecretCreationRequest
object
2 properties 2 required
AppDtoListResult
object
4 properties
BrandingDto
object
3 properties
UserDto
object
2 properties
ModelStateDictionary
object
AppDto
object
12 properties
SecretUpdateRequest
object
3 properties
AppRedirectDtoListResult
object
4 properties
AppResourceDto
object
12 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

saxo-apps-api-openapi.yml Raw ↑

Other APIs Saxo Bank publishes across the network.

Saxo Bank FIX Trading API
Saxo Bank Account Values API
Saxo Bank AccountGroups API
Saxo Bank Accounts API
Saxo Bank AlgoStrategies API
Saxo Bank Allocation Keys API
Saxo Bank Audit - OrderActivities API
Saxo Bank Balances API
Saxo Bank Cash Management - Beneficiary Instructions API
Saxo Bank CashManagement - Cash Withdrawal API
Saxo Bank CashManagement - Cash Withdrawal Limits API
Saxo Bank CashManagement - Inter Account Transfer API
Where this information came from

This is an independent, third-party profile of Saxo Bank Apps API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.