> ## Documentation Index
> Fetch the complete documentation index at: https://takeprofit.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List securities available on an exchange

> Every publicly served security of one exchange, with the `symbol` to use in the other
endpoints and the original exchange-listed `sourceSymbol`.

**Cost:** 1000 credits per request (flat).




## OpenAPI

````yaml /platform-api/specs/openapi.yaml get /api/v1/marketdata/exchanges/{exchange}/securities
openapi: 3.0.3
info:
  title: TakeProfit API (REST)
  version: 0.6.0
  contact:
    email: support@takeprofit.com
  description: |
    Historical marketdata and the security catalog over REST. Live streams
    (candles, volume footprint, order books) are served over WebSocket and
    described by the AsyncAPI document at
    `https://public-api.takeprofit.com/api/v1/marketdata/asyncapi.yaml`.
    Guides (getting an API key, credits and quota, errors) live at
    [takeprofit.com/docs](https://takeprofit.com/docs).

    ## Requests

    - Base URL: `https://public-api.takeprofit.com`.
    - Every endpoint answers `GET` only.
    - Authenticate with the `x-api-key` header; exactly one header value is
      required.
    - Unknown query parameters and repeated scalar parameters are rejected
      with 400.
    - Identify securities with `exchange` and `symbol` as returned by the
      catalog endpoints; internal ids and GUIDs are not accepted (search
      additionally accepts an ISIN as a lookup key).

    ## Credits and quota

    Requests are metered in credits against a fixed quota window of 100000
    credits per 60 seconds, shared by all API keys of the account. Each
    operation states its price; every billed request costs at least 1000
    credits, so an account makes at most 100 requests per minute. Every
    authenticated response carries the window state:

    - `X-RateLimit-Limit` - credits per window;
    - `X-RateLimit-Remaining` - credits still available after this request;
    - `X-RateLimit-Reset` - epoch second the window resets at.

    A request the remaining credits cannot cover is rejected with 429 and
    `Retry-After` (seconds until the window resets); the rejection itself is
    free.

    ## Errors

    Every error response is `{"error": {"code": "<stable code>", "message":
    "<human-readable text>"}}`. The statuses listed on each operation (400,
    401, 403, 404, 429) are the outcomes a client handles explicitly. A 400
    is either `invalid_argument` (a malformed request) or `too_much_data`: the
    request produces more data than can be served in one response, and only a
    narrower window fixes it - it is never a rate limit. In
    addition, any operation can answer 502 (`bad_gateway`), 503
    (`unavailable`) or 504 (`deadline_exceeded`) while the gateway or an
    upstream is unavailable or slow; these are transient - retry with
    exponential backoff.
servers:
  - url: https://public-api.takeprofit.com
    description: Production
security: []
paths:
  /api/v1/marketdata/exchanges/{exchange}/securities:
    get:
      tags:
        - Securities
      summary: List securities available on an exchange
      description: >
        Every publicly served security of one exchange, with the `symbol` to use
        in the other

        endpoints and the original exchange-listed `sourceSymbol`.


        **Cost:** 1000 credits per request (flat).
      operationId: listExchangeSecurities
      parameters:
        - name: exchange
          in: path
          required: true
          schema:
            $ref: '#/components/schemas/ExchangeCode'
      responses:
        '200':
          description: Security list.
          headers:
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecuritiesResponse'
        '400':
          $ref: '#/components/responses/InvalidRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
      security:
        - ApiKeyAuth: []
components:
  schemas:
    ExchangeCode:
      type: string
      description: TakeProfit exchange code as returned by /api/v1/marketdata/exchanges.
      example: BATS
    SecuritiesResponse:
      type: object
      required:
        - exchange
        - securities
      properties:
        exchange:
          $ref: '#/components/schemas/SecurityExchange'
        securities:
          type: array
          items:
            $ref: '#/components/schemas/Security'
      example:
        exchange:
          code: BATS
          name: CBOE BZX U.S. EQUITIES EXCHANGE
          timezone: America/Chicago
        securities:
          - symbol: AAPL
            name: Apple Inc.
            sourceSymbol: AAPL
            isin: US0378331005
          - symbol: MSFT
            name: Microsoft Corporation
            sourceSymbol: MSFT
            isin: US5949181045
    SecurityExchange:
      type: object
      required:
        - code
      properties:
        code:
          $ref: '#/components/schemas/ExchangeCode'
        name:
          type: string
        timezone:
          type: string
          description: >-
            IANA timezone of the marketdata (candle boundaries), not the
            exchange location.
          example: America/Chicago
    Security:
      type: object
      required:
        - symbol
      properties:
        symbol:
          $ref: '#/components/schemas/SecuritySymbol'
        name:
          type: string
        sourceSymbol:
          type: string
          description: Original symbol/ticker as it is listed on the exchange.
        isin:
          $ref: '#/components/schemas/ISIN'
    ErrorResponse:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              description: Stable public error code.
            message:
              type: string
              description: Human-readable public error message.
      example:
        error:
          code: unauthenticated
          message: authentication failed
    SecuritySymbol:
      type: string
      description: >-
        TakeProfit security symbol as returned by
        /api/v1/marketdata/exchanges/{exchange}/securities. In a path segment a
        slash must be percent-encoded (BTC/USDT is requested as BTC%2FUSDT).
      example: AAPL
    ISIN:
      type: string
      example: US0378331005
  headers:
    RateLimitLimit:
      description: Credits allowed per quota window.
      schema:
        type: integer
    RateLimitRemaining:
      description: Credits still available in the current quota window after this request.
      schema:
        type: integer
    RateLimitReset:
      description: Epoch second at which the current quota window resets.
      schema:
        type: integer
        format: int64
    RetryAfter:
      description: Seconds until the quota window resets and the request can be retried.
      schema:
        type: integer
  responses:
    InvalidRequest:
      description: >-
        Invalid request (`invalid_argument`), or a request producing more data
        than can be served (`too_much_data`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            error:
              code: invalid_argument
              message: query parameter "exchange" is required
    Unauthorized:
      description: Authentication failed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            error:
              code: unauthenticated
              message: authentication failed
    Forbidden:
      description: Permission denied.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            error:
              code: permission_denied
              message: permission denied
    NotFound:
      description: The exchange or the security is not served.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            error:
              code: not_found
              message: security not found
    RateLimited:
      description: >-
        The remaining credits of the quota window cannot cover this request;
        retry after the window resets.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/RateLimitLimit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/RateLimitRemaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/RateLimitReset'
        Retry-After:
          $ref: '#/components/headers/RetryAfter'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            error:
              code: rate_limited
              message: rate limit exceeded
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key

````