Type/to search
Getting Started
Welcome to FMZ Quant Trading Platform
Quick Start
Key Security
Platform Basics
Account and Billing
Live Robot Billing and Top-up
Sub-accounts
Exchange
General Protocol
Local Credential Files
Exchange-Specific Notes
Securities and Futures
Crypto
Docker
Strategy Library
Live Trading
Writing Strategies
Development Tools
Backtesting System
Advanced Topics
Data and Research
Integrations

When configuring an exchange, every masked encrypted input (Secret Key, private key, password, etc.) can hold a credential file path file:///name.txt instead of the secret itself. When the live robot runs, the docker reads that file on its own machine and uses the content as the value. The private key then exists only on the docker's machine, and the platform stores nothing but a path.

Path rules

  • The path is resolved relative to this robot's directory logs/storage/<robot ID>/ (logs is under the docker's working directory). For robot ID 123456, file:///rsaKey.txt means logs/storage/123456/rsaKey.txt.
  • Subdirectories are allowed, e.g. file:///keys/rsaKey.txt.
  • Only the .txt suffix is recognized; with any other suffix the text is not read as a file but used literally as the configuration value.
  • The path cannot be absolute, cannot contain .., and after resolution cannot leave the robot directory (symbolic links pointing outside are rejected too).
  • Credential files are read from each robot's own directory, so when several robots use the same exchange configuration, every robot directory needs its own copy.
  • If the file cannot be read, the robot fails to start with an error containing read key file; an invalid path fails with key file path must be relative and cannot contain '..' or key file path escapes the robot directory.

Example: an RSA key
For an exchange that supports RSA KEY authentication:

  1. Generate an RSA public/private key pair, e.g. a PKCS#8 pair with openssl.
  2. Create an RSA KEY on the exchange and upload the public key from step 1.
  3. Configure the exchange on the platform: put the exchange's RSA KEY in Access Key and file:///rsaKey.txt in Secret Key.
  4. Create the live robot and note its ID (e.g. 123456).
  5. Save the private key from step 1 as logs/storage/123456/rsaKey.txt, then start (or restart) the robot.

See the video walkthrough (Chinese) for the full process.