Platform connection password requirements
Review the password strength requirements for the manager accounts that B2CORE and B2COPY use to connect to MetaTrader 4, MetaTrader 5, and cTrader
These requirements apply to the manager account passwords that you specify in Products > Platforms for connections from B2CORE and B2COPY to MetaTrader 4, MetaTrader 5, and cTrader.
Starting 21 September 2026, a password that does not meet these requirements is rejected when you save platform connection settings. Passwords that are already in use remain valid and operational, but if you update any connection detail — even without changing the password itself — you are required to provide a password that meets the requirements.
Requirements by platform
| Platform | Length | Allowed special characters |
|---|---|---|
| MetaTrader 4 | 12–14 characters | !#$%*+-=?@^_~ |
| MetaTrader 5 | 16–20 characters | !#$%()*+,-./:;=?@[]^_{|}~ |
| cTrader, including cTrader WebAPI | 16–20 characters | !#$%()*+,-./:;=?@[]^_{|}~ |
Requirements for all platforms
Character classes
The password must contain at least one uppercase letter, one lowercase letter, one digit, and one special character from the set allowed for the platform.
Encoding
Only ASCII characters are allowed. Spaces and control characters are not allowed.
Forbidden characters
The following characters must not be used: <, >, &, ", ', backslash, and backtick.
Forbidden content
The password must not contain: b2broker, b2copy, b2core, broker, admin, manager, parts of the server name, four-digit sequences, or sequential and repeated patterns.
Example of a password that is rejected: B2broker2025.
The < and > characters break the connection between B2CORE and the platform, because they are interpreted as reserved characters. Avoid &, ", ', backslash, and backtick as well: they can be misinterpreted when the credentials are passed on to the platform.
Recommended practices
These practices are not enforced by B2CORE, but we strongly recommend following them for the manager accounts used by B2CORE and B2COPY:
- Use a unique password for every server, environment (live, demo, UAT), and manager account.
- Change the password when the responsible employee changes, and at least once every 12 months. Change it immediately if you suspect that it has been exposed.
- Store the password in a password manager only, and never in chats, tickets, or spreadsheets.
- Restrict the manager account to the B2CORE IP range in addition to setting a strong password.
Related articles
Last updated on