Platform connection password requirements

Review the password strength requirements for the manager accounts that B2CORE and B2COPY use to connect to MetaTrader 4, MetaTrader 5, and cTrader

These requirements apply to the manager account passwords that you specify in Products > Platforms for connections from B2CORE and B2COPY to MetaTrader 4, MetaTrader 5, and cTrader.

Starting 21 September 2026, a password that does not meet these requirements is rejected when you save platform connection settings. Passwords that are already in use remain valid and operational, but if you update any connection detail — even without changing the password itself — you are required to provide a password that meets the requirements.

Requirements by platform

PlatformLengthAllowed special characters
MetaTrader 412–14 characters!#$%*+-=?@^_~
MetaTrader 516–20 characters!#$%()*+,-./:;=?@[]^_{|}~
cTrader, including cTrader WebAPI16–20 characters!#$%()*+,-./:;=?@[]^_{|}~

Requirements for all platforms

Character classes

The password must contain at least one uppercase letter, one lowercase letter, one digit, and one special character from the set allowed for the platform.


Encoding

Only ASCII characters are allowed. Spaces and control characters are not allowed.


Forbidden characters

The following characters must not be used: <, >, &, ", ', backslash, and backtick.


Forbidden content

The password must not contain: b2broker, b2copy, b2core, broker, admin, manager, parts of the server name, four-digit sequences, or sequential and repeated patterns.

Example of a password that is rejected: B2broker2025.

The < and > characters break the connection between B2CORE and the platform, because they are interpreted as reserved characters. Avoid &, ", ', backslash, and backtick as well: they can be misinterpreted when the credentials are passed on to the platform.

These practices are not enforced by B2CORE, but we strongly recommend following them for the manager accounts used by B2CORE and B2COPY:

  • Use a unique password for every server, environment (live, demo, UAT), and manager account.
  • Change the password when the responsible employee changes, and at least once every 12 months. Change it immediately if you suspect that it has been exposed.
  • Store the password in a password manager only, and never in chats, tickets, or spreadsheets.
  • Restrict the manager account to the B2CORE IP range in addition to setting a strong password.

Last updated on

On this page