{"id":50914210,"url":"https://github.com/mafischer/node-tda","last_synced_at":"2026-06-16T13:02:37.493Z","repository":{"id":49324789,"uuid":"342963499","full_name":"mafischer/node-tda","owner":"mafischer","description":"NodeJS API for TDA","archived":false,"fork":false,"pushed_at":"2021-05-03T19:18:52.000Z","size":579,"stargazers_count":13,"open_issues_count":0,"forks_count":5,"subscribers_count":3,"default_branch":"master","last_synced_at":"2025-10-24T22:34:55.840Z","etag":null,"topics":["async","callback","convenience","nasdaq","node-tda","nyse","promise","stock","td","tda","tda-api","tdameritrade","trade"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"isc","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mafischer.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null},"funding":{"github":["mafischer"],"patreon":null,"open_collective":null,"ko_fi":null,"tidelift":null,"community_bridge":null,"liberapay":null,"issuehunt":null,"otechie":null,"custom":null}},"created_at":"2021-02-27T21:37:27.000Z","updated_at":"2023-09-09T21:06:34.000Z","dependencies_parsed_at":"2022-09-23T14:30:22.445Z","dependency_job_id":null,"html_url":"https://github.com/mafischer/node-tda","commit_stats":null,"previous_names":[],"tags_count":6,"template":false,"template_full_name":null,"purl":"pkg:github/mafischer/node-tda","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mafischer%2Fnode-tda","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mafischer%2Fnode-tda/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mafischer%2Fnode-tda/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mafischer%2Fnode-tda/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mafischer","download_url":"https://codeload.github.com/mafischer/node-tda/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mafischer%2Fnode-tda/sbom","scorecard":{"id":611328,"data":{"date":"2025-08-11","repo":{"name":"github.com/mafischer/node-tda","commit":"a56c8cb9d718c1c810bbe4a84826c6e6b5e7c6f2"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.8,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/node.js.yml:1","Warn: no topLevel permission defined: .github/workflows/npm-publish.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":5,"reason":"dependency not pinned by hash detected -- score normalized to 5","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node.js.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/mafischer/node-tda/node.js.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node.js.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/mafischer/node-tda/node.js.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/npm-publish.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/mafischer/node-tda/npm-publish.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/npm-publish.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/mafischer/node-tda/npm-publish.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/npm-publish.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/mafischer/node-tda/npm-publish.yml/master?enable=pin","Info:   0 out of   4 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned","Info:   2 out of   2 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: ISC License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":0,"reason":"34 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-67hx-6x53-jw92","Warn: Project is vulnerable to: GHSA-c2jc-4fpr-4vhg","Warn: Project is vulnerable to: GHSA-93q8-gq69-wqmw","Warn: Project is vulnerable to: GHSA-cph5-m8f7-6c5x","Warn: Project is vulnerable to: GHSA-wf5p-g6vw-rhxx","Warn: Project is vulnerable to: GHSA-jr5f-v2jv-69x6","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg","Warn: Project is vulnerable to: GHSA-w8qv-6jwh-64r5","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-74fj-2j2h-c42q","Warn: Project is vulnerable to: GHSA-pw2r-vq6v-hr8c","Warn: Project is vulnerable to: GHSA-jchw-25xp-jwwc","Warn: Project is vulnerable to: GHSA-cxjh-pqwp-8mfp","Warn: Project is vulnerable to: GHSA-4q6p-r6v2-jvc5","Warn: Project is vulnerable to: GHSA-43f8-2h32-f4cj","Warn: Project is vulnerable to: GHSA-9c47-m6qq-7p4h","Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3","Warn: Project is vulnerable to: GHSA-xvch-5gv4-984h","Warn: Project is vulnerable to: GHSA-qrpm-p2h7-hrv2","Warn: Project is vulnerable to: GHSA-mwcw-c2x4-8c55","Warn: Project is vulnerable to: GHSA-r683-j2x4-v87g","Warn: Project is vulnerable to: GHSA-hj48-42vr-x3v9","Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j","Warn: Project is vulnerable to: GHSA-hrpp-h998-j3pp","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-4rq4-32rv-6wp6","Warn: Project is vulnerable to: GHSA-64g7-mvw6-v9qj","Warn: Project is vulnerable to: GHSA-pq67-2wwv-3xjx","Warn: Project is vulnerable to: GHSA-8cj5-5rvv-wf4v","Warn: Project is vulnerable to: GHSA-j8xg-fqg3-53r7","Warn: Project is vulnerable to: GHSA-6fc8-4gx4-v693","Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-21T02:43:31.872Z","repository_id":49324789,"created_at":"2025-08-21T02:43:31.873Z","updated_at":"2025-08-21T02:43:31.873Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34406824,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-16T02:00:06.860Z","response_time":126,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["async","callback","convenience","nasdaq","node-tda","nyse","promise","stock","td","tda","tda-api","tdameritrade","trade"],"created_at":"2026-06-16T13:02:36.393Z","updated_at":"2026-06-16T13:02:37.487Z","avatar_url":"https://github.com/mafischer.png","language":"JavaScript","funding_links":["https://github.com/sponsors/mafischer"],"categories":[],"sub_categories":[],"readme":"# node-tda\n\nConvenient library for [TDA REST API](https://developer.tdameritrade.com/apis).\n\n## Status\n\n[![GitHub package.json version](https://img.shields.io/github/package-json/v/mafischer/node-tda)](https://github.com/mafischer/node-tda/blob/master/package.json#L3)\n[![Build](https://github.com/mafischer/tda-node/actions/workflows/node.js.yml/badge.svg)](https://github.com/mafischer/node-tda/actions/workflows/node.js.yml)\n[![nycrc config on GitHub](https://img.shields.io/nycrc/mafischer/tda-node?config=.nycrc\u0026preferredThreshold=lines)](https://github.com/mafischer/node-tda/actions/workflows/node.js.yml)\n[![issues](https://img.shields.io/github/issues/mafischer/node-tda)](https://github.com/mafischer/node-tda/issues)\n[![issues](https://img.shields.io/github/stars/mafischer/node-tda?style=social)](https://github.com/mafischer/node-tda/stargazers)\n\n## Contributing\n\nPlease review the [contributing](CONTRIBUTING.md) documentation.\n\n## Prerequisites\n\n1. Follow these [instructions](https://developer.tdameritrade.com/content/getting-started) to create a tda developer account and app. Set your app redirect uri to `https://localhost:8443/`.\n2. Take note of the consumer key generated for your app.\n3. Install openssl on your system if you want to use the CLI to aid in retrieving your tokens.\n\n## Install\n\n- `npm install node-tda`\n- `npm install node-tda --no-optional` if you don't need puppeteer for oauth authentication in a headless browser\n\n## Usage\n\n### CLI\n\nFor CLI usage, also install node-tda as a global package `npm install -g node-tda`\n\nThe cli uses an https server to retrieve access tokens from the tda oauth login. For convenience, self-signed certs are generated automatically upon install. If your system is missing `openssl` from its path, the certs will not be generated and the cli won't work.\n\nFor automated oauth login:\n``` bash\ntda_authenticate --CONSUMER_KEY='\u003cCONSUMER_KEY\u003e' --UID='\u003cuserid\u003e' --PW='\u003cpassword\u003e'\n```\n\nFor manual oauth login:\n``` bash\ntda_authenticate --CONSUMER_KEY='\u003cCONSUMER_KEY\u003e'\n```\n\n### Lib\n\n#### REST API\n\nAll functions names are a camelCase reflection their respective names found in the [TDA API](https://developer.tdameritrade.com/apis) documentation. As of the writing of this document, all of the functions published in TDA's web api have been implemented.\n\n*Examples:*\n\n``` javascript\n// Get Accounts\n// https://developer.tdameritrade.com/account-access/apis/get/accounts-0\nconst { getAccounts } = require('node-tda');\n\n// Place Order\n// https://developer.tdameritrade.com/account-access/apis/post/accounts/%7BaccountId%7D/orders-0\nconst { placeOrder } = require('node-tda');\n```\n\nThe REST API function signatures `apiFunc(options, [callback])` include an optional callback, which when omitted, returns a promise.\n\n##### Using Promises:\n\n``` javascript\nconst { authenticate, generateTokens, refreshToken, getAccounts } = require('node-tda');\n\nasync function auth(consumerKey) {\n  const grant = await authenticate({\n    consumerKey\n  });\n  const token = await generateTokens({\n    consumerKey,\n    grant\n  });\n  return token['access_token'];\n}\n\nconst consumerKey = \"someKey\";\nauth(consumerKey)\n  .then(async (token) =\u003e {\n    const accounts = await getAccounts({ token });\n    console.log(JSON.stringify(accounts));\n    setInterval(async () =\u003e {\n      // refresh token\n      const newToken = refreshTokenToken({\n        ...token,\n        consumerKey\n      });\n      console.log(JSON.stringify(newToken));\n    }, 1800000);\n  })\n  .catch((err) =\u003e {\n    console.log(err);\n  });\n```\n\n##### Using Callbacks:\n\n``` javascript\nconst { authenticate, generateTokens, refreshToken, getAccounts } = require('node-tda');\n\nfunction auth(consumerKey, callback) {\n  authenticate({\n    consumerKey\n  }, (grant) =\u003e {\n    generateTokens({\n      consumerKey,\n      grant\n    }, (token) =\u003e {\n      callback(null, token['access_token']);\n    });\n  });\n}\n\nconst consumerKey = \"someKey\";\nauth(consumerKey, (err, token) =\u003e {\n  getAccounts({ token }, (accounts) =\u003e {\n    console.log(JSON.stringify(accounts));\n    setInterval(async () =\u003e {\n      // refresh token\n      const newToken = refreshTokenToken({\n        ...token,\n        consumerKey\n      });\n      console.log(JSON.stringify(newToken));\n    }, 1800000);\n  });\n});\n```\n\n#### Streaming API\n\nThe Streamer Class extends EventEmitter and facilitates the use of the streaming API. See TDA's Streaming API documentation [here](https://developer.tdameritrade.com/content/streaming-data).\n\n##### Initialize Streaming Session:\n\n``` javascript\nconst consumerKey = 'YourAppKey';\nconst refreshToken = 'YourRefreshToken';\nasync function streamingFun() {\n  // refresh token:\n  const { access_token } = await tda.refreshToken({\n    consumerKey,\n    refreshToken,\n  });\n\n  const userPrincipalsResponse = await tda.getUserPrincipals({\n    token: access_token,\n    fields: 'streamerSubscriptionKeys,streamerConnectionInfo',\n  });\n\n  const tdaStreamer = new tda.Streamer({\n    userPrincipalsResponse,\n  });\n\n  tdaStreamer.on('connected', () =\u003e {\n    tdaStreamer.request({\n      requests: [\n        {\n          service: 'CHART_EQUITY',\n          requestid: '2',\n          command: 'SUBS',\n          account: 'your_account',\n          source: 'your_source_id',\n          parameters: {\n            keys: 'AAPL',\n            fields: '0,1,2,3,4,5,6,7,8',\n          },\n        },\n      ],\n    });\n  });\n\n  tdaStreamer.on('message', (message) =\u003e {\n    console.log(JSON.stringify(message));\n  });\n}\n\nstreamingFun();\n```\n\n##### Events:\n\n| event        | emits          |\n| ------------ | -------------- |\n| error        | Error          |\n| message      | message object |\n| connected    | n/a            |\n| disconnected | n/a            |\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmafischer%2Fnode-tda","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmafischer%2Fnode-tda","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmafischer%2Fnode-tda/lists"}