MT5 investor (read-only) password vs trading password: which one to use for copy trading
The investor password is the read-only password of an MT5 account: it can view the account but cannot trade, while the trading password can place orders. On Niubang, list a master account with the investor password and add a copy account with the trading password. Neither can deposit or withdraw.
Niubang editorial · Updated
What each password can do
Every MetaTrader 5 trading account has two login passwords. The trading password (the master password in MetaTrader's documentation) gives full access: placing, closing and modifying orders. The investor password, also called the read-only password, lets you see the account status and prices but not trade. This is how the MetaTrader platform itself is designed, whichever broker you use.
Both passwords only log in to the trading terminal; by MetaTrader's design neither can be used to deposit or withdraw, which is done in your broker's own client area. Whichever password you give a copy trading service, your funds stay in your own brokerage account.
Which one to use for copy trading
When you list a master account on Niubang (making it a signal source), enter the investor password. The cloud only needs to read the master's position changes, so read-only access is enough; do not enter the trading password here.
When you add a copy account (letting the cloud execute copied trades in it), enter the trading password. The read-only password cannot place orders, so a copy account submitted with it is rejected during the connection check.
In short: the investor password is for letting others see an account; the trading password is for letting the cloud copy trades into it.
How Niubang handles both passwords
The cloud needs the password to connect to your broker's server, so it is sent to the Niubang cloud rather than kept only on your computer. It travels over an encrypted https connection and never appears in a URL. In the cloud, read-only and trading passwords are stored encrypted with AES-256-GCM, decrypted only in the memory of the execution process to connect to the broker, and never written to logs.
The NB Copy Engine panel itself keeps no MT passwords: the input box is cleared as soon as you submit, and also after 180 seconds of inactivity. MT5 input boxes have no password mode, so characters are visible while you type; enter passwords where no one is watching.
Connecting an account needs only the login, password and server name, not broker back-office (Manager) access. Copied orders carry a fixed tag, and pause or close actions only touch copied orders, never trades you opened yourself.
After you change the password or stop copying
If you change the trading password at your broker, the password stored in the cloud stops working and the copy account can no longer connect; its status turns red and needs attention. Until you enter the new password, the cloud cannot open or close trades in that account, and existing copied positions will no longer follow the master's closes; you need to manage them yourself. Re-enter the new trading password on the account's detail page in the panel to reconnect, or fix other accounts under My copy trading on the website.
If you only want to stop copying, you do not need to change the password: stop copying in the panel or on the website, the copied positions in that account are closed out, and no new signals are received. Changing the trading password is not a cleaner way to stop: the cloud can no longer connect to the account, so existing copied positions are left unmanaged.
Copy trading involves risk, and a strategy's past performance does not guarantee future returns.