MetaTrader Investor Password: What Read-Only Access Does
Someone asks for proof that an account is real before they will copy it, fund it, or hand over a management fee. The answer offered is almost always the same: here is the investor password, log in and see for yourself.
That password is a documented platform feature with a precise scope. What follows is what MetaQuotes actually says it permits, where it comes from, what silently destroys it, and the questions a read-only login is structurally incapable of answering.
Key takeaways
- MetaTrader has exactly two types of account access, master and investor, and both passwords are issued together the moment the account is created.
- Investor authorization permits viewing the account, analysing prices, and working with your own Expert Advisors. What it withholds is the ability to trade, not the ability to run a program.
- A forced change of the master password also resets the investor password, so access granted to someone else can end without either party doing anything.
- A read-only login shows the state of one account on one server. It cannot show what else exists, what was withdrawn, or how many accounts were opened before this one.
- Anyone who needs a viewer to place, modify or close anything is not describing a password setting at all.
Table of contents
- What the Two Access Types Actually Are
- What an Investor Login Permits, Including Expert Advisors
- Where the Investor Password Comes From
- Master and Investor Are Not a Hierarchy
- What a Read-Only Login Cannot Prove About a Record
- Changing or Withdrawing Investor Access
- When Read-Only Is the Wrong Tool
- Who This Page Is Not For
- Frequently Asked Questions
What the Two Access Types Actually Are
The vendor documentation is unusually direct here. Account access exists in exactly two forms, named master and investor, and nothing sits between them. There is no third tier, no partial permission, and no read-and-place-but-not-close arrangement.
Signing in with the master credential carries the complete set of rights over that account. It is what the holder uses day to day, and it is what a broker means by your trading password.
The investor password opens the same account number on the same server, in the same terminal, and produces a session that looks almost identical. Charts load, the balance and equity are visible, the trade history is there, and the terminal behaves normally right up to the moment an order is sent.
MetaQuotes presents the investor route as a way of showing someone else how an account is being traded. Showing is the operative idea: the design purpose is to let a person watch, not to let them participate in a reduced form.
One further authentication mode exists alongside the two passwords. The platform supports extended authentication using SSL certificates, and the certificate details are only reachable in the platform settings when the trade server is running in that mode. This is a server-side decision rather than something a trader enables, and it sits beside the password pair rather than replacing it.
What an Investor Login Permits, Including Expert Advisors
This is the point where the search results and the vendor documentation part company, and the difference matters to anyone evaluating an automated strategy.
MetaQuotes sets out four things at once. Under investor authorization a person may inspect the state of the account, study prices, and operate Expert Advisors belonging to them, while trading alone is withheld. The permission to run a program is explicit, and it sits in the same sentence as the restriction.
The distinction is between running and executing. An Expert Advisor attached to a chart under an investor login loads, reads prices, calculates, and reaches the point where it would send an order. That order does not go. The account is not tradeable from that session, so the request fails rather than the program being blocked from starting.
For someone assessing a strategy this is genuinely useful. A visitor can attach their own analysis to the live data of the account they are inspecting, watch how the strategy behaves on the same feed at the same moment, and compare it against what the account holder is actually doing, without any possibility of touching the positions.
It also sets a limit worth stating plainly. Because nothing can be sent, no test conducted under an investor login produces a fill, a cost, or a result. Anything that needs an actual execution belongs in a demo account or in the tester, and the difference between the two is set out in what a backtest can and cannot show.
| Action in the terminal | Master password | Investor password |
|---|---|---|
| See account status, balance and history | Yes | Yes |
| Analyse prices on the live feed | Yes | Yes |
| Attach and run your own Expert Advisor | Yes | Yes |
| Send, modify or close an order | Yes | No |
| Change the account password | Yes | No |
| Issued in the registration dialog at account creation | Yes | Yes |
Where the Investor Password Comes From
A common assumption is that the investor password is something generated later, when a reason to share the account appears. The registration sequence says otherwise.
Once the account exists on the chosen server, MetaQuotes documents a dialog whose lower half lists three things: the login number; the access password, identified as the master one that permits trading; and an Investor entry, identified as the credential for connecting to view the state of the account and study price movement without trading.
Both exist from the first second of the account. Nobody has to request the second one, and its absence from a broker portal is a matter of where that broker chose to display it rather than whether it was created.
The same dialog carries a QR code, which connects the mobile platform to the account without typing a login, a password or a server name. That is a master-level shortcut and it is worth separating in your mind from the read-only pair, because photographing that screen and photographing the investor line are two very different acts.
The account details window is also the moment to record which server the account belongs to. A login number without its server name is not enough for anyone to connect, which is why an investor password shared without the server is inert.
Master and Investor Are Not a Hierarchy
The two passwords are often described as levels, as though investor were a lesser version of master with the risky parts removed. Treating them that way leads to two practical mistakes.
The first is assuming the investor password is derived from the master one and will therefore stay valid as long as the account does. It is a separate credential on the same account, and the platform manages it separately.
The second is assuming that a session opened with an investor password is somehow supervised or limited in what it can see. It is not. Everything the account holder can read, the visitor can read: open positions and their sizes, the full closed history, the balance and equity, the margin in use, and every deal recorded on that account. If the account holder considers any of that private, the investor password is the wrong instrument, because there is no partial view.
Password strength requirements make the same point from a different angle. Where a server enforces a change, the vendor documentation asks for a new password no shorter than the length the dialog demands, drawn from four groups of characters at once, meaning small letters, capitals, digits and punctuation marks, and different from the one it replaces. A password on a trading account is a security control rather than a convenience toggle, and the investor one is a password on a trading account.
What a Read-Only Login Cannot Prove About a Record
Investor access is presented across the search results as the standard way to prove a track record. It does prove something, and being exact about what saves a great deal of trouble.
What it does prove is narrow and real: that this account number, on this server, is in this state right now, and that the deals listed in its history were recorded on it. That is more than a screenshot, which can be edited, and more than a spreadsheet, which is typed.
What it cannot prove is everything about selection. It shows one account. It cannot show whether nine other accounts were opened at the same time and closed after losing, whether this is the survivor of a set, or whether the operator trades elsewhere under other numbers. A read-only login answers a question about one object and says nothing about the population it was drawn from.
It is equally silent on funding. Deposits and withdrawals move the balance without any trade taking place, so a rising equity curve read at a glance can reflect money added rather than money made, and a flat one can hide profits taken out. The record needed to separate those is the statement, and what it contains is set out in the account statement.
It cannot establish duration either. An account viewed today shows only the history the server still holds, and how far back that runs is a server setting rather than anything the viewer can verify.
The conclusion is not that an investor login is worthless, but that it belongs at the end of a check rather than at the beginning.
Changing or Withdrawing Investor Access
Handing out a password is easy to reverse in principle, and there is one documented behaviour that reverses it whether or not anybody intended to.
MetaQuotes records that a forced master password change also clears the read-only credential on that account, and that a replacement for it is set from inside the platform settings. Forced change is switched on by the trade server administrator, either at first connection or on a repeating schedule, so it is a broker-side decision.
The consequence is worth spelling out. An account holder who shared an investor password months ago may find the viewer locked out on a morning when neither of them did anything, because the server required a master password change and the read-only credential went with it. Nobody is notified that a third party has lost access.
Read the other way, this is the cleanest way to end access deliberately. Changing the master password and then setting a fresh investor password in the platform settings leaves the old read-only credential dead, and the person who held it cannot use the old one to discover what replaced it.
One storage setting deserves attention before sharing anything. The option that keeps personal settings and data at startup writes the account number to disk together with both credentials, master and investor, so the terminal can reconnect on its own next time. On a shared or borrowed machine that is a copy of the credential left behind after the session ends.
Where the terminal has recorded a connection problem or a rejected attempt, that trail sits in the Journal and Experts logs, which is the file to read before assuming a password was changed rather than mistyped.
When Read-Only Is the Wrong Tool
Several arrangements get described as needing an investor password when they need something else entirely, and the giveaway is always the same: somebody expects the second person to act.
If a viewer is expected to close a position when the account holder is unreachable, that is not read-only access. It is either the master password, which hands over the whole account, or a formal arrangement offered by the broker.
If the goal is to have someone trade the account on the holder behalf, that is a managed account and it is a contractual and regulatory matter rather than a terminal setting. Handing over a master password to achieve it moves a permission the broker granted to one named person.
If the goal is to mirror one account onto another, that is copy trading, which runs through a service rather than a shared credential, and where several programs are already running on the receiving side the interactions are covered in running Expert Advisors on one account.
And if the goal is to compare timestamps across two accounts on different servers, note that the clock in the terminal belongs to the trade server rather than to the viewer, a difference set out in the broker server clock.
Who This Page Is Not For
Anyone looking for a way to grant limited trading rights will not find it here, because the platform does not offer that. Two access types exist and neither is a partial trading permission.
Anyone hoping a read-only login settles whether a strategy is worth money is asking a question it cannot answer. It can confirm an account exists in a state; judging a record needs the funding history, the sample length and the accounts that are not being shown.
Anyone who has been sent an investor password by a stranger promising returns should treat the login as a display, not as a verification, and should be aware that the account shown may be one of many opened for exactly this purpose.
Frequently Asked Questions
What is an investor password in MetaTrader?
It is the second of the two account access types the platform provides. Under investor authorization, MetaQuotes documents, a person may inspect the state of the account, study prices and operate Expert Advisors of their own, while trading alone is withheld. It opens the same account number on the same server as the master password and produces a session that can read everything and send nothing.
Can someone trade with my investor password?
No. Trading is precisely what the investor access type withholds, and it is the only thing it withholds. The holder of that password can read the balance, the equity, the margin in use, every open position and the whole closed history, so the credential protects the money rather than the privacy of the account.
Can an Expert Advisor run under an investor login?
Yes, and the vendor documentation says so directly. Operating an Expert Advisor of your own appears in the same list as inspecting the account and studying prices, among the things investor authorization permits. The program loads and calculates on the live feed of that account; what it cannot do is send the order it arrives at, because the session has no trading rights.
Does an investor login prove a trading track record?
It proves the state and recorded history of one account on one server, which is more than a screenshot proves. It cannot show whether other accounts exist, whether the balance moved because money was added or withdrawn rather than earned, or how many attempts preceded the one being shown. Treat it as confirmation of something already checked rather than as the check itself.
How is the investor password different from the master password?
The master credential carries the complete set of rights over the account, including sending orders and changing the password itself. The investor one carries everything except the ability to trade. Both are issued together in the account registration dialog at creation, and a forced change of the master password clears the investor one with it.
Sources checked 6 August 2026: MetaQuotes, MetaTrader 5 platform help, Getting Started, Connect to an Account, for the statement that two types of account access are available, master and investor, for the scope of investor authorization including work with your own Expert Advisors, for extended authentication using SSL certificates, for the forced change of the master password and its password composition requirements, and for the reset of the investor password when the master password is changed forcedly. MetaQuotes, MetaTrader 5 platform help, Getting Started, Open an Account, for the account registration dialog listing the login, the master password and the Investor password together, and for the QR code sign-in on the mobile platform. MetaQuotes, MetaTrader 5 platform help, Getting Started, Platform Settings, for the certificate details shown only under extended authentication, and for the startup option that stores the account number together with both credentials locally. No platform behaviour on this page comes from a third-party article.
Disclaimer: This article is educational only and is not investment advice. Platform behaviour changes between builds, so confirm any setting against current MetaQuotes documentation and your own terminal first. A shared credential of any kind is a risk to the account it belongs to, and leveraged trading carries risk: the sum at stake can be lost in full.
