A small data-grid shape linked by a straight line to a cog shape standing alone on the right.

Betting Bots and APIs: Automation Without Getting Locked Out

The bot runs at 3 a.m. Your account should still be there at 9. Betfair draws a real line between the two ways of getting there, and it is not the line most forum threads describe.

A betting bot is any script that places or manages bets without a finger on the mouse. On Betfair Exchange the word that decides whether that is allowed is not "bot", it is "API". Betfair's terms treat a bet placed by other automated means, other than through the Account holder placing each bet manually, as suspicious activity, then carve the API straight back out of that clause: bets placed through it are explicitly excluded. A second rule catches API users too: the account has to stay personal, not a service run for someone else. Before any of that matters, test the logic against the Delayed key's lagged data and design around the API's own limits on requests, concurrency and logins. The keys themselves, what each costs, and what the four brokers say about their own tools live on a page of their own, linked below.

What the rule actually splits

Automation is one line among several inside the wider set of professional betting methods covered on this site, and it gets its own page because the rules here are more specific than "sharp bettors use software". Forum shorthand treats "bot" as one thing: software placing bets. Betfair's terms are more precise. Clause 12.1.4 lists, among the activities it treats as suspicious, a bet placed "otherwise than through the Account holder placing each Bet manually", which read alone would catch every script ever written. It is not read alone: the same clause carries its own exception, stated for the avoidance of doubt, that bets placed "via the Application Programming Interface (API)" are not included. Put the two fragments together and the split is exact: a script clicking through the ordinary website is what the clause is aimed at, and a script talking to the API is the exception the clause names to itself.

Side note: "bot" is doing a lot of work in that sentence, and the word never actually appears in the clause. Betfair's lawyers wrote "otherwise than through the Account holder placing each Bet manually" instead, which is a longer way of saying the same thing but a much harder sentence to misquote. Anyway, back to what it means for you.

So the rule is not "bots are banned" and not "bots are fine". It is narrower: an unofficial script working the website like a very fast pair of hands sits inside a clause about suspicious activity, while the same logic wired to the official API sits inside the exception. Somebody trading the ladder by hand and a script doing the same thing through the API are treated differently by the same document, and the difference is the door, not the strategy behind it.

The personal-use line, and where a bot can cross it

A second clause matters just as much and gets read far less. Betfair can treat an account's usage as prohibited "if we suspect (acting reasonably) that your Account's usage represents 'business usage'", defined deliberately wide: "'business usage' includes any use by a betting operator or any use by an individual or organisation supplying data or services to a betting operator" (clause 11.2.13). That has nothing to do with the API exception above. A script can be squarely inside 12.1.4's carve-out and still fall foul of 11.2.13 if it is actually running bets for someone else, feeding a subscriber service, or acting as the back end of a product sold to other bettors.

I would treat the two clauses as answering different questions. Clause 12.1.4 asks how the bet was placed. Clause 11.2.13 asks whose money and whose decision it really was. A bot that only ever acts on one person's own account clears the second question by default. A bot managing several people's stakes, or selling its signals, does not, whatever door it uses to place the bet.

Every route into the API starts from a verified account. Betfair's own developer help puts it plainly: without a Betfair account, "you cannot proceed with licensing" at all, and the ID checks verification actually involves sit ahead of any key. Commercial automation has its own separate route through Betfair's business side, not a personal key with a bigger budget.

The API is the door. A script on the website is not.

What to test before a Live key gets funded

Everyone who builds a bot wants to skip to placing bets. The honest order runs the other way: prove the logic against data deliberately slower than real time, at the smallest stake the venue allows, before a paid key or a serious bankroll is anywhere near it.

Betfair Delayed key: how old the price data can be

Source: Betfair's developer documentation, FACTS-betfair.md section 6.

Chart data
ItemValue
Fastest snapshot1
Slowest snapshot180

That range, one second at best and up to three minutes at worst, is not a rounding error to shrug off. A price a script last saw as reasonable can have moved well past it by the time the script acts, and there is no sandbox to soften that: Betfair's own documentation states there is no test bed that lets anyone test without using real funds. Every bet a Delayed key places is a live bet with a real result, which is why the smallest stake the venue allows is the only sane way to run this stage.

A hypothetical, with every figure invented for the arithmetic only. Say a script watches a price sitting at 2.10, decides to back it, and the API hands back a snapshot 180 seconds old at that exact moment. A goal, a red card or a late scratch can happen in three minutes, so the price the script thinks it is backing and the price actually on offer when the order lands can be two different numbers. No clever logic upstream fixes a decision built on stale information; the lag itself, not the strategy on top of it, is the first thing worth testing.

The venue is only half the picture; the other half is the feed a bot actually reacts to, and a script built on thin history will misfire whatever key it runs on. Check the arithmetic by hand on a calculator before trusting a script's own numbers, and remember that exchange commission still comes off any winning bet; what it does to a bot's net numbers is worth reading before a strategy is judged a success on paper.

A row of small mechanical arms over a betting slip, all but one paused mid motion.
Most of a bot is waiting. The part that fires is the part the rules care about.

The limits a script needs to be designed around

None of this is about whether automation is allowed. It is about the ceiling the API itself puts on how a script behaves, set out in plain numbers rather than left to guesswork. Four of them matter most when a script is still on the drawing board, and, together with the delayed key's own lag window above, they are figures Betfair can revise; check the current terms before designing production code around any of them.

  • A 200-point cap on market data requests. The cost is added up across the markets and the type of data asked for; going over the total returns an error rather than the data.
  • A 3-concurrent-request ceiling on order and position calls. Checking current orders, profit and loss, or cleared orders more than three times at once, while earlier calls are still running, is refused rather than queued.
  • A 1,000-instruction-per-second ceiling on placing, cancelling, updating or replacing orders. That covers the whole account across every open connection, not one script in isolation.
  • A 20-minute lockout after too many failed logins. Every further login attempt is automatically refused for that period, whatever caused the earlier failures.

A second hypothetical, and the one that actually catches people. A script whose login handling has a bug fails to refresh its session in time and retries in a tight loop instead of backing off. Twenty minutes is roughly a football half; trip the lockout at kick off and the script misses more of the match than it ever caught. The fix is duller than the story: hold the session, and treat a failed login as a reason to stop, not to retry immediately.

Where a broker's own terms add another layer

Everything above is Betfair's own rulebook, and it only applies to a Betfair account held directly. A broker's exchange tool is a different product, opened with the broker, not Betfair, so Betfair's API clauses do not automatically follow there. What matters instead is each broker's own terms, and they do not all say the same thing about scripts: some publish an API of their own, others bar automated access outright. Treat a broker's anti-scraping clause as its own house rule to respect and report if it changes, never as something to route around. What each broker already says about bots has the detail broker by broker, alongside what the keys cost; this page will not repeat it.

If building and maintaining a script is not the project actually wanted, the brokers already package some of this: a broker's built-in automation instead covers what comes ready-made, no code required. An account flagged for suspicious activity under clause 12.1.4, automated or not, does not get quietly ignored either; what an account restriction actually looks like covers that side of it.

I would not build anything before reading the specific broker's current terms, not a forum summary. The four brokers' terms compared side by side is the fastest way to see where automation is welcomed, where it is silent, and where it is barred outright.

Questions people ask

Is using a betting bot on Betfair Exchange against the rules?

Not automatically. Betfair's terms treat a bet placed by other automated means, outside the account holder manually placing each bet, as suspicious activity, then explicitly exclude bets placed via the official API from that same clause. A script working through the API sits in the exception; one working the ordinary website like very fast hands does not.

Can a betting bot be run for someone else, or as a business?

That crosses a separate line. Betfair can treat an account as prohibited if it reasonably suspects the usage counts as business usage, defined to include use by a betting operator or by anyone supplying data or services to one. A personal account is for the holder's own betting, automated or not.

What is the actual difference between a betting bot and the Betfair API?

"Bot" is shorthand for the software; the API is the specific, sanctioned channel Betfair built for automated access. The terms do not judge software by the label attached to it, only by which channel placed the bet.

Can a betting bot be tested without risking real money?

Not on the Delayed key, the free development option: Betfair says no test bed exists that lets anyone test without using real funds, so every bet it places is a live bet with a real result, best kept to the smallest stake while the logic is still being proved.

How fast can a betting bot place orders before the API throttles it?

The ceilings Betfair sets out are a 200-point cap on how much market data one request can ask for, a limit of 3 concurrent requests on order and position calls, and a cap of 1,000 order instructions across the account in a single second. Too many failed logins add a 20-minute lockout on top. Check the current documentation before relying on any of these for production code.

Do the sports betting brokers on this site allow betting bots?

It varies by broker, and this page will not repeat the detail; the page covering each broker's own position on APIs and automation has it broker by broker, alongside the Betfair key costs.