The controlAddress is the address to be used to issue bind_session requests; if you are using one of our client libraries you don't have to worry about it as the library will automatically send the bind_session request to the correct server (you don't have to issue any call for that to happen)

I suppose your issue is somewhere else. Does your broker know you're autonomously using their server or are you reverse engineering their website/app? In the former case they are probably publishing some documentation that you can follow to get up and running.