Skip to content
Wallets & SecurityBeginner

How to use exchange API keys safely: setup, storage, and review

To use exchange API keys safely, give each app its own read-only or trade-only key, add an IP allowlist, and store the secret in a password manager.

Vahe HakobyanVahe HakobyanEditor-in-chief Updated Oct 6, 20263 min readFact-checked
A dark navy background with a hardware security key, steel plate and padlock on the right.
Illustration: World-Crypt
On this page
Key takeaways
  • Read-only keys can see account data but cannot place trades.
  • A separate key for each app limits a leak.
  • An IP allowlist reduces risk but is not immunity.
  • Store the secret in a password manager, not chat or code.
  • Revoke unused keys; deleting an app does not remove them.

Short answer

To use exchange API keys safely, give each app its own key with read-only or trade-only permissions, whitelist it to a trusted IP, and store the secret in a password manager. Leave withdrawal off.

A bot or tracker needs to reach your exchange account without your password. An API key does that, and its permissions decide what a leak can do.

What permissions should an exchange API key have?

When you connect a bot or tracker, the exchange asks which actions the key may take. Choose read-only if the app only reads balances and history. Choose trade-only if it places orders, and leave withdrawal access off. Use a separate labeled key for each app.

How do you create and secure the key?

Secure the key to one network and store the secret out of reach. The exchange usually shows the secret once, so have your password manager ready. Use IP whitelisting if the exchange offers it.

  1. 1Create the keySet the permissions you chose and name it for the app.
  2. 2Set the IP allowlistEnter your server or trusted network IP.
  3. 3Copy the secret onceThe exchange usually shows it a single time.
  4. 4Store the secretUse a password manager or encrypted environment variable.
  5. 5Connect and testConfirm the app works as intended.

What should you do after setup?

Setup is not finished when the app starts working. A key can stay active after you forget it. Set a review routine and keep records of what each key is for.

After setup checks

  • Review each key's permissions and recent activity.
  • Update the IP allowlist when your server address changes.
  • Revoke keys for apps you stopped using.
  • If a key leaks, revoke it and check for unauthorized orders.

Frequently asked questions

No. A read-only key can view balances and history, but it cannot submit orders. Placing trades requires trade permission, which carries more risk if the key leaks.

Treat the secret as more exposed. Use a unique key for that app, give it only the permissions it needs, and revoke it when you stop using the app.

Usually not. Many keys stay active until you revoke them, though some exchanges let you set an expiry date. Check the settings and remove what you no longer use.

No. Deleting the app or bot does not remove the key from your exchange account. Revoke the key in the exchange's API settings.

Was this guide helpful?
Written byVahe HakobyanVahe Hakobyan is the editor-in-chief of World-Crypt. He covers bitcoin, markets and regulation, and leads the newsroom that fact-checks every story before it goes live.