How to use exchange API keys safely: setup, storage, and review
To use exchange API keys safely, give each app its own read-only or trade-only key, add an IP allowlist, and store the secret in a password manager.

On this page
- Read-only keys can see account data but cannot place trades.
- A separate key for each app limits a leak.
- An IP allowlist reduces risk but is not immunity.
- Store the secret in a password manager, not chat or code.
- Revoke unused keys; deleting an app does not remove them.
A bot or tracker needs to reach your exchange account without your password. An API key does that, and its permissions decide what a leak can do.
What permissions should an exchange API key have?
When you connect a bot or tracker, the exchange asks which actions the key may take. Choose read-only if the app only reads balances and history. Choose trade-only if it places orders, and leave withdrawal access off. Use a separate labeled key for each app.
How do you create and secure the key?
Secure the key to one network and store the secret out of reach. The exchange usually shows the secret once, so have your password manager ready. Use IP whitelisting if the exchange offers it.
- 1Create the keySet the permissions you chose and name it for the app.
- 2Set the IP allowlistEnter your server or trusted network IP.
- 3Copy the secret onceThe exchange usually shows it a single time.
- 4Store the secretUse a password manager or encrypted environment variable.
- 5Connect and testConfirm the app works as intended.
What should you do after setup?
Setup is not finished when the app starts working. A key can stay active after you forget it. Set a review routine and keep records of what each key is for.
Frequently asked questions
No. A read-only key can view balances and history, but it cannot submit orders. Placing trades requires trade permission, which carries more risk if the key leaks.
Treat the secret as more exposed. Use a unique key for that app, give it only the permissions it needs, and revoke it when you stop using the app.
Usually not. Many keys stay active until you revoke them, though some exchanges let you set an expiry date. Check the settings and remove what you no longer use.
No. Deleting the app or bot does not remove the key from your exchange account. Revoke the key in the exchange's API settings.






