INDEPENDENT GUIDEClear explanations. Safer habits. No promises of profit.How this site works ↗
guide 02 · security

protect the connection.
protect your access.

API credentials can allow a third-party tool to interact with an exchange account. Understand permissions before you connect anything.

api permissionsaccount safetyrisk reduction
never share secrets

This website will never need your API key, API secret, exchange password or verification code. Do not paste them into a chat or send them to another person.

security checklist

01

create keys on the exchange itself

Sign in to the exchange using its official app or website. Do not follow unexpected links or let someone else create credentials for you.

02

enable only necessary permissions

Review each permission carefully. Avoid granting access that the intended connection does not require.

03

keep withdrawals disabled

Where the exchange offers separate withdrawal permission, leave it disabled for a trading connection unless official instructions clearly require something different—and verify that requirement independently.

04

use IP restrictions when appropriate

If your exchange supports IP allowlisting and the service provides a verified address, consider using it. Do not guess an IP address.

05

review and revoke old keys

Remove credentials you no longer use and check permissions periodically, especially after changing a service or exchange setup.

what if you suspect a key is exposed?

Use the exchange’s official security controls to revoke the affected key, review account activity and reset any other credentials that may have been exposed. Contact the exchange through its official support channel if you see activity you do not recognise.

security is not a profit guarantee

Even a properly restricted API connection does not eliminate market risk, strategy risk, software risk or exchange outages.