BadRock Capital
Algo Trading
Sign inRegister
Security

How to connect exchange API keys safely

What permissions Terminal needs, why withdrawal access is not required, and how to control access.

API keys are used for data and trading

Terminal uses keys to read balances, positions, orders, trades, and send trading commands.

Withdrawal permission is not required. If the venue allows disabling withdrawals, disable them.

Check market and permissions

Before launch, confirm that the key was created for the correct exchange and supports the required trading type.

Some venues need extra parameters: passphrase, account mode, hedge/one-way, and sandbox/demo specifics.

Remove keys you no longer use

If a key is no longer needed, delete it on the exchange side. This lowers operational risk.

Periodically review active keys and permissions.