API keys are used for data and trading
Terminal uses keys to read balances, positions, orders, trades, and send trading commands.
Withdrawal permission is not required. If the venue allows disabling withdrawals, disable them.
Check market and permissions
Before launch, confirm that the key was created for the correct exchange and supports the required trading type.
Some venues need extra parameters: passphrase, account mode, hedge/one-way, and sandbox/demo specifics.
Remove keys you no longer use
If a key is no longer needed, delete it on the exchange side. This lowers operational risk.
Periodically review active keys and permissions.