This website will never need your API key, API secret, exchange password or verification code. Do not paste them into a chat or send them to another person.
security checklist
create keys on the exchange itself
Sign in to the exchange using its official app or website. Do not follow unexpected links or let someone else create credentials for you.
enable only necessary permissions
Review each permission carefully. Avoid granting access that the intended connection does not require.
keep withdrawals disabled
Where the exchange offers separate withdrawal permission, leave it disabled for a trading connection unless official instructions clearly require something different—and verify that requirement independently.
use IP restrictions when appropriate
If your exchange supports IP allowlisting and the service provides a verified address, consider using it. Do not guess an IP address.
review and revoke old keys
Remove credentials you no longer use and check permissions periodically, especially after changing a service or exchange setup.
what if you suspect a key is exposed?
Use the exchange’s official security controls to revoke the affected key, review account activity and reset any other credentials that may have been exposed. Contact the exchange through its official support channel if you see activity you do not recognise.
Even a properly restricted API connection does not eliminate market risk, strategy risk, software risk or exchange outages.
