Learn

An API key that cannot withdraw

Connecting any trading tool to an exchange means handing it a key. The question that matters is what that key is allowed to do. A tool that trades for you needs to read balances and place orders. It does not need permission to move your coins anywhere.

What permissions does a trading tool actually need?

Three things: read your balances, read your orders, and place or cancel orders. That is the entire set. Every exchange also offers withdrawal or transfer permission on the same screen, and a trading tool has no use for it.

This matters because permissions are the only real limit on what a key can do once it exists. If a key is stolen — from the vendor, from a laptop, from a screenshot — what the thief can do with it is exactly what you ticked when you made it. A key without withdrawal permission cannot move coins off the exchange no matter who is holding it. The exchange refuses the request; there is no setting on the vendor's side that overrides it.

Which boxes to tick

The three exchanges name these differently. These are the exact permission sets Trade Leopard asks for, and the ones it never does:

Kraken API key permissions
Query Funds read your balances
Query Open Orders & Trades
Query Closed Orders & Trades cost basis
Modify Orders places the buys
Cancel/Close Orders
Query Ledger Entries realised P&L
Deposit Funds
Withdraw Funds never
OKX API key permissions
Read balances and prices
Trade places the buys
Withdraw never
Coinbase API key permissions
View read your balances
Trade places the buys
Transfer never — this is withdrawal

Two details are easy to miss. OKX defaults a new key to Read only, which lets a dashboard show balances but never place an order — if orders are not appearing, this is usually why. Coinbase hides the choices inside API restrictions and Advanced Settings, and calls withdrawal Transfer.

What is an IP allowlist, and does it help?

An IP allowlist ties the key to a specific internet address, so the exchange refuses any request that arrives from anywhere else. All three exchanges support it — Kraken calls it IP address restriction, OKX calls it binding, Coinbase calls it an allowlist.

It is the strongest single thing you can do to a key you have given out, and it costs nothing. A stolen copy of an allowlisted key is refused everywhere except the one machine it was issued for. Trade Leopard places every order from one fixed address, which the app shows you with a copy button when you connect an exchange.

One consequence to know about: restricting the key to one address locks it to that tool alone. Your own scripts, or another app sharing the same key, will be refused. Make a second, unrestricted key for those.

What else should you check before connecting anything?

  • Is the secret ever shown back to you? A key that can be read out of the interface after you save it can be read by anyone who gets into that account. Trade Leopard encrypts keys before storage and never returns them to the browser.
  • Can the tool sell? “Trade” permission covers buys and sells — no exchange separates them. So the limit has to come from the software, and it should be stated plainly. Trade Leopard only buys out of the box; the one thing it can ever sell on its own is the scheduled trim, which is off until you switch it on, sells only a holding's profit, and never sells at a loss.
  • Can you see an order before it happens? Lump-sum buys, percentage sells and rebalances should show you the exact orders — asset by asset — before anything is placed.
  • How fast can you stop it? Deleting the key at the exchange cuts the connection immediately. Nothing on the vendor's side can outlive a key you revoke.

How do you revoke a key?

On the same screen you made it. Kraken: Settings → API. OKX: your profile → API. Coinbase: the Developer Platform at portal.cdp.coinbase.com, under Access → API keys. Deleting the key takes effect at once and needs nothing from the tool you gave it to. It is worth doing for any key you are no longer using — an unused key with trade permission is a live one.

Questions

Common questions

Can a crypto trading bot withdraw my funds?

Only if you gave it a key with withdrawal permission. Exchange API keys are limited by the permissions selected when the key is created, and the exchange enforces those limits on its own side. A key created without withdrawal or transfer permission cannot move coins off the exchange, regardless of what the software holding it tries to do.

Which API key permissions does a trading tool need?

Reading balances, reading open and closed orders, and creating, modifying or cancelling orders. On Kraken that is Query Funds, Query Open/Closed Orders & Trades, Modify Orders, Cancel/Close Orders and Query Ledger Entries. On OKX it is Read plus Trade. On Coinbase it is View plus Trade. Withdrawal — called Withdraw Funds on Kraken and OKX, and Transfer on Coinbase — should be left off.

What is an IP allowlist on an exchange API key?

An IP allowlist restricts a key so the exchange only accepts requests from one internet address. A copy of the key used from anywhere else is rejected. Kraken calls it IP address restriction, OKX calls it binding the key, and Coinbase calls it an IP allowlist. It is optional on all three and it makes a stolen key useless to whoever takes it.

Does Trade Leopard hold my crypto?

No. Your coins stay in your own account at Kraken, OKX or Coinbase. Trade Leopard connects through an API key you create and can revoke in seconds, and the key is created without withdrawal permission, so funds cannot be moved off the exchange. Keys are encrypted before storage and never returned to the browser.

How do I revoke an exchange API key?

Delete it on the exchange's own API management page — Settings → API on Kraken, the API page under your profile on OKX, or Access → API keys at portal.cdp.coinbase.com for Coinbase. Deletion takes effect immediately and requires nothing from the tool that was using the key.

Trade Leopard runs this for you.

Set your weights, your budget and the gate. It buys on your schedule at Kraken, OKX or Coinbase, using an API key that cannot withdraw. $15 a month, cancel anytime.