Connecting any trading tool to an exchange means handing it a key. The question that matters is what that key is allowed to do. A tool that trades for you needs to read balances and place orders. It does not need permission to move your coins anywhere.
Three things: read your balances, read your orders, and place or cancel orders. That is the entire set. Every exchange also offers withdrawal or transfer permission on the same screen, and a trading tool has no use for it.
This matters because permissions are the only real limit on what a key can do once it exists. If a key is stolen — from the vendor, from a laptop, from a screenshot — what the thief can do with it is exactly what you ticked when you made it. A key without withdrawal permission cannot move coins off the exchange no matter who is holding it. The exchange refuses the request; there is no setting on the vendor's side that overrides it.
The three exchanges name these differently. These are the exact permission sets Trade Leopard asks for, and the ones it never does:
Two details are easy to miss. OKX defaults a new key to Read only, which lets a dashboard show balances but never place an order — if orders are not appearing, this is usually why. Coinbase hides the choices inside API restrictions and Advanced Settings, and calls withdrawal Transfer.
An IP allowlist ties the key to a specific internet address, so the exchange refuses any request that arrives from anywhere else. All three exchanges support it — Kraken calls it IP address restriction, OKX calls it binding, Coinbase calls it an allowlist.
It is the strongest single thing you can do to a key you have given out, and it costs nothing. A stolen copy of an allowlisted key is refused everywhere except the one machine it was issued for. Trade Leopard places every order from one fixed address, which the app shows you with a copy button when you connect an exchange.
One consequence to know about: restricting the key to one address locks it to that tool alone. Your own scripts, or another app sharing the same key, will be refused. Make a second, unrestricted key for those.
On the same screen you made it. Kraken: Settings → API. OKX: your profile → API. Coinbase: the Developer Platform at portal.cdp.coinbase.com, under Access → API keys. Deleting the key takes effect at once and needs nothing from the tool you gave it to. It is worth doing for any key you are no longer using — an unused key with trade permission is a live one.
Only if you gave it a key with withdrawal permission. Exchange API keys are limited by the permissions selected when the key is created, and the exchange enforces those limits on its own side. A key created without withdrawal or transfer permission cannot move coins off the exchange, regardless of what the software holding it tries to do.
Reading balances, reading open and closed orders, and creating, modifying or cancelling orders. On Kraken that is Query Funds, Query Open/Closed Orders & Trades, Modify Orders, Cancel/Close Orders and Query Ledger Entries. On OKX it is Read plus Trade. On Coinbase it is View plus Trade. Withdrawal — called Withdraw Funds on Kraken and OKX, and Transfer on Coinbase — should be left off.
An IP allowlist restricts a key so the exchange only accepts requests from one internet address. A copy of the key used from anywhere else is rejected. Kraken calls it IP address restriction, OKX calls it binding the key, and Coinbase calls it an IP allowlist. It is optional on all three and it makes a stolen key useless to whoever takes it.
No. Your coins stay in your own account at Kraken, OKX or Coinbase. Trade Leopard connects through an API key you create and can revoke in seconds, and the key is created without withdrawal permission, so funds cannot be moved off the exchange. Keys are encrypted before storage and never returned to the browser.
Delete it on the exchange's own API management page — Settings → API on Kraken, the API page under your profile on OKX, or Access → API keys at portal.cdp.coinbase.com for Coinbase. Deletion takes effect immediately and requires nothing from the tool that was using the key.
Set your weights, your budget and the gate. It buys on your schedule at Kraken, OKX or Coinbase, using an API key that cannot withdraw. $15 a month, cancel anytime.