Is it safe to connect an exchange API key to a trading tool?
It can be, if you give the key the least permission that does the job and the tool stores it properly. Here is what to check before you paste a key anywhere, and how BitMe handles each point.
Permissions are the real protection
An API key can only do what its permissions allow. A read-only key can see positions, orders and history but cannot place orders or move funds — if one leaks, what is exposed is your trading activity. A trade-enabled key can place and cancel orders. A key with withdrawal permission can move money off the exchange, which is why a monitoring or journal tool has no legitimate reason to ask for it.
- Monitoring, alerts, journal, reports: read-only.
- Managing positions from a tool: trade permission, withdrawals off.
- Withdrawal permission: never, for a third-party tool.
A checklist for any tool
- Does it work with a read-only key, and say so clearly?
- Is the secret encrypted at rest and never shown again after saving?
- Can you protect your account there with two-factor authentication or passkeys?
- Can you delete the key yourself, and revoke it on the exchange, at any time?
- Is there a privacy policy and terms you can actually read?
Also use a separate key per tool, so you can revoke one without touching the others, and where your exchange supports it, restrict a key to trusted IP addresses.
How BitMe handles keys
- Monitoring, alerts, the journal and reports need only a read-only key. BitMe never asks for withdrawal permission.
- An optional, separate trade-enabled key powers closing positions, moving stop-loss and take-profit and cancelling orders from the chart; those actions require two-factor authentication.
- Secrets are encrypted on the server and are not sent back to your browser — after saving, only a placeholder is shown, including to BitMe administrators through the interface.
- Accounts can be protected with TOTP two-factor authentication and passkeys (WebAuthn).
- You can remove a key from Config whenever you like. More in the privacy policy and the terms.
Test without risk
You can look around the read-only demo without connecting anything, or use your exchange’s demo trading keys where available (OKX supports them in BitMe).
Common questions
Can someone steal my funds with a read-only key?
By design, no: a read-only key cannot place orders or withdraw. If it leaked, the exposure is your trading data, so revoke and replace it. That is the reason to keep to read-only wherever you can.
What if I stop using BitMe?
Delete the key from Config and revoke it on the exchange. You can also ask us to delete your account and data at contact@bitme.trade.
Related guides
Bybit position monitor
BitMe connects to your Bybit account with a read-only API key and watches your open futures positions around the clock, so a sharp move, a missing stop-loss or a shrinking margin buffer reaches you on Telegram even when you are away from the screen.
OKX position monitor
BitMe watches your OKX futures positions around the clock with a read-only API key and messages you on Telegram when P&L, stop-loss coverage or margin risk needs your attention. It works with both the global and the EEA version of OKX.
Crypto trading journal
A journal you have to fill in by hand tends to be abandoned after a few weeks. BitMe imports your closed futures trades straight from your exchanges, so the numbers are complete and you spend your time reviewing them instead of typing.
See it on your own positions
Create an account and connect your exchange API key in minutes.
Get started