Is it safe to connect an exchange API key to a trading tool?

It can be, if you give the key the least permission that does the job and the tool stores it properly. Here is what to check before you paste a key anywhere, and how BitMe handles each point.

Permissions are the real protection

An API key can only do what its permissions allow. A read-only key can see positions, orders and history but cannot place orders or move funds — if one leaks, what is exposed is your trading activity. A trade-enabled key can place and cancel orders. A key with withdrawal permission can move money off the exchange, which is why a monitoring or journal tool has no legitimate reason to ask for it.

  • Monitoring, alerts, journal, reports: read-only.
  • Managing positions from a tool: trade permission, withdrawals off.
  • Withdrawal permission: never, for a third-party tool.

A checklist for any tool

  • Does it work with a read-only key, and say so clearly?
  • Is the secret encrypted at rest and never shown again after saving?
  • Can you protect your account there with two-factor authentication or passkeys?
  • Can you delete the key yourself, and revoke it on the exchange, at any time?
  • Is there a privacy policy and terms you can actually read?

Also use a separate key per tool, so you can revoke one without touching the others, and where your exchange supports it, restrict a key to trusted IP addresses.

How BitMe handles keys

  • Monitoring, alerts, the journal and reports need only a read-only key. BitMe never asks for withdrawal permission.
  • An optional, separate trade-enabled key powers closing positions, moving stop-loss and take-profit and cancelling orders from the chart; those actions require two-factor authentication.
  • Secrets are encrypted on the server and are not sent back to your browser — after saving, only a placeholder is shown, including to BitMe administrators through the interface.
  • Accounts can be protected with TOTP two-factor authentication and passkeys (WebAuthn).
  • You can remove a key from Config whenever you like. More in the privacy policy and the terms.

Test without risk

You can look around the read-only demo without connecting anything, or use your exchange’s demo trading keys where available (OKX supports them in BitMe).

Common questions

Can someone steal my funds with a read-only key?

By design, no: a read-only key cannot place orders or withdraw. If it leaked, the exposure is your trading data, so revoke and replace it. That is the reason to keep to read-only wherever you can.

What if I stop using BitMe?

Delete the key from Config and revoke it on the exchange. You can also ask us to delete your account and data at contact@bitme.trade.


Related guides

See it on your own positions

Create an account and connect your exchange API key in minutes.

Get started