Audit yourself: what apps can touch your exchange account
Every API key you ever created is still there until you delete it. A ten-minute audit per exchange finds the forgotten ones and closes them.
Open the API management page of every exchange you use and count the keys. Most people find more than they expect: the bot from 2023, the tax tool you tried once, the tracker you stopped using, a key with trading rights that nobody remembers creating. Each one is a standing permission, and standing permissions are how accounts get drained without a password ever leaking.
The audit takes ten minutes per exchange and answers three questions per key: what can it do, who holds it, and is it still needed. Anything that fails the third question gets deleted. Anything that fails the first gets recreated with less power.
Where the key pages live
- Binance: profile menu, then API Management. Each key shows its permissions and any IP restriction.
- Bybit: account menu, then API. Keys are listed with their permission set and expiry.
- OKX: profile, then API keys. Permissions are read, trade and withdraw, and each key shows the IP allowlist.
- Coinbase and Kraken: settings, then API. Both show per-key scopes; Coinbase also lists third-party apps connected through OAuth, which deserve the same audit.
The three questions
First, permissions. A key for a tracker, a tax tool or a portfolio app needs read access and nothing else. If a key shows trading or withdrawal rights and its only job is reading, delete it and create a fresh one with read-only scope. Do not edit the old one in place; a new key means the old secret is dead wherever it was copied.
Second, holder. Name every key after the tool that holds it, and if you cannot say who holds a key, that is the answer: nobody you trust. Delete it. A tool that still needs access will tell you within a day, and reissuing a key costs five minutes.
Third, need. A key for a service you no longer use is pure downside. The service may have been sold, breached or abandoned since, and its database is where your key lives now. Revoke everything that is not actively doing a job you want done.
Two settings worth switching on
Most exchanges let a key be restricted to a list of IP addresses. For a tool that runs on fixed infrastructure, ask for its addresses and set the restriction; a leaked key then works from nowhere else. Most exchanges also let a key expire. Set the shortest expiry the tool tolerates and treat renewal as the moment to re-run the three questions.
What a tracker should look like on that page
A portfolio tracker should appear as exactly one key with read permission only, no trading, no withdrawals, and it should keep working if you restrict it to the tracker’s IP addresses. That is what TrueHold asks for on every exchange it connects to, and it is the test to apply to any tool that asks for more: if reading your balances requires the power to move them, the tool is asking for something it does not need.
Frequently asked questions
How often should I audit exchange API keys?
Quarterly, and immediately after you stop using any tool. Each audit is ten minutes per exchange once keys are named after the tools that hold them.
Is a read-only key safe to leave in place?
It cannot move funds, so the risk is limited to someone seeing your balances and history. Keep it restricted to the tool’s IP addresses where the exchange allows it, and revoke it the day the tool stops being used.
What if I find a key with withdrawal rights I do not recognise?
Delete it first, then change your password and check your withdrawal address whitelist and recent activity. An unknown key with withdrawal rights is the one finding that justifies acting before understanding.
Terms in this article
See your whole portfolio in one view
Read-only by design. Paste a wallet, link an exchange, and watch every chain. Free to start.
Open TrueHold →