TrueHold

Read-only API keys on 20 exchanges: permissions, IP allowlists and expiry, compared

One table from the official docs of 20 exchanges: the read-only option each offers, how IP allowlists work, and when an unbound key expires.

Azat Tulegenov6 min read

Every one of the twenty exchanges below lets you create an API key that can see your account and cannot touch it. That is the whole basis of read-only tracking, and it is worth knowing exactly how each exchange spells it, because the details differ in ways that matter: some keys expire if you do not bind an IP address, some never expire, two are only issued with an IP address attached, and one makes read-only a role that cannot be mixed with anything else.

The table was compiled from each exchange’s own documentation and help center on 2 September 2026. Where a document did not say something, the cell says so rather than guessing. Exchanges change these rules, so treat the table as a map and the key page of your own account as the territory.

The table

Binance

Read-only option

Yes. “Enable Reading” is the default permission on a new key

IP allowlist

Yes

Expiry without an allowlist

Trading permission on a key without an IP allowlist is valid 90 days; keys without an allowlist that sit unused 30 days are deleted

Also worth knowing

Read-only keys keep working without an allowlist

OKX

Read-only option

Yes. Read is one of three permissions (Read, Trade, Withdraw)

IP allowlist

Yes, up to 20 IPs per key

Expiry without an allowlist

Keys without an IP that hold Trade or Withdraw expire after 14 days of inactivity; read-only keys do not expire

Also worth knowing

Passphrase set at creation and never shown again

Bybit

Read-only option

Yes. Read-Only is a creation option

IP allowlist

Yes

Expiry without an allowlist

A key created without an IP expires after 90 days; extendable from API management

Also worth knowing

Binding an IP removes the expiry

Kraken

Read-only option

Yes, by permission: Query Funds, Query Open Orders and Trades, and so on

IP allowlist

Yes

Expiry without an allowlist

No forced expiry; optional key expiration and start date you set yourself

Also worth knowing

The most granular permission list of the twenty

Coinbase

Read-only option

Yes. View is the read-only level next to Trade and Transfer

IP allowlist

Yes, allowlist at creation or later

Expiry without an allowlist

No forced expiry stated

Also worth knowing

Keys are scoped to a portfolio, so one key can see one portfolio

Bitget

Read-only option

Yes. Read and write are separate permissions

IP allowlist

Yes, up to 20 IPs per key

Expiry without an allowlist

No forced expiry stated

Also worth knowing

Passphrase required; withdrawals only from allowlisted IPs; up to 50 keys per account

KuCoin

Read-only option

Yes. The “General” permission is read-only

IP allowlist

Yes

Expiry without an allowlist

General-only keys never expire; trading keys without an IP are disabled or deleted after 30 days of inactivity

Also worth knowing

Passphrase required

Gate

Read-only option

Yes. Each permission group can be Read Only or Read and Write

IP allowlist

Yes, up to 20 IPv4 addresses per key

Expiry without an allowlist

Keys not bound to an IP are valid 90 days, then disabled until an IP is bound

Also worth knowing

20 keys per account; keys are deleted after 90 days without login

MEXC

Read-only option

Yes. Read-only can be enabled at creation

IP allowlist

Yes, up to 20 IPs per key

Expiry without an allowlist

Keys without an IP are valid 90 days; renewable in the last 5 days

Also worth knowing

Up to 30 keys per account

BingX

Read-only option

Yes. Read is a separate permission

IP allowlist

Yes, up to 20 IPs per key

Expiry without an allowlist

Read-only keys never expire; trading keys without an IP are deleted after 14 days of inactivity

Also worth knowing

Withdrawal keys must be IP-bound; 20 active keys per account

HTX

Read-only option

Yes, permissions are assigned per key

IP allowlist

Yes, up to 4 IPs per key

Expiry without an allowlist

Keys with trade or withdrawal rights and no IP are deactivated after 90 days of inactivity

Also worth knowing

Up to 5 keys per user

Crypto.com Exchange

Read-only option

Yes. New keys default to “Can Read” only

IP allowlist

Yes, optional at creation

Expiry without an allowlist

No forced expiry stated

Also worth knowing

2FA to create; secret shown once

Bitfinex

Read-only option

Yes. Read and write are ticked separately per category, Account Info included

IP allowlist

Yes, up to 20 IPs per key

Expiry without an allowlist

No forced expiry stated

Also worth knowing

2FA or U2F to confirm creation

Gemini

Read-only option

Yes. The Auditor role is read-only and cannot be combined with other roles

IP allowlist

Yes, Trusted IPs Only or Unrestricted

Expiry without an allowlist

No forced expiry stated

Also worth knowing

Trader and Fund Manager are the other roles

Bitstamp

Read-only option

Yes, by selecting only read permissions such as account balance

IP allowlist

Yes, lock to a specific IP

Expiry without an allowlist

No forced expiry stated

Also worth knowing

Withdrawals can also be locked to a specific address

Backpack

Read-only option

Yes. A Read Only toggle at creation

IP allowlist

Not stated in the docs we checked

Expiry without an allowlist

Not stated in the docs we checked

Also worth knowing

Authenticator code to create

Deribit

Read-only option

Yes. Scopes such as account:read, trade:read and wallet:read

IP allowlist

Yes

Expiry without an allowlist

No forced expiry stated

Also worth knowing

Scopes are the model; a read-only key is a key with only read scopes

BitMart

Read-only option

Yes. A new key is Read-Only by default

IP allowlist

Yes, optional, comma-separated list

Expiry without an allowlist

No forced expiry stated

Also worth knowing

A memo string is part of the signature

Upbit

Read-only option

Yes, by choosing only inquiry functions such as asset inquiry

IP allowlist

Required at issuance, up to 10 IPs per key

Expiry without an allowlist

Every key is valid 1 year and cannot be extended

Also worth knowing

Up to 10 keys per account; 2FA to issue

Bithumb

Read-only option

Yes, by choosing only inquiry items such as asset inquiry and order inquiry

IP allowlist

Required at issuance, up to 5 IPs per key

Expiry without an allowlist

Every key is valid 1 year and cannot be extended

Also worth knowing

Up to 10 keys per account

How to read it

The second column is the one that matters for tracking: every exchange here has a way to issue a key that reads balances and history without trading or withdrawal rights. On Binance, Crypto.com and BitMart it is the default; on Gemini it is a role of its own; on Kraken, Deribit and Bitfinex it is a matter of ticking only the query or read boxes. A tracker that asks for anything beyond that column is asking for more than it needs.

The fourth column is where people get surprised. Binance, Bybit, Gate, MEXC and HTX put a 90-day clock on keys that are not bound to an IP address, OKX and BingX a 14-day one, KuCoin 30 days, and in most cases the clock applies to keys that carry trading rights. Read-only keys are exempt on OKX, KuCoin and BingX by their own docs. Upbit and Bithumb go the other way: every key lives exactly one year, IP attached from the start, and then gets reissued.

Three rules that make the table boring

  • One key per tool, named after the tool. When a key page reads like an inventory, revoking a service never breaks another.
  • Read-only unless the tool genuinely trades for you. The second column exists on every exchange; use it.
  • Bind an IP allowlist wherever the tool has fixed addresses. It removes the expiry clock on most exchanges and turns a leaked key into a key that works from nowhere.

Frequently asked questions

Does a read-only key expire?

It depends on the exchange. OKX, KuCoin and BingX state that read-only keys do not expire; Binance, Bybit, Gate and MEXC apply their 90-day clock to keys without an IP allowlist; Upbit and Bithumb expire every key after one year regardless.

Is an IP allowlist required for a read-only key?

Only on Upbit and Bithumb, where every key is issued against a list of IPs. Everywhere else it is optional, and binding one usually removes the expiry clock.

Which exchange has the most granular permissions?

Kraken, with separate permissions for querying funds, orders and trades, followed by Deribit’s scope model and Gate’s per-group read or write setting. Gemini is the strictest in a different way: its read-only Auditor role cannot be combined with anything else.

Can a read-only key be used to withdraw?

No. Withdrawal is a separate permission on every exchange in the table, and on Bitget and BingX it additionally requires an IP allowlist.

See your whole portfolio in one view

Read-only by design. Paste a wallet, link an exchange, and watch every chain. Free to start.

Open TrueHold →