Read-only API keys on 20 exchanges: permissions, IP allowlists and expiry, compared
One table from the official docs of 20 exchanges: the read-only option each offers, how IP allowlists work, and when an unbound key expires.
Every one of the twenty exchanges below lets you create an API key that can see your account and cannot touch it. That is the whole basis of read-only tracking, and it is worth knowing exactly how each exchange spells it, because the details differ in ways that matter: some keys expire if you do not bind an IP address, some never expire, two are only issued with an IP address attached, and one makes read-only a role that cannot be mixed with anything else.
The table was compiled from each exchange’s own documentation and help center on 2 September 2026. Where a document did not say something, the cell says so rather than guessing. Exchanges change these rules, so treat the table as a map and the key page of your own account as the territory.
The table
Binance
Read-only option
Yes. “Enable Reading” is the default permission on a new key
IP allowlist
Yes
Expiry without an allowlist
Trading permission on a key without an IP allowlist is valid 90 days; keys without an allowlist that sit unused 30 days are deleted
Also worth knowing
Read-only keys keep working without an allowlist
OKX
Read-only option
Yes. Read is one of three permissions (Read, Trade, Withdraw)
IP allowlist
Yes, up to 20 IPs per key
Expiry without an allowlist
Keys without an IP that hold Trade or Withdraw expire after 14 days of inactivity; read-only keys do not expire
Also worth knowing
Passphrase set at creation and never shown again
Bybit
Read-only option
Yes. Read-Only is a creation option
IP allowlist
Yes
Expiry without an allowlist
A key created without an IP expires after 90 days; extendable from API management
Also worth knowing
Binding an IP removes the expiry
Kraken
Read-only option
Yes, by permission: Query Funds, Query Open Orders and Trades, and so on
IP allowlist
Yes
Expiry without an allowlist
No forced expiry; optional key expiration and start date you set yourself
Also worth knowing
The most granular permission list of the twenty
Coinbase
Read-only option
Yes. View is the read-only level next to Trade and Transfer
IP allowlist
Yes, allowlist at creation or later
Expiry without an allowlist
No forced expiry stated
Also worth knowing
Keys are scoped to a portfolio, so one key can see one portfolio
Bitget
Read-only option
Yes. Read and write are separate permissions
IP allowlist
Yes, up to 20 IPs per key
Expiry without an allowlist
No forced expiry stated
Also worth knowing
Passphrase required; withdrawals only from allowlisted IPs; up to 50 keys per account
KuCoin
Read-only option
Yes. The “General” permission is read-only
IP allowlist
Yes
Expiry without an allowlist
General-only keys never expire; trading keys without an IP are disabled or deleted after 30 days of inactivity
Also worth knowing
Passphrase required
Gate
Read-only option
Yes. Each permission group can be Read Only or Read and Write
IP allowlist
Yes, up to 20 IPv4 addresses per key
Expiry without an allowlist
Keys not bound to an IP are valid 90 days, then disabled until an IP is bound
Also worth knowing
20 keys per account; keys are deleted after 90 days without login
MEXC
Read-only option
Yes. Read-only can be enabled at creation
IP allowlist
Yes, up to 20 IPs per key
Expiry without an allowlist
Keys without an IP are valid 90 days; renewable in the last 5 days
Also worth knowing
Up to 30 keys per account
BingX
Read-only option
Yes. Read is a separate permission
IP allowlist
Yes, up to 20 IPs per key
Expiry without an allowlist
Read-only keys never expire; trading keys without an IP are deleted after 14 days of inactivity
Also worth knowing
Withdrawal keys must be IP-bound; 20 active keys per account
HTX
Read-only option
Yes, permissions are assigned per key
IP allowlist
Yes, up to 4 IPs per key
Expiry without an allowlist
Keys with trade or withdrawal rights and no IP are deactivated after 90 days of inactivity
Also worth knowing
Up to 5 keys per user
Crypto.com Exchange
Read-only option
Yes. New keys default to “Can Read” only
IP allowlist
Yes, optional at creation
Expiry without an allowlist
No forced expiry stated
Also worth knowing
2FA to create; secret shown once
Bitfinex
Read-only option
Yes. Read and write are ticked separately per category, Account Info included
IP allowlist
Yes, up to 20 IPs per key
Expiry without an allowlist
No forced expiry stated
Also worth knowing
2FA or U2F to confirm creation
Gemini
Read-only option
Yes. The Auditor role is read-only and cannot be combined with other roles
IP allowlist
Yes, Trusted IPs Only or Unrestricted
Expiry without an allowlist
No forced expiry stated
Also worth knowing
Trader and Fund Manager are the other roles
Bitstamp
Read-only option
Yes, by selecting only read permissions such as account balance
IP allowlist
Yes, lock to a specific IP
Expiry without an allowlist
No forced expiry stated
Also worth knowing
Withdrawals can also be locked to a specific address
Backpack
Read-only option
Yes. A Read Only toggle at creation
IP allowlist
Not stated in the docs we checked
Expiry without an allowlist
Not stated in the docs we checked
Also worth knowing
Authenticator code to create
Deribit
Read-only option
Yes. Scopes such as account:read, trade:read and wallet:read
IP allowlist
Yes
Expiry without an allowlist
No forced expiry stated
Also worth knowing
Scopes are the model; a read-only key is a key with only read scopes
BitMart
Read-only option
Yes. A new key is Read-Only by default
IP allowlist
Yes, optional, comma-separated list
Expiry without an allowlist
No forced expiry stated
Also worth knowing
A memo string is part of the signature
Upbit
Read-only option
Yes, by choosing only inquiry functions such as asset inquiry
IP allowlist
Required at issuance, up to 10 IPs per key
Expiry without an allowlist
Every key is valid 1 year and cannot be extended
Also worth knowing
Up to 10 keys per account; 2FA to issue
Bithumb
Read-only option
Yes, by choosing only inquiry items such as asset inquiry and order inquiry
IP allowlist
Required at issuance, up to 5 IPs per key
Expiry without an allowlist
Every key is valid 1 year and cannot be extended
Also worth knowing
Up to 10 keys per account
| Exchange | Read-only option | IP allowlist | Expiry without an allowlist | Also worth knowing |
|---|---|---|---|---|
| Binance | Yes. “Enable Reading” is the default permission on a new key | Yes | Trading permission on a key without an IP allowlist is valid 90 days; keys without an allowlist that sit unused 30 days are deleted | Read-only keys keep working without an allowlist |
| OKX | Yes. Read is one of three permissions (Read, Trade, Withdraw) | Yes, up to 20 IPs per key | Keys without an IP that hold Trade or Withdraw expire after 14 days of inactivity; read-only keys do not expire | Passphrase set at creation and never shown again |
| Bybit | Yes. Read-Only is a creation option | Yes | A key created without an IP expires after 90 days; extendable from API management | Binding an IP removes the expiry |
| Kraken | Yes, by permission: Query Funds, Query Open Orders and Trades, and so on | Yes | No forced expiry; optional key expiration and start date you set yourself | The most granular permission list of the twenty |
| Coinbase | Yes. View is the read-only level next to Trade and Transfer | Yes, allowlist at creation or later | No forced expiry stated | Keys are scoped to a portfolio, so one key can see one portfolio |
| Bitget | Yes. Read and write are separate permissions | Yes, up to 20 IPs per key | No forced expiry stated | Passphrase required; withdrawals only from allowlisted IPs; up to 50 keys per account |
| KuCoin | Yes. The “General” permission is read-only | Yes | General-only keys never expire; trading keys without an IP are disabled or deleted after 30 days of inactivity | Passphrase required |
| Gate | Yes. Each permission group can be Read Only or Read and Write | Yes, up to 20 IPv4 addresses per key | Keys not bound to an IP are valid 90 days, then disabled until an IP is bound | 20 keys per account; keys are deleted after 90 days without login |
| MEXC | Yes. Read-only can be enabled at creation | Yes, up to 20 IPs per key | Keys without an IP are valid 90 days; renewable in the last 5 days | Up to 30 keys per account |
| BingX | Yes. Read is a separate permission | Yes, up to 20 IPs per key | Read-only keys never expire; trading keys without an IP are deleted after 14 days of inactivity | Withdrawal keys must be IP-bound; 20 active keys per account |
| HTX | Yes, permissions are assigned per key | Yes, up to 4 IPs per key | Keys with trade or withdrawal rights and no IP are deactivated after 90 days of inactivity | Up to 5 keys per user |
| Crypto.com Exchange | Yes. New keys default to “Can Read” only | Yes, optional at creation | No forced expiry stated | 2FA to create; secret shown once |
| Bitfinex | Yes. Read and write are ticked separately per category, Account Info included | Yes, up to 20 IPs per key | No forced expiry stated | 2FA or U2F to confirm creation |
| Gemini | Yes. The Auditor role is read-only and cannot be combined with other roles | Yes, Trusted IPs Only or Unrestricted | No forced expiry stated | Trader and Fund Manager are the other roles |
| Bitstamp | Yes, by selecting only read permissions such as account balance | Yes, lock to a specific IP | No forced expiry stated | Withdrawals can also be locked to a specific address |
| Backpack | Yes. A Read Only toggle at creation | Not stated in the docs we checked | Not stated in the docs we checked | Authenticator code to create |
| Deribit | Yes. Scopes such as account:read, trade:read and wallet:read | Yes | No forced expiry stated | Scopes are the model; a read-only key is a key with only read scopes |
| BitMart | Yes. A new key is Read-Only by default | Yes, optional, comma-separated list | No forced expiry stated | A memo string is part of the signature |
| Upbit | Yes, by choosing only inquiry functions such as asset inquiry | Required at issuance, up to 10 IPs per key | Every key is valid 1 year and cannot be extended | Up to 10 keys per account; 2FA to issue |
| Bithumb | Yes, by choosing only inquiry items such as asset inquiry and order inquiry | Required at issuance, up to 5 IPs per key | Every key is valid 1 year and cannot be extended | Up to 10 keys per account |
How to read it
The second column is the one that matters for tracking: every exchange here has a way to issue a key that reads balances and history without trading or withdrawal rights. On Binance, Crypto.com and BitMart it is the default; on Gemini it is a role of its own; on Kraken, Deribit and Bitfinex it is a matter of ticking only the query or read boxes. A tracker that asks for anything beyond that column is asking for more than it needs.
The fourth column is where people get surprised. Binance, Bybit, Gate, MEXC and HTX put a 90-day clock on keys that are not bound to an IP address, OKX and BingX a 14-day one, KuCoin 30 days, and in most cases the clock applies to keys that carry trading rights. Read-only keys are exempt on OKX, KuCoin and BingX by their own docs. Upbit and Bithumb go the other way: every key lives exactly one year, IP attached from the start, and then gets reissued.
Three rules that make the table boring
- One key per tool, named after the tool. When a key page reads like an inventory, revoking a service never breaks another.
- Read-only unless the tool genuinely trades for you. The second column exists on every exchange; use it.
- Bind an IP allowlist wherever the tool has fixed addresses. It removes the expiry clock on most exchanges and turns a leaked key into a key that works from nowhere.
Frequently asked questions
Does a read-only key expire?
It depends on the exchange. OKX, KuCoin and BingX state that read-only keys do not expire; Binance, Bybit, Gate and MEXC apply their 90-day clock to keys without an IP allowlist; Upbit and Bithumb expire every key after one year regardless.
Is an IP allowlist required for a read-only key?
Only on Upbit and Bithumb, where every key is issued against a list of IPs. Everywhere else it is optional, and binding one usually removes the expiry clock.
Which exchange has the most granular permissions?
Kraken, with separate permissions for querying funds, orders and trades, followed by Deribit’s scope model and Gate’s per-group read or write setting. Gemini is the strictest in a different way: its read-only Auditor role cannot be combined with anything else.
Can a read-only key be used to withdraw?
No. Withdrawal is a separate permission on every exchange in the table, and on Bitget and BingX it additionally requires an IP allowlist.
Terms in this article
See your whole portfolio in one view
Read-only by design. Paste a wallet, link an exchange, and watch every chain. Free to start.
Open TrueHold →