TrueHold

Read-only API keys on OKX, Kraken and Coinbase, step by step

Where the read-only permission lives on OKX, Kraken and Coinbase, what to leave unticked, IP allowlists, key expiry, and what to paste into a tracker.

Three exchanges, three different screens, one rule: a tracker needs a key that can read balances and history and nothing else. This guide walks through the read-only key on OKX, Kraken and Coinbase in the order the screens appear, names the permissions to leave unticked, and covers the two settings most people skip, IP allowlists and expiry. Binance has its own guide, and the rules for twenty exchanges side by side are in the API keys table. The permission names and expiry rules below come from each exchange’s own documentation, checked on 2 September 2026.

Before you start

  • Sign in on the web. Key screens are web-first on all three exchanges, and the secret is shown once, so have the tracker open in the next tab and paste it straight in.
  • Decide about an IP allowlist. It only works when the tracker publishes the addresses it connects from; if it does not, leave the allowlist empty and rely on read-only scope, which is what limits the damage anyway.
  • Name the key after the tracker. Six months from now a key called “portfolio, read-only” is one you can safely delete or rotate.

OKX

  • Open your profile menu on the web and choose API keys, then create a new key.
  • Set the passphrase. OKX asks you to create one and never shows it again; it travels with the key and secret, so store all three together.
  • Permissions: tick Read. Leave Trade and Withdraw unticked. That single choice is the whole security model.
  • IP allowlist is optional, up to 20 addresses per key. Confirm with two-factor and copy the key and secret.
  • Expiry: read-only keys do not expire. Keys that hold Trade or Withdraw and no IP allowlist expire after 14 days of inactivity, which is one more reason to leave those unticked.
  • In TrueHold, paste key, secret and passphrase. OKX is a three-part credential; the OKX page shows what arrives: trading, funding and earn balances.

Kraken

  • Open Settings, then API, and create a new key.
  • Kraken has the most granular permission list of the three. Tick only the Query permissions: Query Funds, Query Open Orders and Trades, Query Closed Orders and Trades, Query Ledger Entries. Export Data is safe to add if you want tax exports to work later.
  • Leave everything that creates, modifies or cancels orders unticked, and leave Deposit Funds and Withdraw Funds unticked.
  • Optional: a key expiration date and a start date, both set by you. Kraken does not force an expiry.
  • Optional: IP restriction. Generate the key and copy the key and the private key; the private key is shown once.
  • In TrueHold, paste key and secret. The Kraken page shows balances and staking positions arriving next to your other venues.

Coinbase

  • Coinbase moved key creation to its developer portal; from Settings, then API, on coinbase.com you land there. This is the consumer Coinbase with Advanced Trade. Coinbase Exchange and Prime, the institutional products, use their own key systems.
  • Choose the portfolio the key may see. A Coinbase key is scoped to one portfolio; to read another, create another key.
  • Permissions: tick View. Leave Trade and Transfer off.
  • Signature algorithm: Coinbase offers ECDSA and Ed25519. Pick ECDSA unless the tracker’s form says it accepts Ed25519; exchange libraries expect ECDSA by default.
  • IP allowlist is optional and can be added at creation or later.
  • Download or copy the key name and the private key. They are the key and secret a tracker asks for, and they are shown once.
  • Expiry: Coinbase states no forced expiry for these keys. In TrueHold, paste them in the Coinbase flow and the balances join your total next to Base wallets and cold storage; the Coinbase page shows the result.

The two settings people skip

OKX

Read-only permission

Read, next to Trade and Withdraw

IP allowlist

Optional, up to 20 IPs per key

Expiry

Read-only keys never expire; keys with Trade or Withdraw and no IP expire after 14 days of inactivity

Kraken

Read-only permission

Query permissions, ticked one by one

IP allowlist

Optional

Expiry

No forced expiry; optional expiration and start dates you set

Coinbase

Read-only permission

View, next to Trade and Transfer

IP allowlist

Optional, at creation or later

Expiry

No forced expiry stated; one key sees one portfolio

Paste it into the tracker

In TrueHold, open Exchanges, choose Link an exchange, pick the venue and paste the credential: key and secret, plus the passphrase for OKX. The key is validated against the exchange before it is stored, then stored encrypted; the methodology page has the details. Balances and history assemble over the next minutes, and the account settings let you replace the key later without deleting the history. If a sync fails, the help center lists the usual causes, and the first one to check is always the permissions screen you just left.

If a key leaks

Delete it on the exchange’s API page, create a new one with the same read-only scope and paste the replacement into the tracker. A leaked read-only key exposes balances and history, which is bad enough, but it cannot place an order or start a withdrawal. Rotate it anyway, and check the exchange’s login and activity history while you are there.

Frequently asked questions

Can a read-only key move my funds?

No. Trading and withdrawals are separate permissions that the exchange enforces on its side. A key without them cannot place orders or withdraw, whoever holds it.

Do OKX read-only keys expire?

No. OKX expires keys that hold Trade or Withdraw permissions and no IP allowlist after 14 days of inactivity; read-only keys are exempt.

Why does Coinbase ask which portfolio?

A Coinbase key is scoped to one portfolio. Pick the one you want the tracker to read, and create another key for another portfolio.

Should I set an IP allowlist for a hosted tracker?

Only if the tracker publishes the addresses it connects from; otherwise the key stops working the first time it is used. Read-only scope is the protection that matters; the allowlist is a second layer when it is possible.

Terms in this article

See your whole portfolio in one view

Read-only by design. Paste a wallet, link an exchange, and watch every chain. Free to start.

Open TrueHold →