HelpKeys and security
Replace or rotate an API key
Open the exchange account in TrueHold, replace the key from its settings, and the account keeps its history. Expiring keys are flagged in advance.
Keys get rotated for good reasons: an exchange expiry policy, a security review, or a key that was created with more permission than it needed. Replacing one keeps the account and its history intact.
Steps
- 01Create the new read-only key on the exchange first, so there is no gap.
- 02In TrueHold, open the exchange account and choose its settings. Replace the API key and secret, and the passphrase where one is used.
- 03The new key is validated before it is stored. Once it is accepted, delete the old key on the exchange.
Expiring keys
Some exchanges expire keys that are not bound to an IP address, Bybit after 90 days for example. Where the exchange reports an expiry date, TrueHold shows how many days remain next to the account and asks you to rotate the key on the day it expires. The 20-exchange table in the blog lists each venue’s expiry rule.
Related
Connect an exchange with a read-only API key
Create a read-only key on the exchange, paste it into TrueHold, and balances, positions and history appear. The key is validated before it is stored.
What TrueHold can and cannot do with your keys
Keys are read-only, validated before storing and encrypted at rest. They cannot trade or withdraw; revoking one on the exchange ends access at once.
Why a sync failed and what to do
A failed sync usually means a revoked or expired key or an exchange outage. TrueHold retries, emails you if it keeps failing, and lets you re-connect.
Still stuck?
Write to hello@truehold.xyz with the screen you are on. Answers become docs, so the next person finds it here.
