Read-Only API Key: How to Create One on Bybit, Binance and OKX

Step by step for Bybit, Binance and OKX: create a read-only API key, keep trading and withdrawals off, bind IPs, and check or delete a key.

Fresco-style painting of a padlocked strongbox with glass sides showing gold and gemstones inside, with a brass key lying beside it on a stone table

An API key is a pair of strings, the key and the secret, that lets a program into your exchange account without your password. Trading journals, tax tools and analytics services ask for one to read your trades and balance. A read-only key is all they need. It sees the data but cannot trade or withdraw. Here is how to create one on Bybit, Binance and OKX.

What is a read-only API key?

Exchanges let you grant a key three kinds of rights:

  • Read. View balances, positions, orders and trade history.
  • Trade. Place, change and cancel orders on your behalf.
  • Withdraw and transfer. Move money out of the account or between accounts.

A key with trading rights is access to your money. If it is stolen from a service or from your computer, a stranger can trade on your account. With withdrawal rights, they can also take the funds. Binance warns plainly that entering your keys into any third-party platform is a security risk.

A read-only key removes that risk. It shows trades, positions and balances, but it cannot place, change or cancel orders, and it cannot move funds. A trading journal or analytics tool needs nothing more.

Even so, a read-only key exposes your data: your trade history and the size of your account. Give it only to services you trust.

How to create a read-only API key on Bybit

Keys are created on the Bybit website only; the app cannot do it. A new account may be blocked from creating keys for its first 48 hours.

  1. Click the profile icon at the top right and choose API. The API Management page opens.
  2. Click Create New Key and choose System-generated API Keys: a key the exchange generates for you.
  3. Keep API Transaction selected. The other option, Connect to Third-Party Applications, is for apps on Bybit's own list.
  4. Name the key and under API Key Permissions choose Read-Only.
  5. Choose IP binding or No IP restriction. Which one to pick is covered below.
  6. Tick the sections the service needs, for example Unified Trading. A Read-Only key will only read them.
  7. Confirm with your Google Authenticator code.
  8. Copy the API Key and API Secret. The secret will not be shown again.

How to create a read-only API key on Binance

Before it lets you create a key, Binance requires three things: two-factor authentication (2FA) turned on, a deposit of any amount to your Spot wallet, and completed identity verification.

  1. Click the profile icon and choose Account, then API Management.
  2. Click Create API and choose System generated: a key the exchange generates for you.
  3. Name the key and confirm with 2FA or a passkey.
  4. Copy the API Key and Secret Key. The secret is visible only at creation; after that it is masked.
  5. Click Edit restrictions on the key. Only one box should be ticked: Enable Reading. It is on by default.
  6. Leave Enable Spot & Margin Trading, Enable Futures, Enable Withdrawals and Permits Universal Transfer off.

Since 30 January 2023, a system-generated Binance key with no IP restriction can only read. Other permissions stay locked until you add an IP restriction or turn off the default security controls.

How to create a read-only API key on OKX

  1. Open your profile and the API section; on the website it may be called API and connections. Click Create API key.
  2. Enter a name, choose the account (main or a sub-account) and the key's purpose.
  3. IP addresses are optional: one key can be bound to up to 20 addresses.
  4. Under Permissions keep only Read. Leave Trade and Withdraw off, and Transfer, Loan and Earn too if you see them.
  5. Set a Passphrase, the key's own password. Write it down: you cannot view it later, and the key does not work without it.
  6. Confirm and save all three strings: API key, Secret key and Passphrase.

In some regions OKX lets you create a key only if the account holds more than $100. Residents of the European Economic Area and the US have their own OKX sites. A key from such a site works only through that site's address, so check that the service supports yours.

IP binding, checking permissions and deleting a key

IP binding means the key accepts requests only from the addresses you list. Exchanges recommend it. If a service publishes its addresses, enter them. If it does not, a read-only key can stay unbound, but each exchange has its own rules for unbound keys:

ExchangeRead-only permissionKey without IP binding
BybitRead-OnlyStops working after 90 days, or 7 days after you change the account password
BinanceEnable Reading onlyDeleted after 30 days without use
OKXRead onlyDeleted after 14 days without use, if it has Trade or Withdraw

Button names here come from the exchanges' English sites. Other languages and regional sites may word them differently, and exchanges redesign their pages from time to time.

How to check permissions. Open the API page on the exchange: each key lists its permissions. A service can check them too: Binance has the apiRestrictions request, Bybit has query-api with a readOnly field, OKX has account/config with a perm field. If a journal asks for trading or withdrawal rights, that is a reason to say no.

How to delete a key. On Bybit, open API Management, click Delete in the Action column and confirm; this works on the website only. On Binance, delete the key on the API Management page; on OKX, click the key in the API section. Once a key is deleted, the service you gave it to loses access. If a key may have leaked, delete it at once and create a new one.

Key takeaways

  • A journal only needs to read. Create a separate read-only key for each service, so you can delete any one without touching the others.
  • Treat the secret like a password. Do not send it in messengers, and delete keys of services you no longer use.

Sources

Share

Read next