Read-Only API Key: How to Create One on Bybit, Binance and OKX
Step by step for Bybit, Binance and OKX: create a read-only API key, keep trading and withdrawals off, bind IPs, and check or delete a key.

An API key is a pair of strings, the key and the secret, that lets a program into your exchange account without your password. Trading journals, tax tools and analytics services ask for one to read your trades and balance. A read-only key is all they need. It sees the data but cannot trade or withdraw. Here is how to create one on Bybit, Binance and OKX.
What is a read-only API key?
Exchanges let you grant a key three kinds of rights:
- Read. View balances, positions, orders and trade history.
- Trade. Place, change and cancel orders on your behalf.
- Withdraw and transfer. Move money out of the account or between accounts.
A key with trading rights is access to your money. If it is stolen from a service or from your computer, a stranger can trade on your account. With withdrawal rights, they can also take the funds. Binance warns plainly that entering your keys into any third-party platform is a security risk.
A read-only key removes that risk. It shows trades, positions and balances, but it cannot place, change or cancel orders, and it cannot move funds. A trading journal or analytics tool needs nothing more.
Even so, a read-only key exposes your data: your trade history and the size of your account. Give it only to services you trust.
How to create a read-only API key on Bybit
Keys are created on the Bybit website only; the app cannot do it. A new account may be blocked from creating keys for its first 48 hours.
- Click the profile icon at the top right and choose API. The API Management page opens.
- Click Create New Key and choose System-generated API Keys: a key the exchange generates for you.
- Keep API Transaction selected. The other option, Connect to Third-Party Applications, is for apps on Bybit's own list.
- Name the key and under API Key Permissions choose Read-Only.
- Choose IP binding or No IP restriction. Which one to pick is covered below.
- Tick the sections the service needs, for example Unified Trading. A Read-Only key will only read them.
- Confirm with your Google Authenticator code.
- Copy the API Key and API Secret. The secret will not be shown again.
How to create a read-only API key on Binance
Before it lets you create a key, Binance requires three things: two-factor authentication (2FA) turned on, a deposit of any amount to your Spot wallet, and completed identity verification.
- Click the profile icon and choose Account, then API Management.
- Click Create API and choose System generated: a key the exchange generates for you.
- Name the key and confirm with 2FA or a passkey.
- Copy the API Key and Secret Key. The secret is visible only at creation; after that it is masked.
- Click Edit restrictions on the key. Only one box should be ticked: Enable Reading. It is on by default.
- Leave Enable Spot & Margin Trading, Enable Futures, Enable Withdrawals and Permits Universal Transfer off.
Since 30 January 2023, a system-generated Binance key with no IP restriction can only read. Other permissions stay locked until you add an IP restriction or turn off the default security controls.
How to create a read-only API key on OKX
- Open your profile and the API section; on the website it may be called API and connections. Click Create API key.
- Enter a name, choose the account (main or a sub-account) and the key's purpose.
- IP addresses are optional: one key can be bound to up to 20 addresses.
- Under Permissions keep only Read. Leave Trade and Withdraw off, and Transfer, Loan and Earn too if you see them.
- Set a Passphrase, the key's own password. Write it down: you cannot view it later, and the key does not work without it.
- Confirm and save all three strings: API key, Secret key and Passphrase.
In some regions OKX lets you create a key only if the account holds more than $100. Residents of the European Economic Area and the US have their own OKX sites. A key from such a site works only through that site's address, so check that the service supports yours.
IP binding, checking permissions and deleting a key
IP binding means the key accepts requests only from the addresses you list. Exchanges recommend it. If a service publishes its addresses, enter them. If it does not, a read-only key can stay unbound, but each exchange has its own rules for unbound keys:
| Exchange | Read-only permission | Key without IP binding |
|---|---|---|
| Bybit | Read-Only | Stops working after 90 days, or 7 days after you change the account password |
| Binance | Enable Reading only | Deleted after 30 days without use |
| OKX | Read only | Deleted after 14 days without use, if it has Trade or Withdraw |
Button names here come from the exchanges' English sites. Other languages and regional sites may word them differently, and exchanges redesign their pages from time to time.
How to check permissions. Open the API page on the exchange: each key lists its permissions. A service can check them too: Binance has the apiRestrictions request, Bybit has query-api with a readOnly field, OKX has account/config with a perm field. If a journal asks for trading or withdrawal rights, that is a reason to say no.
How to delete a key. On Bybit, open API Management, click Delete in the Action column and confirm; this works on the website only. On Binance, delete the key on the API Management page; on OKX, click the key in the API section. Once a key is deleted, the service you gave it to loses access. If a key may have leaked, delete it at once and create a new one.
Key takeaways
- A journal only needs to read. Create a separate read-only key for each service, so you can delete any one without touching the others.
- Treat the secret like a password. Do not send it in messengers, and delete keys of services you no longer use.
Sources
- Bybit: How to Create Your API Key: website only, the 48-hour block for new accounts, the API Management steps.
- Bybit EU: What Is API Trading and How to Set It Up on Bybit EU: key types, API Transaction and third-party apps, Read-Only, the 90-day limit for unbound keys.
- Bybit API: Create Sub UID API Key: unbound keys expire after 90 days, or 7 days after a password change.
- Bybit API: Get API Key Information: the readOnly field.
- Bybit: How to Delete Your API Key: deleting from API Management, website only.
- Binance: How to Create API Keys on Binance?: requirements, the steps, read-only for unrestricted-IP keys since 30 January 2023.
- Binance: Frequently Asked Questions on API: the secret is masked after creation; third-party platforms are a security risk.
- Binance: How to Use an API Key Securely: unbound keys inactive for 30 days are deleted; one key per purpose.
- Binance API: Get API Key Permission: the apiRestrictions request.
- OKX: API FAQ: creating a key, the passphrase, the $100 requirement, EEA and US domains.
- OKX API v5 documentation: Read, Trade and Withdraw permissions, up to 20 IP addresses, the 14-day rule, account/config.


