Support Desk

Submit a ticket My Tickets
Welcome
Login  Sign up

API security instructions

TL;DR:
Incorrectly configured API keys can lead to the loss of all funds at an exchange. CoinTracking only requires read-only API permissions. Never create API keys with trading or withdrawal permissions for CoinTracking, never share keys with services you do not trust, and handle API keys as carefully as your passwords.


Why is API key security important?

Incorrectly configured API keys can lead to the loss of all funds at an exchange.

Please pay attention to the following points and handle API keys very carefully, just like your passwords.


What permissions should my API key have?

When creating a new API key, always assign only the permissions that are required.

CoinTracking only requires keys with read-only permission.

Make sure that your keys have:

  • No trade permissions

  • No withdrawal permissions

We will never ask you for keys with permissions other than read-only.


Can I use the same API key for multiple services?

No. Use an API key only with a single service, such as CoinTracking. Using one key for multiple services will always result in errors.


How are API secrets stored at CoinTracking?

All API secrets stored at CoinTracking are encrypted. They cannot be viewed or decrypted by our employees.


Should I use IP whitelisting?

Some exchanges allow whitelisting of IPs. This increases the security of your key. You can find the IPs used by CoinTracking here.


How should I manage my API keys over time?

Check your key permissions regularly and change your keys from time to time, just like your passwords. Do not write down API keys and secrets locally on your computer or in the cloud. If your browser automatically saves form data and passwords, make sure that your API secrets are not stored.


Should I share API keys with other services?

Never share your keys with services you do not trust. A few exchanges do not have any API permissions, and each key has full access. Avoid such insecure exchanges and switch to trustworthy exchanges.


Summary

CoinTracking only needs read-only API keys. Never use keys with trading or withdrawal permissions, do not reuse keys across multiple services, and store them as securely as your passwords. Use IP whitelisting where available and avoid exchanges that do not offer proper API permission controls.

Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.