How to Safely Connect Your Exchange to a Portfolio Tracker
API keys explained: what read-only means, what permissions to grant, and how to verify you are never at risk.
What Is an API Key?
An API key is a credential that allows a third-party application to access your exchange account, but only within the permissions you define. Think of it like a visitor badge for your exchange. It lets the visitor see certain areas but locks them out of everything else.
SmartViewAI only ever requests read-only permissions, which means we can see your balances, trade history, and positions. We cannot place orders, withdraw funds, or make any changes to your account.
What "Read-Only" Actually Means
When you create a read-only API key, you are explicitly granting these permissions:
- View account balances
- View trade history
- View open orders
- View deposit and withdrawal history
And explicitly NOT granting:
- Place new orders
- Cancel orders
- Withdraw funds
- Transfer between accounts
Even if SmartViewAI were to be compromised (and we work hard to prevent that), a read-only API key cannot be used to move your funds. This is enforced by the exchange itself, not just our policy.
Step-by-Step: Creating a Safe API Key
Binance
Go to Account, then API Management, then Create API. Select "Restrict access to trusted IPs only" and enable only "Read Info". Do not enable Spot and Margin Trading or Withdrawals.
Bybit
Go to Account, then API, then Create New Key. Choose "Read-Only" as the API type. No additional permissions needed.
OKX
Go to Profile, then API, then Create V5 API Key. Under Permissions, select "Read" only. Leave Trading and Withdrawal unchecked.
KuCoin
Go to Account, then API Management, then Create API. Under Permissions, check only "General" which covers balance and history. Do not check Trade or Transfer.
Additional Safety Tips
- Create a dedicated API key for SmartViewAI. Never reuse an API key across multiple services.
- Restrict by IP if possible. Lock the key to SmartViewAI's server IPs to prevent misuse even if the key is stolen.
- Rotate keys periodically. Delete and recreate your API key every few months as a precaution.
- Review connected apps regularly. Your exchange's API management panel shows all active keys. Delete any you no longer use.
Enjoyed this article? Put it into practice.
SmartViewAI gives you live portfolio analytics, AI-graded signals, and a built-in academy. All in one place.