100-Day Trade Challenge: trade on our AI predictions, up to 2 trade ideas a day. Free · educational · unregulated & risky Create free account
Cryptos: 21,748 Exchanges: 1,506 Market Cap: $2.87T 2.62% 24h Vol: $100.72B Dominance: BTC: 58.3% ETH: 11.4% Fear & Greed: 74/100 USD/INR: ₹95.83
Guides

How to Create a Binance API Key in India: Full Steps

Create a Binance API key via Account, API Management, Create API. New HMAC keys can trade only after an IP restriction. Permissions, futures and safety.

How to Create a Binance API Key in India: Full Steps
Photo: Markus Spiske from Forchheim, Bavaria Upper Franconia, CC0, via Wikimedia Commons

To create a Binance API key in India, log in on the Binance website, click your profile icon, go to "Account" and then "API Management", click "Create API", choose a key type, add a label and confirm with your 2FA code or passkey. On a system-generated key, Binance lets you enable trading only after you restrict the key to trusted IP addresses, so decide where your bot will run before you start.

Key takeaways

  • Binance is registered with FIU-IND (since 2024), so Indians can legally use it and its API.
  • You need 2FA, completed identity verification and a deposit of any amount in your Spot Wallet before you can create a key.
  • A system-generated (HMAC) key can only read data until you add an IP restriction. Self-generated Ed25519 keys are the alternative Binance's docs recommend.
  • Never enable the withdrawals permission on a bot key.
  • For a futures bot, open your Futures account first, then create the key, or the key cannot get futures permission.
  • No key, bot or strategy guarantees profit. Most retail bots lose money after fees, and Indian tax applies to every trade.

Can Indians use the Binance API?

Yes. Binance registered with FIU-IND in 2024. FIU-IND had acted against it for serving Indian users without registering, and on 19 June 2024 ordered a penalty of ₹18.82 crore. As a registered platform it must follow India's anti-money-laundering rules, including KYC. We rate it 7.5/10 (sixth among exchanges we cover) in our Binance review, and the full legal background is in is Binance legal in India. Product access can vary by country, so check what your own account shows before you plan a bot around a product such as futures.

Before you start

  • Two-factor authentication must be switched on.
  • Identity verification (KYC) must be complete.
  • A deposit of any amount must be in your Spot Wallet. Binance will not let you create a key until there is one.
  • Know your bot's IP address. If the bot runs on a cloud server, note its fixed public IP. Home connections usually change address from time to time, which breaks IP-restricted keys.

Binance updates its menus regularly, so the labels below may differ slightly in your app or site version.

How to create a Binance API key on the website

  1. Open API Management. Log in, click your profile icon, then "Account", then "API Management".
  2. Click "Create API".
  3. Choose the key type. "System-generated" gives you an API key and a Secret Key made by Binance. "Self-generated" means you create an Ed25519 or RSA key pair with key-generation software and give Binance only the public key.
  4. Enter a label. Name it after the job it does, such as "spot-grid-server1".
  5. Verify. Confirm with your 2FA code or passkey.
  6. Save the secret now. Binance says Secret Keys "are only visible at the time the API Key is created". Put it straight into a password manager. If you lose it, delete the key and create a new one.
  7. Set restrictions. Click "Edit restrictions", select "Restrict access to trusted IPs only (Recommended)", enter your server's IP address, tick only the permissions your bot needs and click "Confirm".

How to create a Binance API key in the app

  1. Switch the app to the Binance Pro version if you are using the simpler mode.
  2. Tap "More" to open the Services panel.
  3. In the "Other" section, tap "API Management".
  4. Tap "Create API" and follow the same steps as on the website.

The website is usually easier, because you can paste the secret straight into a password manager on the same computer instead of copying a long string across devices.

System-generated vs self-generated keys

QuestionSystem-generated (HMAC)Self-generated (Ed25519 or RSA)
Who creates the secret?Binance creates the API key and Secret KeyYou create the key pair; Binance receives only the public key
Where does the secret live?Shown once, then stored by youThe private key never leaves your computer
Can it trade without an IP restriction?No. It is limited to reading data until you add trusted IPsYes, although an IP restriction is still wise
What do Binance's developer docs say?Described as deprecatedEd25519 is recommended
Best forTools that ask you to paste a key and secretYour own code

Binance API key permissions: what to tick

PermissionWhat it allowsDoes a bot need it?
"Enable Reading"View balances, orders and trade historyYes. It is on for every key.
"Enable Spot & Margin Trading"Place and cancel spot orders, and margin ordersOnly for a spot bot. Margin means borrowing, which a beginner's bot should not do.
"Enable Futures"Futures orders, positions and leverageOnly for a futures bot.
The withdrawals permissionSending crypto out of your Binance accountNever. No trading bot needs it. Binance also requires an IP restriction before it can be switched on.
Anything else you seeVariesLeave it off unless you know exactly why you need it.

A portfolio tracker needs only "Enable Reading". Give each tool its own key with the least it needs, and you can cut off one tool without touching the others. Binance allowed up to 30 keys per account at last check.

The IP restriction rule, explained

Since 30 January 2023, a system-generated key with unrestricted IP access can only have "Enable Reading". To trade with it, you must add trusted IP addresses under "Edit restrictions". This is deliberate: an IP-restricted key is useless to a thief who copies it, because Binance refuses requests from any other address.

You may read that Binance deletes unrestricted trading keys after 90 days. That rule was retired in October 2023. Today an unrestricted system-generated key simply cannot trade.

For a bot on your own computer, the catch is that home broadband and mobile data addresses change. A small cloud server with a fixed public IP solves that. If you use a third-party platform, add the server IP addresses it publishes. If it publishes none, a system-generated key it uses cannot trade at all, and that tells you something about how seriously the platform takes security.

How to create a Binance futures API key

Order matters here. If you create a key before your Futures account exists, that key can never get the "Enable Futures" permission; the same applies to keys on a Portfolio Margin account. So open and fund your Futures account first, then create a new key and tick "Enable Futures" along with an IP restriction.

A futures bot uses leverage, so a bug or a bad rule can lose more than the margin you meant to risk in a single move. Keep leverage low, put stop-losses on the exchange rather than only in your code, and read crypto futures trading in India: legal status and tax first, because the tax treatment of futures is still unsettled.

How Binance signs API requests

For a system-generated key, your program joins the request's parameters into one string, signs it with the Secret Key using HMAC-SHA256, and adds the result as a signature parameter. The API key goes in a header. Binance repeats the calculation and accepts the request only if the signatures match and the timestamp falls inside the allowed window. The Secret Key itself is never sent.

Part of the requestExampleWhat it does
Header X-MBX-APIKEYyour API keyIdentifies your account.
Parameter stringsymbol=BTCUSDT&side=BUYThe order details as "parameter=value" pairs joined by "&".
timestamp1759300000000Time of the request in milliseconds. Required on every signed call.
recvWindow5000How long, in milliseconds, the request stays valid. The default is 5,000 and the maximum 60,000.
signature64 hex charactersHMAC-SHA256 of the parameter string, made with your Secret Key.

If your computer's clock drifts, requests fall outside the window and are rejected, so keep automatic time sync on. The full reference is at developers.binance.com. Binance is also supported by the free, open-source ccxt library and by Freqtrade, so many open-source bots can connect to it. Our guide to how crypto trading bots place trades walks through the whole order pipeline.

Practise on the testnet and demo first

Binance runs a Spot Test Network at testnet.binance.vision, with its own test keys and test funds, so you can check that your code signs requests and places orders correctly without touching real money. Binance also has a demo mode, including futures demo trading. Use them to find bugs, not to prove a strategy works: demo fills are kinder than real ones. Our guide on how to backtest a crypto trading strategy covers the testing steps in order.

Binance's built-in trading bots

You do not always need an API key. Binance offers its own bots inside the app: Spot Grid, Futures Grid, TWAP, VP (volume participation), Rebalancing Bot, Spot DCA, Futures DCA and Futures Funding Rate Arbitrage. Binance says they are "Free to use on Binance; low trading fees apply as normal", and Spot Grid pays normal spot fees. We could not confirm which of these Binance offers to Indian users, so check that a bot appears in your app before you plan around it. Built-in bots run inside Binance, so no key leaves your account, but they still trade your money by fixed rules. A grid bot, for example, loses in a strong trend; see what a grid trading bot is before you start one.

Security checklist for your Binance key

  • Never enable the withdrawals permission for any bot or third-party tool.
  • Restrict every trading key to trusted IP addresses.
  • Store the Secret Key like a password, in a password manager or an environment variable, never in a screenshot or shared file.
  • Never paste a secret into Telegram, WhatsApp, a Google Form or a website you do not trust. Binance itself says: "Both API key and secret key are sensitive. Never share them."
  • Delete keys you no longer use, and create a new key after you stop using any platform.
  • Check your order history regularly for trades you did not make.

Anyone offering guaranteed returns from a bot in exchange for your API key is running a scam. A leaked trading key cannot withdraw if you left that permission off, but it can still trade your balance into worthless coins. Read is it safe to give an API key to a trading bot before you connect any outside service.

Common Binance API problems and fixes

ProblemLikely causeFix
Trading permissions cannot be tickedA system-generated key with no IP restrictionAdd trusted IPs, or use a self-generated key.
"Enable Futures" is missingThe key was made before your Futures account, or you use Portfolio MarginOpen the Futures account, then create a new key.
Requests rejected for their timestampClock drift, or a slow connectionTurn on automatic time sync and build the timestamp just before sending.
Requests refused from your serverThe server's IP is not on the trusted listAdd the server's current public IP under "Edit restrictions".
Secret lostBinance shows it only onceDelete the key and create a new one.

Tax and TDS for Indian Binance users

Indian tax applies to you wherever you trade. Gains are taxed at a flat 30% plus 4% cess, only the cost of acquisition can be deducted, and losses cannot be set off against other income or carried forward. The 1% TDS rules apply to transfers. Do not assume Binance deducts TDS the way Indian exchanges do: download your Binance tax statements and compare them with the entries in Form 26AS and AIS. The basics are in what 1% TDS on crypto means.

For a bot, every sale is a taxable transfer. A grid bot that makes 200 sells of ₹5,000 each has sold ₹10 lakh of crypto; wherever 1% TDS is deducted on those sales, ₹10,000 is held back from your trading money until you claim it in your return. Each winning trade is taxed on its own and losses cannot be set off against it, so a bot that roughly breaks even can still leave you with a tax bill. Most retail bots lose money after fees, backtests overstate results and automation repeats mistakes as faithfully as good decisions. Start with our crypto algo trading guide for beginners in India, and compare other platforms in our guide to crypto exchange API keys in India.

FAQ

Where do I find API Management on Binance?

On the website, click your profile icon, then "Account", then "API Management". In the app, use the Pro version, tap "More", and find "API Management" in the "Other" section.

Why can't I enable trading on my Binance API key?

Since 30 January 2023, a system-generated key without an IP restriction can only read data. Add trusted IP addresses under "Edit restrictions", or use a self-generated Ed25519 key.

Do Binance API keys expire after 90 days?

No. That rule for unrestricted trading keys was retired in October 2023. Delete keys yourself when you stop using them.

How do I get a Binance futures API key?

Open your Futures account first, then create a new key and tick "Enable Futures". A key made before the Futures account existed cannot get that permission.

Can I see my Binance secret key again?

No. Binance shows the Secret Key only when the key is created. If you lose it, delete that key and create a new one.

Is it safe to use the Binance API from India?

Binance is registered with FIU-IND, so using its API is legal. It is as safe as your key setup: trading only, no withdrawals, IP restriction on, and the secret never shared.


This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.

Put it into practice

Run the 100-trade challenge: cap every loss, log every trade, and find out honestly whether you have an edge.