How to Create a CoinDCX API Key: Steps and Safety
Create a CoinDCX API key on the web in 7 steps via the API Dashboard and an OTP. Save the secret (shown once), bind your IP and fix common API errors.
To create a CoinDCX API key, log in on the CoinDCX website, hover over the Profile icon, click "Profile", open "API Dashboard" in the left menu and click "Create A New One". Name the key, tick "Bind IP Address to the API Key" if you want it locked to your current connection, click "SEND OTP", enter the codes sent to your email and mobile, and click "CREATE". Copy the secret at once, because CoinDCX hides it forever after you refresh the page.
Key takeaways
- CoinDCX API keys are made in the API Dashboard of the web platform and confirmed with an OTP sent to your email and mobile.
- The secret is shown only once. If you lose it, delete the key and create a new one.
- Binding the key to your IP address is optional, but it is the best single protection if the key ever leaks.
- CoinDCX's official API docs say all keys have the same trading permissions and list no withdrawal endpoint, so treat every key as a trading key.
- One key covers spot and futures, including USDT-margined and INR-margined futures.
- A bot does not create an edge. Most retail bots lose money after fees, and every spot sell on an INR pair has 1% TDS deducted.
Before you start
You need a CoinDCX account with KYC completed and two-factor authentication switched on; CoinDCX's own guide asks for both first. CoinDCX is run by Neblio Technologies Pvt Ltd, which is registered with FIU-IND, and it is our top-rated Indian exchange at 8.4/10 in the CoinDCX review. Its API help pages describe the web platform, so if the mobile app shows no API section, use a laptop browser. Have a password manager open, because you will need a safe place for the secret within a minute.
Menus change from time to time, so the labels below may differ slightly in your version of the site.
How to create a CoinDCX API key, step by step
- Open the API Dashboard. On the CoinDCX web dashboard, hover over the Profile icon in the top-right corner and click "Profile". On the "My Profile" page, click "API Dashboard" in the left-hand menu.
- Start a new key. Click "Create A New One". The window for creating a key opens.
- Name the key. Use a label that says what the key is for, such as "futures-bot-server1". CoinDCX places no limit on the number of keys, so give each bot or tool its own key. You can then delete just the one you stop trusting.
- Decide on IP binding. Tick "Bind IP Address to the API Key" if the key will only ever be used from the device you are on now. CoinDCX binds the key to that device's IP address, and requests from anywhere else fail.
- Verify. Click "SEND OTP". CoinDCX sends a one-time password to your registered email and mobile number. Enter the codes and click "CREATE".
- Save the key and secret. Both appear on screen. Copy the secret into your password manager or your bot's protected settings now. In CoinDCX's words, "The Secret key is forever hidden after you refresh the screen."
- Go back to the list. Click "Go to Dashboard". The new key appears in your list, where you can later read it, copy it or scan it as a QR code. The secret can never be shown again.
API key vs secret: what each one does
The API key works like a username: it tells CoinDCX which account a request belongs to and travels with every request. The secret works like a password that never travels: your program uses it to sign each request. Anyone who holds both can trade your account from their own computer unless the key is bound to your IP address, so give the secret the same care as your net banking password.
What a CoinDCX API key can do
CoinDCX's official API documentation says it does not have read-only keys and that "all API users have the same level of permissions". A later CoinDCX blog post mentions read-only access, so check whether your key screen offers permission choices. If it does not, assume every key can trade.
| Action | Available through the API? | What it means for you |
|---|---|---|
| Read balances, open orders and trade history | Yes | Portfolio trackers and tax tools need this. |
| Place, edit and cancel spot orders | Yes | Any key can trade your spot balance. |
| Futures orders, leverage and margin | Yes, through the futures endpoints | A leaked key could open leveraged positions. |
| Transfers between wallets and sub-accounts inside CoinDCX | Yes | Money can move within your CoinDCX account. |
| Withdraw crypto to an outside address | Not listed in the API docs | Protect the key anyway. If a withdrawal option ever appears on your key screen, leave it off. |
Sub-accounts need their own keys, and a main-account key does not see a sub-account's trades. If you use sub-accounts, a bot kept in one with only the money it may risk has a hard ceiling on what a bug can lose.
IP binding on CoinDCX: how it works
CoinDCX's help pages describe IP binding as a tick box that locks the key to the IP address of the device you create it from, not an address you type in. That shapes your setup:
- Home computer: home broadband and mobile data often get a new public IP address without warning, and a bound key then stops working until you create a new one.
- Cloud server: a fixed public IP suits binding well, but the key must be created from that same address.
- Third-party platform: if it gives you IP addresses to whitelist, check whether your key screen accepts them. An unbound key works from anywhere, so the platform's security becomes yours.
- Several machines: create a separate key for each one.
CoinDCX futures API
The same key works for futures. CoinDCX's API docs have a full futures section covering instruments, order books, candles, orders, positions, leverage, margin and wallet transfers, for both USDT-margined and INR-margined contracts. You pick the margin currency on each order. The main fields of a futures order look like this:
| Field | Example value | What it does |
|---|---|---|
pair | B-BTC_USDT | The futures instrument. |
side | buy | Buy or sell. |
order_type | stop_market | One of market, limit, stop_limit, stop_market, take_profit_limit or take_profit_market. |
total_quantity | 0.002 | Order size. |
stop_price | your trigger price | Trigger price for stop and take-profit orders. |
leverage | 5 | Must match the position's leverage, or the order is rejected. |
margin_currency_short_name | INR | INR or USDT margin. USDT is used if you leave it out. |
timestamp | 1759300000000 | Time in milliseconds. Futures orders arriving more than 10 seconds late are rejected. |
There is also a separate endpoint that attaches take-profit and stop-loss orders to an open position. Use it. A stop-loss that sits on the exchange still works if your bot crashes or your internet drops, while a stop that lives only in your code does not. Leverage also moves your liquidation price closer, so read how liquidation price works before a bot trades futures for you. On spot, check each market's allowed order types first: the BTCINR market, for example, accepts only limit and market orders.
How CoinDCX signs API requests
Every private CoinDCX API call is a POST request with a JSON body. Your program adds the current time in milliseconds to the body, signs the exact body text with your secret using HMAC-SHA256, and sends the result as a hexadecimal string in a header. CoinDCX repeats the calculation with its copy of the secret. If both results match and the timestamp is recent, the request goes through. The secret itself is never sent.
| Part of the request | Example | What it holds |
|---|---|---|
| Base URL | api.coindcx.com | The CoinDCX API server. Full documentation is at docs.coindcx.com. |
Header X-AUTH-APIKEY | your API key | Identifies your account. |
Header X-AUTH-SIGNATURE | 64 hex characters | HMAC-SHA256 of the JSON body, made with your secret. |
Body field timestamp | 1759300000000 | When the request was made, in milliseconds. Old requests are rejected. |
| Other body fields | side, order_type, market, total_quantity | The order or query itself. |
The docs list a general rate limit of 16 requests a second and 960 a minute, with higher per-endpoint limits for spot order placement (2,000 per 60 seconds) and a tight one for cancelling all orders (30 per 60 seconds). Limits change, so check the docs before you build around them. One practical point: CoinDCX is not supported by the popular open-source ccxt library, so most free bots cannot connect to it out of the box. You need code written for CoinDCX's own API or a platform that supports it. Our guide to API keys on every Indian exchange compares this with other platforms.
Security rules for your CoinDCX key
A bot needs only the API key, the secret and, if you bound the key, a connection from the allowed IP address. It never needs your login password, OTPs, 2FA codes or a deposit into someone else's account. For the full path from signal to signed order, see how crypto trading bots place trades.
- Bind the IP whenever the bot runs from a fixed address.
- Never enable a withdrawal permission for a bot key if one is ever offered.
- Store the secret like a password: in a password manager or an environment variable on the server, never in a screenshot, a shared document or code you upload.
- Never paste the secret into Telegram, WhatsApp, a Google Form or any website you do not fully trust. No genuine support team needs it.
- Delete keys you no longer use, and create a fresh one whenever you stop using a platform.
- Watch your order history. Orders you did not place are the first sign a key has leaked.
Even without withdrawals, a leaked key can do real damage: scammers use such keys to buy a thinly traded coin at inflated prices from their own sell orders, or to open leveraged futures. Anyone who promises guaranteed returns from a bot in exchange for your API key is running a scam. Our guide on whether it is safe to give an API key to a trading bot goes deeper, and if money has already gone, follow the steps to report a crypto scam in India.
Common CoinDCX API errors and fixes
| Error or symptom | Likely cause | Fix |
|---|---|---|
| 401 Unauthorized | Wrong key or secret, a stray space when pasting, a deleted key, or a signature that does not match the body sent | Copy the key again from the dashboard. Sign the exact JSON text you send. A deleted key can never be used again, so create a new one. |
| A key that worked now fails | Your public IP address changed and the key is bound to the old one | Create a new key from the new address, or run the bot from a server with a fixed IP. |
| Request rejected for its timestamp | Your computer's clock has drifted, or the request was built too early | Turn on automatic time sync and create the timestamp just before sending. |
| 429 Too Many Requests | Rate limit reached | Slow the bot down and cache market data. |
| "Invalid Request" or "Order type not allowed" | A missing field, a wrong value, or an order type that market does not accept | Check fields and allowed order types against the docs. |
| 422 leverage mismatch (futures) | Order leverage differs from the position's leverage | Set the position's leverage first, then send the order. |
| Access refused for a product | A permission or product is not enabled | If your key screen shows permission choices, tick the right one, and check the product, such as futures, is active on your account. |
CoinDCX's help pages do not mention an expiry date for API keys. If a key suddenly stops working, first check it still appears on your API Dashboard.
How to delete or rotate a CoinDCX API key
- Open the API Dashboard and find the key.
- Click "DELETE", then "Continue" in the confirmation box.
- Enter your account password and click "Confirm". The key stops working at once and cannot be restored.
To rotate a key, create the new one first, update your bot with it, confirm the bot works, and only then delete the old key. Rotate after you stop using any platform, change servers or suspect a leak, and review your key list every few months.
Before you automate anything
Automation does not create an edge; it repeats your rules faster, mistakes included. Most retail bots and strategies lose money after fees and slippage, and backtests nearly always look better than live trading. Our crypto algo trading guide for beginners in India has the full roadmap.
Costs add up quickly for a busy bot. CoinDCX deducts 1% TDS on spot sells in INR pairs, none on spot buys in INR pairs, 1% on both sides of crypto-to-crypto trades, and no TDS on its futures. A spot bot that makes 50 sells of ₹10,000 each in a month on INR pairs has ₹5,000 deducted as TDS (1% of ₹5,00,000). That cash sits in your tax account until you claim it in your return, so the bot has less to trade with. Trading fees also carry 18% GST, gains are taxed at 30% plus 4% cess, and losses cannot be set off against other income. The tax treatment of futures is still unsettled; see crypto futures trading in India: legal status and tax.
If you have never followed a fixed rule set by hand, practise that first. Our free 100-Day Trade Challenge gives up to 2 AI-generated trade ideas a day, each with an entry, a stop-loss and targets, sized so one stop-loss costs about ₹200 on the default ₹2,220 wallet. You place every trade yourself on your own exchange, and there is no guarantee of profit.
FAQ
Where is the API option in CoinDCX?
On the CoinDCX website, hover over the Profile icon, click "Profile" and choose "API Dashboard" in the left-hand menu. CoinDCX's help pages describe the web platform, so use a browser if the app does not show it.
Can I see my CoinDCX API secret again?
No. CoinDCX shows the secret only once and hides it forever after you refresh the screen. If you lose it, delete the key and create a new one.
Does the CoinDCX API support futures trading?
Yes. The API docs include full futures endpoints for USDT-margined and INR-margined contracts, including orders, positions, leverage, margin and take-profit or stop-loss orders.
Can I create a read-only API key on CoinDCX?
CoinDCX's official API docs say there are no read-only keys and that all keys have the same permissions. Check your key screen in case this has changed, and otherwise treat every key as a trading key.
Can someone withdraw my crypto with my CoinDCX API key?
CoinDCX's API docs list no crypto withdrawal endpoint, but a leaked key can still place trades that drain your balance. Bind the key to your IP address and never share the secret.
Why does my CoinDCX API key say unauthorised?
The usual causes are a wrong or deleted key, a signature that does not match the body you sent, a changed IP address on a bound key, or a computer clock that has drifted. Fix the cause, or create a fresh key.
This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.