How to Create a Delta Exchange India API Key
Create a Delta Exchange India API key in 6 steps. Trading keys need a whitelisted IP, the secret shows once, and India uses its own API URL, not Global.
To create a Delta Exchange India API key, log in, click the profile icon in the header and select "API Keys", enter a name and the IP address your bot will trade from, tick the "Trading" permission, click "Create New Key", then copy the key and the secret. Delta displays the secret only once, and it will not create a key with trading permission unless at least one IP address is whitelisted.
Key takeaways
- Keys are created on the "API Keys" page of your Delta account and confirmed with verification codes.
- There are two permissions, "Read Data" and "Trading". Delta offers no withdrawal permission at all.
- A key with "Trading" permission must have at least one whitelisted IP address. IPv4 and IPv6 both work, and you can add several.
- India accounts must use api.india.delta.exchange. The address api.delta.exchange belongs to Delta Global and will not accept India keys.
- Each request signature is valid for only 5 seconds, so your computer's clock must be accurate.
- Delta also has a free testnet and a built-in TradingView webhook bot. Neither turns a losing strategy into a winning one.
What Delta Exchange India is
Delta Exchange India is a crypto derivatives exchange for futures and options, with margin and settlement in rupees. It is operated by Excelium Technologies Pvt Ltd, which Delta says is registered with FIU-IND (reporting entity ID VA00041101). The old address india.delta.exchange now redirects to www.delta.exchange. We rate it 7.2/10 (eighth among exchanges we cover) in our Delta Exchange review, and the regulatory background is in is Delta Exchange legal in India. Delta says both its trading API and its data API are free to use; you pay only the normal trading fees.
Before you start
- A verified Delta Exchange India account with two-factor authentication switched on. Key creation asks for verification codes, and Delta's TradingView bot does not work without 2FA.
- Your bot's public IP address. For a cloud server, use its fixed public IPv4 address. For a home computer, note that the address can change. If you get it wrong, Delta's error message shows the address it actually saw.
- A safe place for the secret, such as a password manager, open before you begin.
Menus change from time to time, so the labels below may differ slightly in your version of the site or app.
How to create a Delta Exchange India API key, step by step
- Open the API page. Log in, click the profile icon in the header and select "API Keys". On the web, the page address ends in /app/account/manageapikeys.
- Name the key. Pick a name that says what it is for, such as "btc-futures-bot".
- Whitelist IP addresses. Enter the IP address your bot will trade from. For several addresses, separate them with commas.
- Choose permissions. Select "Trading" if the key will place orders. A key only for reading data does not need it.
- Create and verify. Click "Create New Key" and enter the verification codes. More than 5 wrong OTP or 2FA codes blocks key creation for 30 minutes.
- Copy both values. Copy the API key and the secret and store them safely. The secret is only displayed once; if you lose it, delete the key and create another.
Delta API key permissions
| Permission | What it allows | Who needs it |
|---|---|---|
| "Read Data" | Market data and other read-only calls | Dashboards, data downloaders and research scripts. |
| "Trading" | Placing and cancelling orders, closing positions, changing margin and leverage. Delta's docs also place the orders, positions and wallet endpoints under this permission. | Any bot that places orders. Requires at least one whitelisted IP. |
| Withdrawal | Not offered | Nobody. A Delta API key cannot move funds out of your account. |
Delta's own advice is to grant only the permissions you need and to use separate keys for different jobs. The missing withdrawal permission is a real safety feature, but it does not make a leaked key harmless: whoever holds it can still open leveraged positions that wipe out your margin.
IP whitelisting rules on Delta
A key with "Trading" permission only works from a whitelisted address. Requests from anywhere else fail with the error code "ip_not_whitelisted_for_api_key", and the response shows the IP address Delta saw, which you can then add. You can whitelist several addresses, use IPv4 or IPv6, and change the list later from the same page. Delta's docs point out the usual traps:
- IPv4 vs IPv6: your machine may connect over IPv6 while you whitelisted an IPv4 address, or the reverse. Whitelist both, or turn off the one you did not whitelist.
- Changing home addresses: your internet provider may change your home or office IP about once a week. Update the whitelist when it does.
- Cloud servers: give the server a static public IPv4 address, so you are not whitelisting again and again.
- VPNs: a VPN changes the address your requests come from, so switch it off or whitelist the VPN's fixed address.
If you connect a third-party platform, whitelist only the server addresses it gives you. A platform that cannot tell you its addresses cannot use a Delta trading key at all.
India API vs Global API vs testnet
| Environment | Base URL | Which keys work |
|---|---|---|
| Delta Exchange India (live) | api.india.delta.exchange | Keys from your India account. |
| Testnet (demo account) | cdn-ind.testnet.deltaex.org | Only keys created in the demo account at demo.delta.exchange. |
| Delta Global | api.delta.exchange | Not India accounts. India keys fail here. |
Using a key in the wrong environment is one of the most common causes of the invalid_api_key error. It also matters for open-source tools: the ccxt library lists Delta as delta, but it points to the Global API by default, so an India account may need the base URL changed in its settings. Test that on the testnet with demo keys before you try it live. Our guide to API keys on every Indian exchange shows which other platforms ccxt supports.
How Delta signs API requests
Every private request carries your API key, a timestamp and a signature in its headers. To make the signature, your program joins the HTTP method, the timestamp, the request path, the query string and the body into one string, then signs it with your secret using HMAC-SHA256 and converts the result to hexadecimal. Delta repeats the calculation and accepts the request only if the result matches and the signature is less than 5 seconds old.
| Header | Example value | What it does |
|---|---|---|
api-key | your API key | Identifies your account. |
timestamp | 1759300000 | Unix time in seconds. It must be the same value used inside the signature. |
signature | 64 hex characters | HMAC-SHA256 of method + timestamp + path + query string + body, made with your secret. |
User-Agent | python-3.10 | Names your language or library. Delta requires it; without it, requests can be blocked. |
Content-Type | application/json | Request bodies must be valid JSON. |
Because of the 5-second limit, keep automatic time sync switched on (on Windows, the Windows Time service) and create a fresh timestamp for every request. Delta's rate limits use a quota of 20,000 per 5-minute window, with each endpoint weighted differently, plus a cap of 500 operations per second per product. The full picture of how a bot turns a signal into a signed order is in how crypto trading bots place trades.
Common Delta API errors and fixes
| Error | Likely cause | Fix |
|---|---|---|
invalid_api_key | A deleted or regenerated key (regenerating deletes the old one), a typo, or a key used in the wrong environment | Confirm the key still exists and match live keys to the India URL and demo keys to the testnet. |
SignatureExpired | The signature was more than 5 seconds old when it arrived | Sync your clock and build the timestamp just before sending. |
Signature Mismatch | The signed string differs from the real request | Use the same method, path, query string and body in both, and the right secret. |
UnauthorizedApiAccess | The key lacks the permission that endpoint needs | Create a key with the right permission ticked. |
| IP not whitelisted | The request came from an address not on the whitelist | Add the IP shown in the error response. |
| "Request blocked by CDN" | No User-Agent header, or a hidden client IP | Set a User-Agent and check your hosting does not mask your IP. |
Delta's docs we checked do not describe an expiry date for keys. If a key stops working, first check it still appears on your API Keys page.
Delta's built-in TradingView webhook bot
If you trade from TradingView alerts, Delta has a no-code option that needs no API key. Delta says it costs nothing extra.
- Open the "Algo" menu in the header and choose "Trading Bot". Two-factor authentication must be on.
- Enter a "Webhook Name", pick the "Account Name" to trade on, tick the box confirming you understand the risks and click "Create Webhook".
- Enter the email OTP and your 2FA code and submit.
- Copy the TradingView message and the Webhook URL from the popup. The URL is not shown again after you leave the page, and Delta says it should not be shared with anyone. Treat it like a password.
- In TradingView, create an alert on your strategy and paste in the message and the webhook URL.
Delta's tutorial message uses these fields:
| Field | Value in the alert | What it does |
|---|---|---|
| symbol | {{ticker}} | The contract to trade. |
| side | {{strategy.order.action}} | "buy" or "sell", from your strategy. |
| qty | {{strategy.order.contracts}} | Number of contracts. |
| trigger_time | {{timenow}} | When the alert fired. |
TradingView sends webhooks only on paid plans (Essential or higher) and only with 2FA on your TradingView account. It warns that webhooks may occasionally fail, and it stops an alert that triggers more than 15 times in 3 minutes. Delta advises opening the first position by hand, because strategy alerts reverse positions, and it emails trade confirmations and errors. Our explainer on what a webhook is in crypto trading covers failure modes such as missed and duplicate alerts.
Delta's menus also list an "Algo Marketplace" for subscribing to automated strategies, a "Strategy Builder" for basket orders, and "Demo Trading". A strategy's past results in a marketplace are no promise of future ones.
Options and data through the API
Delta's API covers options as well as futures. Its tickers endpoint returns the Greeks (delta, gamma, theta, vega and rho) for option contracts, and its historical candles endpoint returns up to 2,000 candles per request across many timeframes, useful for testing ideas. An options bot must also handle expiry correctly; our Bitcoin options expiry page shows the schedule, and the best crypto options trading apps in India compares platforms.
Security and risk: what to get right first
- Whitelist tight: list only the addresses your bot really uses, and remove old ones.
- One key per bot, named clearly, so you can delete one without breaking the rest.
- Store the secret like a password, in a password manager or an environment variable, never in shared files or code you upload.
- Never paste the secret or webhook URL into Telegram, WhatsApp, a Google Form or a website you do not trust.
- Delete unused keys and old webhooks.
- Distrust promises. Anyone offering guaranteed returns from a bot in exchange for your API key is running a scam. Read is it safe to give an API key to a trading bot first.
Delta is a leverage venue, so a bot's mistakes compound fast. Understand how liquidation price works and funding rates before you automate anything. Most retail bots and strategies lose money after fees, backtests overstate results, and automation repeats mistakes as reliably as good trades. If you have never traded a fixed rule set by hand, our free 100-Day Trade Challenge is one way to practise: up to 2 AI-generated trade ideas a day, sized so one stop-loss costs about ₹200 on the default ₹2,220 wallet, with every trade placed by you on your own exchange and no guarantee of profit. The crypto algo trading guide for beginners in India sets out the full path.
Tax and fees on Delta API trading
Delta says the 1% TDS and the 30% VDA tax do not apply to its INR-settled futures and options. That is the exchange's own view, not an official ruling. The government has issued no specific clarification: the conservative view taxes futures profits at 30% under the VDA rules, while some tax experts treat INR-settled contracts as business income at slab rates. Read crypto futures trading in India: legal status and tax before filing. Trading fees carry 18% GST, which Delta shows as a $20 fee costing $23.60. A bot that trades often pays that on every fill, so count fees before you judge any strategy.
FAQ
Where is the API key option in Delta Exchange India?
Click the profile icon in the header and select "API Keys". There you name the key, whitelist IP addresses, choose permissions and click "Create New Key".
Is IP whitelisting mandatory for a Delta Exchange API key?
Yes, for any key with "Trading" permission. You can whitelist several IPv4 or IPv6 addresses and change them later.
Can a Delta Exchange API key withdraw funds?
No. Delta offers only "Read Data" and "Trading" permissions. A leaked trading key can still open positions, so protect it anyway.
Which API URL should I use for Delta Exchange India?
Use api.india.delta.exchange for live trading and cdn-ind.testnet.deltaex.org for the testnet. The address api.delta.exchange belongs to Delta Global and will not accept India keys.
Does Delta Exchange have a testnet or demo account?
Yes. Create a demo account at demo.delta.exchange and make separate demo keys there; they work only on the testnet.
Is the Delta Exchange API free?
Delta says its trading and data APIs are free, and its TradingView webhook bot has no extra cost. You still pay trading fees plus 18% GST.
This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.