Is It Safe to Give Your API Key to a Trading Bot?
Yes, if the key can trade but never withdraw, is locked to fixed IPs and runs on software you control. Permission risks, scam signs and a leak checklist.
Giving an API key to a trading bot can be reasonably safe if you limit what the key can do: trading permission only, withdrawals switched off, the key bound to fixed IP addresses, and the bot run by you or a well-known platform. It is never risk-free, because a trading key can still lose your money through bad or malicious trades, so never give one to a stranger, a Telegram group or anyone promising guaranteed returns.
Key takeaways
- The most important rule: never enable withdrawal permission on a key that a bot or any third party will use.
- Bind every key to fixed IP addresses. Delta Exchange India makes this mandatory for trading keys, and on Binance a system-generated key without IP restriction can only read.
- A trade-only key can still be abused. Scammers use stolen keys to buy near-worthless coins from themselves at inflated prices.
- Keep only the money the bot needs on the account, use one key per bot and delete keys you no longer use.
- If a key leaks, delete it first, then check orders and positions, then report at cybercrime.gov.in or call 1930.
What can someone do with your API key?
An API key and its secret let software act on your exchange account within the permissions you chose. The risk depends almost entirely on those permissions.
| Permission | What it allows | Worst case if the key leaks | Does a bot need it? |
|---|---|---|---|
| Read only | View balances, orders and trade history | Privacy loss: a scammer learns what you hold and targets you | Yes |
| Spot trading | Place and cancel spot orders | Your balance is used to buy an illiquid coin at inflated prices, or churned until fees and TDS eat it | Only for a spot bot |
| Futures trading | Open leveraged positions, change leverage and margin | High-leverage positions opened and liquidated, wiping out the futures balance | Only for a futures bot |
| Wallet transfers | Move funds between your own wallets or sub-accounts | Money moved to where a trading key can lose it | Rarely |
| Withdrawals | Send crypto out of the exchange | Everything sent away in minutes; blockchain transfers cannot be reversed | Never |
A leaked read-only key is a privacy problem. A leaked withdrawal key is usually a total loss. Everything in between depends on how well the key is protected and how much money sits in the account.
How scams use API keys
Most of these schemes do not hack anything. They persuade you to hand the key over, or to install something that takes it. These are the patterns to know.
- Pump-and-dump through your account. The attacker holds a thinly traded coin, uses your key to place large buy orders at inflated prices, and sells their own coins into your orders. No withdrawal is needed: your rupees or USDT simply turn into a coin that is worth a fraction of what you paid. This is why "trade only" does not mean "safe".
- Fake "AI trading bot" schemes. PIB Fact Check has repeatedly debunked AI-generated deepfake videos of the Finance Minister promoting "AI trading software" or "Quantum AI" schemes that promise lakhs of rupees a month on a deposit of ₹22,000 to ₹25,000, in November 2025 and again from February to May 2026. Similar "AI forex bots" are common too; the RBI keeps an Alert List of unauthorised forex trading platforms.
- "Managed bot" offers with guaranteed returns. A Telegram or WhatsApp group asks for your API key and secret "to connect the bot" and promises a fixed daily or monthly return. Anyone promising guaranteed returns from a bot in exchange for your key is showing a scam sign. I4C's CyberDost cyber-safety account warned in July 2026 to treat guaranteed returns and "VIP tips" as red flags.
- Phishing forms and fake support. A Google Form, a fake "exchange support" chat or an email asks you to submit your key, secret or OTP to "verify" your account.
- Malicious downloads. A "free bot" program or app shared through a private link steals keys stored on your device. CyberDost's advice is never to download trading apps from private links.
- Accidental leaks. A secret pasted into code that is shared online, a screenshot sent to a friend or a settings file uploaded to a public folder.
Our guide to avoiding crypto scams in India covers the wider tricks these groups use.
The safe setup: eight rules
- Use an exchange registered with FIU-IND. Our list of registered exchanges shows which ones. FIU-IND named 15 unregistered offshore platforms in September 2026, including the bot-focused exchange Pionex.
- Never tick withdrawals. Some platforms make this easy. Delta Exchange India offers only "Read Data" and "Trading" permissions, CoinDCX's API docs list no withdrawal endpoint, and KuCoin keys linked to third-party apps cannot withdraw. Where a withdrawal option exists, leave it off.
- Bind the key to fixed IP addresses, as explained in the next section.
- Use one key per bot and label it with the bot's name, so you can delete exactly one key if something goes wrong.
- Keep the bot's balance small. Leave only the capital the bot trades on the account. CoinDCX supports sub-accounts, each with its own keys; check whether your exchange offers them to ring-fence bot money.
- Store the secret like a password. Keep it in a password manager or a protected settings file on the server, never in shared code, screenshots, email or chat. Never paste it into Telegram, WhatsApp, a Google Form or a website you do not trust.
- Protect the account itself. Use an authenticator app for two-factor authentication and a unique password, and secure the email linked to the exchange. Whoever controls the account can create new keys.
- Review and rotate. Check the API page every month, delete keys you no longer use, and replace any key that may have been exposed. On CoinSwitch PRO, generating a new key pair cancels the old one; Mudrex lets you rotate or revoke a key.
Exact steps for these settings are in our guides to creating a CoinDCX API key and creating a Binance API key in India. Menu labels can differ slightly between app versions.
IP whitelisting: the setting that stops most key theft
IP whitelisting (also called IP binding or IP restriction) tells the exchange to accept requests with your key only from IP addresses you list. If someone copies your key and secret but uses them from another computer, the exchange rejects the request. Delta Exchange India, for example, returns the error ip_not_whitelisted_for_api_key.
| Exchange | IP rule for API keys |
|---|---|
| Delta Exchange India | Mandatory for keys with trading permission. Several IPv4 or IPv6 addresses allowed, editable later |
| Binance | A system-generated key with unrestricted IP access can only read. Trading needs an IP restriction or a self-generated key, and withdrawals always need an IP restriction |
| KuCoin | Trading or withdrawal permission needs an IP whitelist. Trading keys without an IP lose trading permission or are deleted after 30 days of inactivity |
| Bybit | Keys without bound IP addresses expire after 90 days unless you extend them |
| CoinDCX | Optional. It binds the key to the IP address of the device you create it from |
| Pi42, ZebPay, Giottus | Whitelisting supported; switch it on |
Which address should you whitelist? The one your bot actually runs from. Home broadband addresses can change without notice, which breaks a whitelisted key, so most people run bots on a rented server with a fixed IP address. Note the CoinDCX detail above: if you create the key on your laptop but run the bot on a server, the bound IP will not match. If you use a paid bot platform, whitelist the server addresses it publishes; a platform that cannot tell you where its requests come from gives you no way to lock the key down.
Who holds your key? Four ways to run a bot
| Setup | Who holds the key | Main risk | How to reduce it |
|---|---|---|---|
| Exchange's own bot tools, such as Delta Exchange India's TradingView webhook bot | No key leaves the exchange | Strategy losses; a leaked webhook URL | Keep the webhook URL private, as Delta advises |
| Open-source bot you run yourself, such as Freqtrade | You, on your own computer or server | Your server's security; fake copies of the software | Download only from the official project; start in dry-run (paper) mode |
| Paid bot platform that connects by API | The platform stores it | A breach at the platform; wrong settings | Trade-only key, whitelisted to the platform's IPs |
| A person, Telegram group or unknown app | A stranger | Total loss | Do not do it |
If you connect TradingView alerts to a bot, never put your API secret in the alert message; TradingView itself says not to put passwords or credentials in webhook messages. Our explainer on how bots place trades through APIs and webhooks shows where the key sits in each step, and free crypto trading bots in India compares the free options.
A safe key can still lose money
Security settings protect you from theft, not from the bot. Most retail bots and strategies lose money after fees, backtests usually look better than live trading, and automation repeats a mistake as fast as it repeats a good trade. A bug can send duplicate orders, and an exchange outage can leave a position open. Keep a stop-loss on the exchange itself so it still works if the bot crashes, and start with a small amount. If you want to practise a rules-based method with a fixed loss limit before automating, our free 100-Day Trade Challenge is one option: members place every trade themselves, and nothing about it guarantees a profit.
What to do if your API key leaks
- Delete the key immediately on the exchange's API page. Deleting is faster and safer than editing permissions, and it stops every request at once. On CoinDCX you click "DELETE", then "Continue", then enter your account password.
- Secure the account if the password, email or two-factor app may also be exposed: change the password and reset two-factor authentication.
- Check open orders and positions. Cancel orders you did not place and close futures positions you did not open.
- Check trade and withdrawal history, including saved withdrawal addresses. Note times, order IDs and amounts.
- Contact the exchange's support with the key's label, when you noticed the problem and the suspicious trades.
- Report it on the national cybercrime portal, cybercrime.gov.in, or call the 1930 helpline as soon as possible. Our guide on how to report a crypto scam in India lists what to keep ready.
- Find the leak before creating a new key. Check the device or server, remove the secret from any file or chat, then create a fresh key with IP binding.
Red flags before you share anything
- Someone asks for your API secret by chat, form or email.
- The offer promises guaranteed or fixed daily, weekly or monthly returns.
- The bot "needs" withdrawal permission, for example to pay out profits.
- You must deposit money to "activate" the bot or unlock withdrawals.
- The app comes from a private link rather than an official store or project page.
- A celebrity or minister appears in a video endorsing it.
- You are pushed to act fast because slots are "limited".
For the bigger picture of which exchanges offer API keys and how their rules differ, see our comparison of crypto exchange API keys in India, and if you are new to bots, start with the beginner's guide to crypto algo trading in India.
FAQ
Is it safe to share my API key?
With trading-only permission, withdrawals off, IP whitelisting and a bot you control or trust, the risk is manageable. Never share a key with a person, group or app that promises guaranteed returns.
Can someone steal my crypto with just an API key?
If withdrawals are enabled, yes. Without withdrawal permission they cannot send your crypto out directly, but they can still drain value with bad trades, such as buying a thin coin from themselves at inflated prices.
Should I enable withdrawal permission for a trading bot?
No. A trading bot only needs to read balances and place orders, so there is no reason to give it withdrawal access.
What is IP whitelisting for an API key?
It limits the key to requests from IP addresses you list, so a stolen key fails when used from any other computer. Delta Exchange India requires it for trading keys.
What should I do if my API key is leaked?
Delete the key at once, check and cancel any orders or positions you did not create, contact the exchange, and report the incident at cybercrime.gov.in or on 1930.
Is an API secret the same as my password?
No, but treat it like one. It cannot log in to the website, yet it can act on your account through the API within whatever permissions you gave it.
This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.