Two-factor authentication must be enabled on your account before you can create or delete API keys. See the Two-Factor Auth guide to get set up.
Key permissions (scopes)
When you create an API key you choose which scopes to grant. Assign the minimum permissions required for your use case.Creating an API key
1
Open API Keys settings
Go to Settings → API Keys. You’ll see a list of all your existing keys along with their scopes and last-used timestamps.
2
Start a new key
Click New API Key to open the key creation form.
3
Enter a label
Give the key a descriptive label that identifies where it will be used — for example,
trading-bot-prod or portfolio-dashboard. This label appears in your activity log, making it easy to trace which key performed any given action.4
Select permissions
Check the scopes your integration needs. Avoid selecting
all unless you are testing locally. For a read-only dashboard, select only read. For an automated trading script, select read and trade.5
Set an IP allowlist (optional)
Enter one or more IP addresses or CIDR ranges that are allowed to use this key. Requests from any other IP will be rejected. Leave this field empty if your integration runs from a dynamic IP address.
6
Confirm with 2FA
Enter the current 6-digit code from your authenticator app and click Create Key.
7
Copy your key immediately
Your new API key is displayed exactly once. Copy it now and store it securely — for example, in your deployment environment’s secrets manager or an encrypted vault. After you close this dialog, the full key cannot be retrieved again.
IP restrictions
Adding an IP allowlist to a key means it will only work when requests originate from the addresses you specify. This protects you in the event the key is leaked — an attacker would also need to be on your allowed network to use it. You can enter:- A single IPv4 address, e.g.
203.0.113.42 - An IPv6 address, e.g.
2001:db8::1 - A CIDR range, e.g.
203.0.113.0/24 - Multiple entries by adding one per line
Rotating a key
Rotate your API keys regularly to limit the damage of any undetected exposure. Follow these steps to rotate without downtime:- Create a replacement key with the same scopes and IP restrictions as the key you’re replacing. Copy the new key value.
- Update your integration to use the new key. Deploy and verify that the integration is working correctly with the new key.
- Revoke the old key once you have confirmed the replacement is live (see the section below).
Revoking a key
To permanently revoke an API key:- Go to Settings → API Keys.
- Find the key you want to remove and click Revoke.
- Confirm the action in the dialog. You will be asked to enter your 2FA code.
401 Unauthorized response. If your integration is still using that key, update it to a new one before revoking.
Using an API key
Include your API key as a Bearer token in theAuthorization header of every request.
bba_sk_live_abc123... with your actual key value.