Category:

API key security & permissions

Updated: 07/12/2026 · 2 min read

An API key lets AlphaSet place trades on your behalf. But it's designed so it can never move your money out.

Your funds always stay on your exchange. AlphaSet never holds your assets.

Why only trade permission is needed

AlphaSet does exactly one thing with your key: place buy/sell orders for the Alpha you chose. To do that, the key only needs:

  • Trade permission (Trade / Futures / Spot) — so the Engine can enter/exit positions.
  • NO Withdraw permission — AlphaSet doesn't need it, doesn't ask for it, and will reject any key that has it.
  • NO internal transfer permission.

The result: even in a worst case, no one can use this key to move funds out of your account. You remain the only person in control of your assets.

IP whitelist — a second lock

You should restrict the key to work only from AlphaSet's trusted IPs. Once whitelisted:

  • Only AlphaSet's servers can use your key.
  • Even if the key leaks to someone else, they can't use it from another IP.
  • Some exchanges auto-disable keys after 90 days if not whitelisted — whitelisting keeps the key alive longer.

AlphaSet's IP list appears in the app at the connect step. Copy it, paste it into the exchange's IP field, separating each IP with a space.

🖼️ [IMAGE PLACEHOLDER] Image: exchange "IP access restriction" field with AlphaSet's IP list pasted (from the app), each IP separated by a space.

How AlphaSet protects your key

  • AES-256 encryption at rest: the key is encrypted in storage and decrypted only at execution time.
  • No secret exposure: the Secret Key is never displayed again after entry and is never logged.
  • Permission check on connect: AlphaSet tests the key first and rejects it if it detects withdrawal permission.

Revoke anytime

You stay in full control. Go to API Management on the exchange → delete or disable the AlphaSet key. The moment the key is invalidated, the Engine stops placing orders immediately. Any open positions remain on your exchange for you to manage.

🖼️ [IMAGE PLACEHOLDER] Image: exchange API Management page, red box around the "Delete" / "Disable" button for the AlphaSet key.

Quick summary

PermissionDoes AlphaSet need it?
Trade (Trade/Futures/Spot)✅ Yes
Withdraw❌ Never
Internal transfer❌ No
IP whitelist✅ Strongly recommended

Was this article helpful? 🙂 Still need help? → Contact us

Was this article helpful?

QUESTIONS

STILL NEED HELP?

Our technical team is always ready to answer your questions 24/7.

Contact support