Category:

Connect Bybit (create an API key)

Updated: 07/24/2026 · 3 min read

An API key is how AlphaSet places trades on your behalf in your Bybit account. Important: this key only allows trading, never withdrawals.

Your funds always stay on your exchange. AlphaSet never holds your assets. You can revoke the key anytime - the Engine stops immediately.

Before you start

  • You need a verified (KYC) Bybit account using the Unified Trading Account.
  • Minimum capital for Alpha Crypto: $500 in your trading balance.
  • Note: the Engine manages your connected account's entire trading balance, up to your plan's capital cap - any excess sits idle, fee-free. If you want to keep part of your capital aside, hold it in a Funding account or a separate account.

Step 1 - Open API Keys on Bybit

Log in to Bybit → click your Account icon in the top-right → select API Keys. Click Create New Key → choose System-generated API Keys. Give it a memorable name, e.g. "AlphaSet".

🖼️ [IMAGE PLACEHOLDER] Image: the Bybit account menu, "API Keys" and the "Create New Key" button highlighted in red. Marketing will replace with a real screenshot.

Step 2 - Grant trade permission, NO withdrawal

Configure the key's permissions like this:

  • ✅ Select Read-Write mode.
  • ✅ Enable Unified Trading - Orders, Positions, Trade (so the Engine can enter/exit positions).
  • ✅ Enable Assets - Convert, Exchange History (so the Engine can read and reconcile your balance).
  • Do NOT check the Withdraw permission or transfer permission.

This is the most important point. AlphaSet only needs order-placement permission. If a key has withdrawal permission, AlphaSet will refuse the connection to protect you.

🖼️ [IMAGE PLACEHOLDER] Image: Bybit's create-API-key page, with Read-Write selected, Unified Trading (Orders/Positions/Trade) and Assets (Convert/Exchange History) checked, and Withdraw left off. Red box around the Withdraw toggle in the OFF state.

For extra security, paste AlphaSet's trusted IP list (shown in the app when you connect) into the "Only IPs with permissions granted are allowed to access the OpenAPI" field. On Bybit, the IPs are separated by commas. Once whitelisted, only AlphaSet can use this key - even if the key leaks, no one else can use it.

🖼️ [IMAGE PLACEHOLDER] Image: Bybit's Trusted IP field with AlphaSet's IP list, each IP separated by a comma.

Step 4 - Save the API Key and Secret Key

Click Submit. Bybit shows your API Key and Secret Key. Note: the Secret Key is shown only once - copy and store it safely. If you lose it, you must delete the old key and create a new one.

Step 5 - Paste into AlphaSet and Test Connection

Back in AlphaSet → Connect exchange screen → select Bybit → Enter API key manually → paste your API Key and Secret Key → click Test Connection.

AlphaSet automatically checks that the key can read your balance, has trade permission, and does NOT have withdrawal permission. When it shows connection successful, you're done. Your API key is stored with AES-256 encryption, decrypted only at execution time.

🖼️ [IMAGE PLACEHOLDER] Image: AlphaSet "Connect Bybit" screen with API Key / Secret Key fields and a "Test Connection" button, showing a mint-colored "Connection successful" state.

Quick tips

  • On Air you connect 1 exchange × 1 Alpha; Plus up to 2 exchanges × 2 Alphas. Pro/Max connect unlimited.
  • Bybit auto-disables an API key after 3 months if you don't bind a whitelist IP - whitelisting keeps the key alive longer.

Was this article helpful?

QUESTIONS

STILL NEED HELP?

Our technical team is always ready to answer your questions 24/7.

Contact support