Which permissions does Altrady need?
When you create an API key on your exchange, it will ask you to choose which permissions (sometimes called “scopes” or “access rights”) to turn on. This can feel confusing, so here’s exactly what Altrady needs, and what it never needs.
What Altrady needs
1. Read / view access
This lets Altrady see your account information, such as:
- Your balances
- Your open and past orders
- Your trade history
This is a “look but don’t touch” permission. It’s required so Altrady can show you accurate data.
2. Trading permission
This lets Altrady place and manage orders on your behalf:
- Spot trading: needed if you trade on the spot market
- Futures trading: needed only if you also trade futures
Only enable the trading types you actually plan to use. If you never trade futures, you don’t need to turn on futures permission.
What Altrady never needs
Withdrawal (or “transfer”) permission.
Never enable this checkbox when creating an API key for Altrady. Altrady works perfectly well without it; it doesn’t need to move funds anywhere to do its job.
This is actually great news for your security: because this permission is off, an Altrady API key can never withdraw or transfer funds out of your exchange account, even in the worst-case scenario where the key was somehow exposed.
The checkbox names are different on every exchange
Every exchange labels these permissions a little differently. You might see wording like:
- “Enable Reading”
- “Enable Spot & Margin Trading”
…or something similar, depending on the exchange you use.
Because the exact names vary, always follow the step-by-step guide for your specific exchange in Connecting Your Exchange; it will show you exactly which boxes to tick.
One more layer of safety: IP whitelisting
For extra protection, most exchanges let you restrict your API key so it only works from specific IP addresses. This is optional but recommended. Learn how to set it up in IP Whitelisting Explained.