Security

API Permission Auditor

Review API permission combinations and identify severe key-permission risks without entering a key.

Runs locallySelections onlyEducational use

API permission checklist

Lower permission risk

Withdrawal permission is a severe risk for third-party tools. Use read-only or trading permissions without withdrawals whenever possible.

  • Recommended minimum profile: read balances, read orders, and no withdrawals.
  • Use IP allowlists where the exchange supports them.
  • Create one key per tool and rotate or delete unused keys.
  • Document revocation steps before connecting automation.

Local-only privacy notice: no API key value is requested.

Research context: This tool is inspired by transparent scenario analysis, observability, and network-model thinking. It does not reproduce proprietary formulas, provide investment advice, or predict prices.

Read PartnerCrypto methodology