API keys, explained
An exchange account has two doors. One is your login: password, two-factor code, the app on your phone. The other is the API, the door programs use. A bot never needs the first one. It uses an API key, a separate credential you create on the exchange, which can do only what you allow it to do and which you can delete at any moment.
What an API key is
A key is a set of credentials the exchange issues for one program.
- The API key is a public name. It tells the exchange which key is calling.
- The secret signs every request. The exchange checks the signature, so a request without the secret is refused. It is shown once, when the key is created.
- On OKX there is also a passphrase, which you choose yourself and enter again on A9.
- Binance also accepts a key pair you generate yourself (Ed25519): the public half is pasted into Binance and the private half is the secret. A9's keys page can generate the pair for you.
A key is not your login. It cannot change your password, your email or your security settings, and it cannot see anything the exchange does not expose through the API.
The permissions A9 asks for, and the one it refuses
When you create a key, the exchange offers a list of permissions. A9 needs only these.
- Read: balances, open orders and positions, so a bot can check the account against what it believes it holds.
- Trade: placing and cancelling orders. On Binance this is the spot and margin trading box.
- Futures: only for a bot with shorting switched on, because a short is placed on the perpetual in your futures account. Binance has a separate box for it; on OKX the trade permission covers both.
- Withdraw: never. A9 reads the key's permissions when you save it and again before any live bot starts, and a key that can withdraw is refused.
Why withdrawal rights are never needed
A9 is non-custodial. It places orders inside your account and nothing else: it does not move money between your accounts, and it never sends funds anywhere. Plans are paid by a transfer you make yourself. So there is no task for which A9 would need to withdraw, and a key without that permission cannot be talked into it. If a trade-only key were ever stolen, the worst it could do is trade inside your own account. That is still a risk, which is what the IP list closes.
The IP list, and where the key is kept
Exchanges let you restrict a key to named internet addresses. A request from anywhere else is refused, even with the correct secret.
A9's servers send every request from one fixed range, 4.144.67.208/28, which is sixteen addresses. A9 keeps this range fixed so that it does not change under your key. The two exchanges take it in different forms.
- OKX accepts the range as one entry.
- Binance needs the sixteen addresses written out, separated by spaces.
A9's keys page shows the line ready to paste for each exchange, so nothing has to be typed by hand.
With the list in place, a copy of the key is useless from any other machine. Exchanges also treat keys without an IP list with suspicion: OKX, for example, deletes keys that can trade but have no IP list once they go unused for a while.
On A9 the secret is encrypted before it is stored and decrypted only to sign a request. It is never shown again, never logged, and never sent to your browser after you save it. The keys page checks a new key straight away: permissions, IP list, and on futures whether the account is in one-way position mode, which a shorting bot needs.
How to cut access
You can end A9's access at any time, and the order of steps matters if bots are running.
- Stop the bots that use the key, from A9. When a bot holds a position, the stop asks whether to sell it or leave it in your account. Deleting the key first takes that choice away: the positions stay open on the exchange with nothing managing them.
- Delete the key on the exchange. This takes effect at once: no bot can place another order with it.
- Remove the key from A9's keys page, so nothing tries to use it again.
If you only want to pause trading, pausing a bot on A9 keeps its position and cancels its resting orders; the key can stay.
A short checklist
- Read and Trade on. Futures only if a bot will short. Withdraw off.
- IP list set to A9's line, copied from the keys page.
- Secret pasted once into A9 and kept nowhere else.
- For shorting bots, the futures account in one-way mode.