Secret terminal

How to Connect an Exchange to Secret Terminal via API Keys.

How to Connect an Exchange to Secret Terminal via API Keys.

LESSON 2. API keys and connecting an exchange

Without an API key, Secret Terminal is just a window with a chart. No order book with real density levels, no tape, no account balance. Everything that makes the terminal a working tool for a scalper comes through this connection. And it's also the most common spot where beginners waste time on nonsense: the wrong set of permissions, an extra space when copying the key, a forgotten IP whitelist.

Let's walk through the whole path: what an API key is, which permissions to grant (and which ones absolutely not), how to create a key on Binance, Bybit and OKX, and how to connect it to the terminal without mistakes. If the terminal isn't installed yet - go through the basic setup first, described in the article "Installing Secret Terminal: The Complete Guide", then come back here for the keys.

What API Keys Are and Why the Terminal Needs Them

An API key is a pair of codes (a public API Key and a secret Secret Key) that let one program get authorized access to another program's data and functions. In our case, the terminal talks directly to the exchange's servers, bypassing its website and mobile app.

The practical benefit is simple. The terminal gets real-time data from the exchange: the order book, the tape, account balance, open positions. And it can send commands back: place a limit order, move a stop, close a position. All without switching between browser tabs and the exchange's app.

I usually explain it to beginners like this: an API key is like a separate entrance to your apartment that you hand out for one specific purpose. You can set it up so that whoever comes through can only look around, or you can also let them move things. Or you could throw in the key to your safe too. That last part is exactly what you shouldn't do.

With access comes responsibility. Through the API the terminal can work with your account, your money and your orders. So the section below isn't a formality - it's what actually protects your deposit.

If exchanges and APIs are a completely new topic for you, our free trading course on YouTube has a lesson covering exchanges and futures from the ground up. It's part of the playlist "Trading From Scratch | Free Crypto Trading and Scalping Course" - there are five lessons, and the second one is specifically about API keys.

Security: Which Permissions to Grant a Key (No Withdrawal)

There's one rule, and it's not up for discussion: withdrawal access is always off. For any exchange, under any circumstances. The terminal physically doesn't need it: to trade, place and cancel orders, check the balance - this function isn't required at all.

Permission checklist for the terminal key:

  • Reading - must be on. Without it the terminal won't see the balance or history.
  • Trading / Spot & Margin Trading - on if you trade spot.
  • Futures Trading - on if you work with futures (for scalping this is usually the main mode).
  • Withdrawal - off. Always.
  • IP White List - binds the key to a specific IP address. Recommended.

A few more rules that people often forget once the main checklist is done.

The key and Secret Key should never end up in messengers, phone notes, or text files on your desktop. In my experience, leaked keys almost always leak not through an exchange hack, but through a screenshot in a chat or a cloud file someone accidentally shared. One key, one job. Don't use the terminal's key for a bot or other software at the same time: if suspicious activity shows up, you won't be able to tell where it came from.

IP White List binds the key to your internet connection. If your IP is static, you add the address once and forget about it. If it's dynamic and changes, you'll need to update it periodically in the exchange settings. You can work without this binding, but it lowers your protection level: if the key leaks, an attacker could use it from any device.

And separately: two-factor authentication (2FA) via Google Authenticator on the exchange account itself isn't optional - it's the mandatory minimum. The API key protects trading access, but it's 2FA that keeps an outsider from getting into your account at all and creating their own keys there.

A detailed breakdown of key security settings for each exchange separately is in the article "Exchange API Keys: Security".

Creating API Keys on Binance (Step by Step)

Binance is the most common exchange for connecting to the terminal, so let's go through it in detail.

  • Go to the account menu in the top right corner → "API Management."
  • Click "Create API" and choose "System generated."
  • Give the key a name. Something clear, like ST, so that in six months you're not guessing what it was for.
  • Confirm creation with a code from Google Authenticator.

Right after the key is generated, move straight to setting permissions - don't put it off.

  • In the permissions editor, enable Futures Trading (if you trade futures) and leave Reading on. For spot, also activate Spot & Margin Trading.
  • Turn on "Restrict access to trusted IPs only" and add your IP address (you can find it through any IP-check service, like speedtest or whatismyip).
  • Save the settings. The exchange will ask for confirmation again: a code from the authenticator app and a code from email.

Done - the key is created and configured. One critically important rule remains: the Secret Key is shown only once. Refresh the page or close the window and that's it - you can't copy it again, only delete the key and create a new one. So the order of operations is: first copy the API Key and Secret Key, paste them into the terminal, check the connection, and only then close the window on the exchange.

For more on the login process itself and the general principles of working with Binance, see the article "How to Trade on Binance".

Creating API Keys on Other Exchanges (Bybit, OKX)

The logic is the same everywhere (reading plus trading, no withdrawal), but the interfaces differ. Here are the key nuances.

Bybit

Go to the account menu → API section → "Create New Key" → "System-generated." Set a name (e.g. ST) and choose Read-Write permissions. An important point specifically for Bybit: you must activate Unified Trading Account. Without it, the terminal won't be able to work with positions correctly. Optionally enable IP binding. Confirmation is a code from the Google Authenticator linked to the account.

OKX

The "API & Connections" section → "Create API Key." There are two things here that catch almost every beginner. First: you must select the Main Account, not a sub-account. Second: on OKX, generating an API key often requires a balance of at least $100 on the account. If there's less money than that, the exchange simply won't let you create a key - you'll need to top up first. Set permissions the standard way: reading and trading. Optionally enable Trade by IP and add your address.

The same rule applies to both exchanges as to Binance: the secret key is only shown once, at the moment of creation. Don't close the window until you've copied and saved both values somewhere reliable (in the terminal itself, not in a notepad file on your desktop).

Here's a quick summary for all three exchanges:

ExchangeWhere to Create a KeyWhat to EnableCommon Gotcha
BinanceAccount menu → API ManagementReading, Trading, Futures (if needed)IP whitelist via "Restrict access to trusted IPs only"
BybitAccount menu → APIRead-WriteWithout Unified Trading Account the terminal won't see positions
OKXAPI & Connections → Create API KeyReading, TradingKey must be created on the Main Account; generation sometimes requires a balance of $100+

When this doesn't work: you created the key on an OKX sub-account instead of the main one - the indicator in the terminal glows green, the connection seems to be established, but the balance and positions are empty. The key technically works, it's just looking at the wrong account. A similar thing happens with Bybit: forget to enable Unified Trading Account, and the terminal connects, but part of the futures position data just doesn't come through.

Connecting Keys in Secret Terminal

Once the key is ready on the exchange, connecting it in the terminal itself takes literally a minute.

  • Open "Settings" → "Trading Connections" (in some interface versions - the "Connections" section).
  • Select the exchange you need from the list.
  • Paste the API Key into the corresponding field.
  • Go back to the exchange website, copy the Secret Key, paste it into the terminal's second field.
  • Click "Create" and wait for the check to finish.

Below, an "Accounts" section appears with connection info. A green indicator next to the account name means the connection is up and data is flowing. Gray or red means there's an error somewhere - we'll cover that in the next section.

Checking the connection is simple: place a small limit order far from the price and see if it shows up in the order book. If it appears and cancels correctly, all the permissions are set right and the terminal genuinely sees your account, not just holding a token.

All keys are stored locally on the device; the terminal doesn't send them to third-party servers (Zero-Cloud Policy). The profile file with settings and keys is encrypted. Only technical information for syncing settings between devices goes to our servers, if sync is enabled, and even then without the keys themselves.

Common Connection Errors and Fixes

Indicator red, or the connection stuck on "Connecting"? Let's go through it in order, from the most common cause to the rarest.

An extra space when copying the key. The most common cause - I've run into it myself more than once. When copying the API Key or Secret Key, a space at the start or end of the line gets accidentally grabbed. Fix: clear the fields, paste the keys again, and check visually that there's nothing before the first character or after the last one.

The key wasn't given the right permissions. If only reading is enabled on the exchange, the terminal will see the balance but won't be able to place orders, and part of the modules will run in limited mode. Check on the exchange that Reading and Trading are enabled (plus Futures if needed).

IP whitelist enabled without the current address added. If your key has an IP binding but your actual current IP isn't in the list, the exchange just rejects all requests. Fix: go to the exchange, check your current IP through a checking service, and add it to the key settings. For a dynamic IP, you'll need to do this periodically.

System clock out of sync. Exchanges use timestamps in API requests, and if the system time is off by even a couple of minutes, authorization will keep getting rejected. The fix is simple: enable automatic time sync in Windows settings.

Blocked by antivirus or firewall. Less common, but it happens. Some security software blocks the terminal's outgoing connections to the exchange servers. Check the list of allowed apps in your antivirus and add the terminal to the exceptions.

If, after checking all of these, the connection still won't go through, message support on Telegram and attach the error text or a screenshot - that gets the problem solved much faster.

Once the key is finally connected and data is flowing, the next question usually is how to actually read what the terminal shows. That's covered in a separate lesson in the same free YouTube course, which breaks down the order book, clusters, and tape in practice.

FAQ

  • Do I need to give the API key withdrawal access?

    No. Reading and trading permissions are enough for the terminal to work. Leave withdrawal permission off always, regardless of the exchange.

  • Why doesn't the terminal connect to the exchange after creating a key?

    Most often it's an extra space when copying, an incomplete set of permissions on the key, or an enabled IP whitelist without the current address added. Less often it's the computer's clock being out of sync.

  • Can I use one API key for several terminals or programs?

    Technically yes, but you shouldn't. One key, one program. This makes it easier to revoke access if you suspect a leak, and keeps you from getting confused about where a strange request came from.

  • What if I lose the Secret Key?

    The exchange shows the Secret Key only once, at the moment of creation. It can't be recovered. Delete the old key on the exchange and create a new one.

  • Do I have to bind the key to an IP address?

    It's not mandatory, but it's good practice. IP binding means that even if the key leaks, it can't be used from another device.

The key is connected, the account is green, and the order book and tape are streaming in real time. What's left is getting familiar with the interface itself: how to read density levels in the order book, what cluster analysis shows, and how to set up your workspace.

Was helpful

Your rating will help us improve the quality of published materials and increase their usefulness.